Idempotency prevents retries becoming duplicates

Networks fail mid-request, so clients retry, so your system will receive the same instruction twice.

Without idempotency the customer is charged twice or the order ships twice, and it looks like an application bug rather than a design gap. It is also a security property: an attacker replaying a request gets a second effect unless something says this has already been done.

More on API security