# User state change

Triggered every time a user's state is updated.
* Event type: `users#state-change`
* Profile level subscriptions: Not Supported
* Application level subscriptions: Supported

**User state change transitions**:
Possible `previous_state` and `current_state` values:
- `ACTIVE`: The user's account is active.
- `WITHDRAW_ONLY`: The user has 90 calendar days to remove their money from their balance before we fully close their account. This can be done through sending from their balance to themselves and others or spending with their card. The user still cannot order new cards, convert between balances, open and close balances, and download balance statements. After 90 calendar days, the account moves into a `DEACTIVATED` state.
- `DEACTIVATED`: The user's account is deactivated and they cannot perform any actions on their account. The end-user tokens are revoked and you will receive a `401 Unauthorized` response for API calls.

Events may not be delivered in the order they occurred. Use `data.occurred_at` to reconcile the order.
See the [Event ordering guide](/guides/developer/webhooks/event-ordering) for details.
See the [Webhooks guide](/guides/developer/webhooks) for setup instructions, signature verification, and best practices.

Endpoint: POST users#state-change

## Header parameters:

  - `X-Signature-SHA256` (string)
    RSA-SHA256 signature of the request body, Base64 encoded. Verify this against the [Wise public key](/guides/developer/webhooks/event-handling#requests) to ensure the request is authentic and has not been tampered with.

  - `X-Delivery-Id` (string)
    Unique identifier for this webhook delivery attempt.

  - `X-Test-Notification` (boolean)
    Present with the value `true` if this is a test notification sent to verify your callback URL during subscription setup.

## Request fields (application/json):

  - `schema_version` (string)
    Version of the event schema. Determined by the `schema_version` on your [webhook subscription](/api-reference/legacy/webhook).
    Enum: "4.0.0"

  - `subscription_id` (string)
    ID of the webhook subscription that triggered this event.
    Example: f5b51f77-e14a-433b-9f7c-fc2834ffcff5

  - `event_type` (string)
    Event type identifier
    Example: users#state-change

  - `sent_at` (string)
    Timestamp when the event was sent.
    Example: 2020-01-01T12:34:56.123Z

  - `data` (object)

  - `data.resource` (object)

  - `data.resource.id` (integer)
    ID of the user.
    Example: 1234

  - `data.resource.type` (string)
    Resource type (always `user`).
    Example: user

  - `data.previous_state` (string)
    Enum: "ACTIVE", "WITHDRAW_ONLY", "DEACTIVATED"

  - `data.current_state` (string)
    The current state of the user.
    Enum: "ACTIVE", "WITHDRAW_ONLY", "DEACTIVATED"

  - `data.deactivation_type` (string)
    If the type is `ACCOUNT_SUSPENSION`, it is possible to appeal the deactivation by contacting Wise.
    Enum: "ACCOUNT_SUSPENSION", "ACCOUNT_CLOSURE"

  - `data.deactivation_reason` (string)
    The reason for deactivation.
    Example: REQUESTED_BY_CUSTOMER_CS

  - `data.occurred_at` (string)
    When the user state change occurred.
    Example: 2020-01-01T12:34:56.789Z

  - `subscription_id` (string)
    ID of the webhook subscription that triggered this event
    Example: f5b51f77-e14a-433b-9f7c-fc2834ffcff5

  - `sent_at` (string)
    Timestamp when the event was sent
    Example: 2020-01-01T12:34:56Z

## Response 200 fields (application/json):

  - `status` (string)
    Example: ok

