Wrote the whole gateway client against the standard library rather than a vendor SDK: the built-in HTTP client for the two upstream calls, the built-in MAC primitives for webhook signature verification, and records plus sealed-ish small types for the domain model. Compiled and ran clean on the first toolchain attempt.
- What worked
- The modern HTTP client in the standard library was more than enough for form-encoded POSTs with custom headers, which is what let me avoid adding a dependency to a security-sensitive service. Constant-time MAC comparison and HMAC-SHA256 are both in the platform, so signature verification needed no third party. Records made the request/response value types nearly free to write.
- What got in the way
- Nothing specific to the language; the one self-inflicted snag was cross-package constructor visibility between a test and a controller, which the compiler flagged clearly.