At some point every connected-account app shows it: one of your banks or brokerages has quietly stopped updating. The balance is frozen on last Tuesday's number, or there is a small warning asking you to reconnect. The instinct is to worry that something is broken, or worse, that your data leaked. Almost always, neither is true. A connection going stale is normal, and usually it is the security design doing exactly what it is supposed to.
This guide explains how these read-only connections actually work, why they break, and the order to troubleshoot them in so you fix the real cause instead of poking at the wrong one.
How a read-only connection works
When you link a bank or brokerage to an aggregator, you are not handing over a permanent key. You are granting a read-only connection through a data provider. In Mozaic's case that is Plaid for banks and SnapTrade for brokerages. The connection can read your balances, positions, and transactions. It carries no authority to move money, place trades, or change anything at the institution.
Two properties of that connection explain almost everything about why it sometimes stops:
- It is read-only, so nothing it does can harm your accounts, and reconnecting is always safe.
- It is not permanent by design. It carries a consent that expires, and it can be interrupted whenever the bank wants to re-verify that it is really you granting access.
A connection that breaks is, more often than not, the second property working as intended.
The handful of reasons it breaks
Stale connections almost always trace to one of these, roughly in order of how common they are:
- Re-authentication is due. Many connections carry a consent window that expires on a schedule the institution sets, and some banks periodically re-verify you regardless. When it lapses, the connection pauses until you renew consent. This is one of the most common causes and it is completely routine.
- You changed your password or username at the bank or broker. The stored connection is now trying to authenticate with credentials that no longer exist, so it fails until you reconnect with the new ones.
- The bank added or changed a login step. A new multi-factor challenge, a new security question, updated terms you have to accept, or a redesigned login flow can all interrupt a connection that worked yesterday.
- A new-device or security verification triggered on the bank's side, holding access until you clear the challenge.
- Your multi-factor method changed (a new phone, a new number), so the previous verification path no longer reaches you.
- The institution's data connection is temporarily down. Banks and brokers do maintenance, and their third-party data endpoints have outages independent of their consumer app. This one fixes itself.
- The account itself is locked at the bank, in which case even you cannot log in directly, and that has to be sorted with the bank first.
Notice what is not on this list: your data being stolen. A break is a pause in read access, not a leak.
The order to fix it in
Troubleshooting works best from the outside in. Do these in order and you will usually land on the cause quickly.
Step 1: Is it one connection or all of them? If every institution stopped at once, the issue is more likely app-side or a broad provider hiccup, and waiting a short while is the right first move. If it is a single bank, the cause is specific to that institution, and you continue.
Step 2: Can you log into the bank directly? Open the bank or broker's own website or app and sign in normally. This one check splits the problem cleanly:
- If you cannot log in directly, the account is locked or the password changed. Fix that with the bank first. Nothing on the aggregator side can help until direct login works.
- If you can log in directly, your credentials are fine, and the connection simply needs to be renewed or re-authenticated.
Step 3: Reconnect the connection. In the app, reconnect the affected institution. This re-runs the secure login flow (Plaid calls this update mode; SnapTrade re-authorizes the brokerage), lets you enter a new password if it changed, and completes any new multi-factor challenge. For the large majority of stale connections, this single step is the whole fix.
Step 4: If reconnect still fails, suspect the institution's side. If direct login works but the reconnect will not complete, the bank's data endpoint may be temporarily down even though its consumer app is up. Wait and retry later in the day. Transient endpoint issues are common and clear on their own.
Step 5: If it persists across days, contact support. When a connection stays broken after a clean direct login and repeated reconnect attempts over more than a day, note the exact institution name and the precise error message, and reach out. Some banks periodically change how they expose data, and a specific institution may need work on the provider side.
Why relinking is safe
People hesitate to reconnect because re-entering credentials feels risky. It is the safe move. You are re-granting the same read-only access you granted the first time, through the same provider's secure flow, with no new powers. The connection still cannot move a dollar or place a trade. If anything, a connection that forces you to re-authenticate on a schedule is protecting you: it guarantees that read access cannot quietly outlive your intention to grant it.
If you are choosing an app in the first place and want to know which Canadian institutions connect cleanly, the supported banks and supported brokers directories list the current coverage, and the guide on tracking multiple brokerage accounts covers the wider setup.
How Mozaic helps
The Mozaic net-worth tracker shows a clear last-updated state for each connected account, so a connection that has gone stale is visible rather than silently frozen, and reconnecting runs the same read-only Plaid or SnapTrade flow described above. Because every connection Mozaic holds is read-only, a break is never a risk to your money, and a reconnect never grants more than read access.
Mozaic cannot force a bank's data endpoint back online or unlock an account locked on the bank's side; those are the institution's to resolve. What it does is make the state of each connection legible and the reconnect path short. Data is stored in Google Cloud's Montreal region under PIPEDA and Quebec Law 25 (/security), and the connection can be revoked from your side at any time.
The bottom line
A bank connection that stops syncing is usually not broken in any alarming sense. Read-only links are built to expire and to re-verify you periodically, so the top causes are a due re-authentication, a changed password, or a new login step at the bank, with the occasional temporary outage on the institution's side. Work from the outside in: check whether it is one connection or all, confirm you can log into the bank directly, then reconnect. Relinking is safe because the access is read-only, and a connection that asks you to prove it is you is the security model working.
If you would like a net-worth view that shows each connection's freshness at a glance and makes reconnecting a two-minute job, the 14-day free trial needs no card.
