# Profile state change

Triggered every time a profile's state is updated.
* Event type: `profiles#state-change`
* Profile level subscriptions: Not Supported
* Application level subscriptions: Supported

Events may not be delivered in the order they occurred. Use `data.occurred_at` to reconcile the order.
See the [Event ordering guide](/guides/developer/webhooks/event-ordering) for details.
See the [Webhooks guide](/guides/developer/webhooks) for setup instructions, signature verification, and best practices.

Endpoint: POST profiles#state-change

## Header parameters:

  - `X-Signature-SHA256` (string)
    RSA-SHA256 signature of the request body, Base64 encoded. Verify this against the [Wise public key](/guides/developer/webhooks/event-handling#requests) to ensure the request is authentic and has not been tampered with.

  - `X-Delivery-Id` (string)
    Unique identifier for this webhook delivery attempt.

  - `X-Test-Notification` (boolean)
    Present with the value `true` if this is a test notification sent to verify your callback URL during subscription setup.

## Request fields (application/json):

  - `schema_version` (string)
    Version of the event schema. Determined by the `schema_version` on your [webhook subscription](/api-reference/legacy/webhook).
    Enum: "4.0.0"

  - `subscription_id` (string)
    ID of the webhook subscription that triggered this event.
    Example: f5b51f77-e14a-433b-9f7c-fc2834ffcff5

  - `event_type` (string)
    Event type identifier
    Example: profiles#state-change

  - `sent_at` (string)
    Timestamp when the event was sent.
    Example: 2020-01-01T12:34:56.123Z

  - `data` (object)

  - `data.resource` (object)

  - `data.resource.id` (integer)
    ID of the profile.
    Example: 1234

  - `data.resource.type` (string)
    Resource type (always `profile`).
    Example: profile

  - `data.current_state` (string)
    The current state of the profile. Possible values:
- `ACTIVE` - The profile is active.
- `WITHDRAW_ONLY` - The profile has 90 calendar days to remove their money from their balance before Wise fully deactivates their account. This can be done through sending from their balance to themselves and others or spending with their card. They cannot receive money to their balances and fund transfers from external bank accounts. They can still order new cards, convert between balances, open and close balances, and download balance statements. After 90 calendar days, the profile will move into a `DEACTIVATED` state.
- `VIEW_ONLY` - The profile can access and view balances and account activities such as transfer history and balance statements. However, they can no longer perform actions such as moving money with Wise in any way. All transfers sent to the account after it is set to `VIEW_ONLY` mode will also bounce back to the sender. Cards will also be suspended.
- `DEACTIVATED` - The profile's account is deactivated and no actions can be performed on the account. The end-user tokens will be revoked and you will receive a `401 Unauthorized` response for API calls.
    Example: WITHDRAW_ONLY

  - `data.occurred_at` (string)
    When the profile state change occurred.
    Example: 2020-01-01T12:34:56.789Z

  - `data.requested_by_customer` (boolean)
    Whether the state change was requested by the customer. Not applicable for `current_state` in `ACTIVE`.
    Example: false

  - `subscription_id` (string)
    ID of the webhook subscription that triggered this event
    Example: f5b51f77-e14a-433b-9f7c-fc2834ffcff5

  - `sent_at` (string)
    Timestamp when the event was sent
    Example: 2020-01-01T12:34:56Z

## Response 200 fields (application/json):

  - `status` (string)
    Example: ok

