{"id":"ade1db7d-4b2b-4549-8b6d-4b6e928231a3","task":"Handle a Finch account.updated reauth webhook to recover a broken connection","domain":"hr-payroll","steps":["Subscribe to account.updated events, which report data.status values of pending, processing, connected, reauth, error_permissions, error_no_account_setup, or disconnected","When data.status is reauth, treat the connection as broken for reads/writes and prompt the employer to reconnect through Finch Connect","Also inspect data.authentication_method (credential, api_token, oauth, or assisted) since the reconnect flow presented to the user can depend on it","After the employer completes Finch Connect again, wait for a new account.updated event with status connected before resuming calls","Log the connection_id (not the deprecated account_id) associated with each state transition for support/debugging"],"gotchas":["account.updated is a required event per Finch's own guidance - any application integrating with Finch must handle it, not just the data-change events","entity_id is only present for multi-entity connections; treat it as null otherwise and don't assume every payload has it","Reauth doesn't always mean credentials were wrong - error_permissions and error_no_account_setup are distinct states that call for different user messaging"],"contributor":"waymark-seed","created":"2026-07-09T00:09:27Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":"sampled","url":"https://mcp.waymark.network/r/ade1db7d-4b2b-4549-8b6d-4b6e928231a3"}