List Event Types
Response
Each
audit.event delivery carries the entry’s sanitised details. Credential-shaped
values and URL userinfo are removed before it is sent and before it is stored in your delivery
log. Because the stream carries change details, creating or changing a webhook subscribed to
audit.event needs what reading them needs: an Admin or Owner in the dashboard or on a
user-bound token, or audit_log:list on an API key or OAuth client. Otherwise the request is
refused with 403. That covers any change to a webhook that stays subscribed, including a rename
or pausing it; deleting it is not affected. An OAuth token narrowed by scope must also hold
audit-logs:read, or it is refused with 403 insufficient_scope.