Migração 100% grátis na contratação semestral · nossa equipe migra tudo de qualquer provedor · novos clientes Migrar agora
Agente de IA no WhatsApp na API Oficial da Meta · somos Tech Provider aprovado · orçamento sob consulta Pedir orçamento
VPS com OpenClaw pré-instalado · a partir de R$ 56,90/mês · gerenciada pela Rollin Quero a VPS
VPS com Hermes Agent pré-instalado · a partir de R$ 56,90/mês · gerenciada pela Rollin Quero a VPS
Hospedagem com 30 dias de garantia · Não gostou? Devolvemos 100%, sem perguntas. Ver hospedagem

Webhooks in EvolutionAPI

How to configure and receive EvolutionAPI webhooks with retries, idempotency and production-grade security, with real payload examples.

EvolutionAPI sends events via HTTP POST webhook to a URL you define. The webhook is how your automation (n8n, your own API, etc.) knows that a message has arrived.

Available events

EventWhen it fires
MESSAGES_UPSERTMessage received or sent
MESSAGES_UPDATEStatus changed (delivered, read)
CONNECTION_UPDATEConnected/disconnected
PRESENCE_UPDATE”Typing…” / online
QRCODE_UPDATEDNew QR code for pairing

Configure the global webhook

Set it when you create the instance:

curl -X POST https://sua-evolution.rollinhost.com.br/instance/create \
  -H "Content-Type: application/json" \
  -H "apikey: SUA_API_KEY" \
  -d '{
    "instanceName": "atendimento",
    "qrcode": true,
    "webhook": {
      "url": "https://seu-n8n.exemplo.com/webhook/whats-in",
      "events": ["MESSAGES_UPSERT", "CONNECTION_UPDATE"],
      "webhook_by_events": false
    }
  }'

Payload structure

{
  "event": "messages.upsert",
  "instance": "atendimento",
  "data": {
    "key": {
      "remoteJid": "5511999999999@s.whatsapp.net",
      "fromMe": false,
      "id": "3EB0..."
    },
    "pushName": "João Silva",
    "message": {
      "conversation": "Oi, gostaria de saber sobre os planos"
    },
    "messageTimestamp": 1735689600
  }
}

Retries and idempotency

Best practices:

  1. Always return 200 quickly (< 5s) and process in a queue
  2. Idempotency by data.key.id: webhooks may arrive duplicated after a reconnection
  3. Persist the raw event before processing it (if there is a bug, you can reprocess)

Security

EvolutionAPI does not sign webhooks by default. To make sure the request came from it:

  • Restrict by IP in the firewall (only the Evolution server’s IP)
  • Use a URL with a secret path (/webhook/abc123-supersecreto)
  • Validate a custom apikey in the header (configure n8n to check it)

Next steps

Last updated: