# Stripe Connect deauthorized: detect it and stop sending transfers

## The symptom

Transfers or destination charges to a connected account start failing. The account looked fine yesterday. In the dashboard the account shows as disconnected, or your API calls return errors about the account.

## Confirm the cause

Listen for `account.application.deauthorized`. It fires when a connected account disconnects your platform (usually the user clicking Disconnect in their Stripe dashboard). It is distinct from `account.updated`: the latter covers capability and requirement changes, the former means your access is gone.

Check the Connect webhook endpoint configuration: it must be a Connect-enabled endpoint subscribed to `account.application.deauthorized`. A platform-only endpoint never sees it.

## The fix

Handle the event by disabling the account in your system immediately:

```js
if (event.type === 'account.application.deauthorized') {
  const acctId = event.account;
  await db.connectedAccounts.update(acctId, { status: 'disconnected' });
  cancelPendingTransfers(acctId); // stop future transfer attempts
  notifyAccountOwner(acctId, reconnectLink(acctId));
}
```

Then:
- Gate every charge-on-behalf-of and transfer call on the local `status` field. A disconnected account must never reach the Stripe call.
- Unknown-account events should be acknowledged (2xx) and dropped, not retried: a disconnect means there is nothing to retry.
- Do not conflate deauthorization with a failed payout. A failed payout is retryable; a deauthorized account needs the owner to reconnect through onboarding again.

Also watch `account.updated` for `requirements.disabled` or capability flips on Custom/Express accounts: payouts or charges can be restricted while the account stays connected, which needs a different remediation (collect the due requirements).

## Verify the fix

In test mode, connect a test account, trigger deauthorization, and confirm the event arrives, the local status flips to disconnected, and no further transfer attempts are made. Confirm a transfer attempt against the disconnected account is blocked by your gate before touching the Stripe API.
