> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.ada.cx/reference/audit-log/audit-log-webhook/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.ada.cx/_mcp/server. # Webhook: Audit log event POST A webhook sent when a configuration change is recorded in the Audit log. Delivery is best-effort; use the Audit log pull API (`GET /api/v2/analytics/audit-log/events/`) as the durable record to reconcile any events that were not delivered. Reference: https://docs.ada.cx/reference/audit-log/audit-log-webhook ## Request ### Payload - `type` (string, required) — The webhook event type. Audit log events use `v1.audit_log.emitted`; the `data.activity` field identifies what changed. - `timestamp` (string, required) — When the event was generated (millisecond precision, to help with event ordering) - `data` (AuditLogWebhookEventData, required) — The Audit log event data - `tags` (list of string, optional) — Tags for filtering webhook events in the Ada dashboard. Includes `entity_type`, `activity`, and `entity_id` by default. Ada may add additional tags at any time. ## Types ### AuditLogWebhookEventData A configuration change recorded by the Audit log, delivered as the `data` field of a `v1.audit_log.emitted` webhook. - `id` (string, required) — Globally unique audit event id - `timestamp` (string, required) — When the configuration change occurred (ISO 8601, UTC, millisecond precision) - `entity_type` (string, required) — The type of entity that was changed - `entity_id` (string, required) — The id of the entity that was changed - `activity` (enum, required) — What happened to the entity - Allowed values: `created`, `updated`, `deleted`, `executed`, `invited`, `activated`, `deactivated` - `actor_email` (string, optional) — Email of the actor (the user, or the owner of a dashboard-created Platform API key); empty for system and service-token actors. - `actor_name` (string, optional) — Display name of the actor; empty when unavailable - `actor_user_id` (string, optional) — User id of the actor. For an API key, the id of the user who created the key. Empty for system and service-token actors. - `entity_name` (string, optional) — Human-readable name of the changed entity - `interface` (string, optional) — Where the change originated, such as `dashboard`, `api`, `mcp`, `cli`, `import`, `export`, or `system`. - `context_ip` (string, optional) — Source IP address of the request that made the change - `context_user_agent` (string, optional) — User agent string of the request that made the change - `api_key_name` (string, optional) — Name of the API key used, when the change was made by a dashboard-created Platform API key; empty otherwise.