Is this a typical definition of idempotency? One where you have to be idempotent even when another system is in play? I wouldn't expect anything to be idempotent if something else can come along and change arbitrary state.
> An HTTP method is idempotent if an identical request can be made once or several times in a row with the same effect while leaving the server in the same state.
Which is according to what OP wrote.
I wouldn't translate this into "the intended effect happens at most once", as that behavior includes the effect of the transport. "at most once", "at least once" and "exactly once" are messaging behaviors after all, and idempotency is a method to convert an "at least once"-messaging-effect into an "exactly once"-change-effect.
Or your authorization could change and you no longer have access to the resource.
Honestly I'm not sure what the author thinks idempotency is.