We want our payment provider API tokens to only have the required privileges. We should document how to create these tokens with least privileges for each payment provider. NOTE: Webhook events are easily interpretable through code, API token privileges not so much.