# List events

`GET /api/v1/events`

Everything that has happened in the organization, newest first — the same envelopes webhooks deliver. Use it to catch up after downtime, or as a polling trigger instead of webhooks. Scopes are per event type, because an event carries the whole resource: booking.* needs "bookings:read", customer.* needs "customers:read", gift_card.* needs "gift_cards:read". Without ?type you get the types your key may read; asking for a type it may not read answers 403.

Scope: none

## Parameters

- `limit` (query, integer) — How many results to return, 1-100. Defaults to 25.
- `order` (query, "asc" | "desc") — Sort by creation time: "desc" (newest first, default) or "asc".
- `starting_after` (query, string) — The next_cursor from a previous page. Opaque — pass it back verbatim.
- `type` (query, "booking.created" | "booking.confirmed" | "booking.cancelled" | "booking.rescheduled" | "customer.created" | "customer.updated" | "gift_card.issued" | "gift_card.redeemed") — Only events of this type. Omit to get every type your key may read.

## Responses

- `200` — A page of events.
- `400` — Invalid request — codes "validation_failed" or, on an endpoint that requires one, "idempotency_key_required".
- `401` — Missing, invalid, revoked or expired API key — codes "api_key_missing", "api_key_invalid", "api_key_revoked", "api_key_expired".
- `403` — The API app is off, the plan does not include the API, or the key lacks the required scope — codes "app_not_enabled", "plan_upgrade_required", "insufficient_scope" (the last carries "required_scope").
- `429` — Rate limit exceeded — code "rate_limited". See the x-ratelimit-* headers.
- `500` — Something went wrong on our side — code "internal_error".

## Response `200`

- `data` (Event[], required) — The page of results, in the requested order.
- `has_more` (boolean, required) — True when more results exist after this page. Fetch them with next_cursor.
- `next_cursor` (string | null, required) — Pass this back as ?starting_after= to fetch the next page. Null when has_more is false. Opaque — do not parse it.

## Example

```bash
curl -X GET "https://your-site.awrora.app/api/v1/events" \
  -H "Authorization: Bearer $AWRORA_API_KEY"
```