Você registra um endpoint HTTPS (painel → Webhooks, ou POST /webhook-endpoints) e o Connect faz POST de um envelope versionado para cada evento. ⚠ O seu endpoint precisa aceitar POST com corpo JSON (n8n/Make/Zapier põem o trigger em GET por padrão — mude para POST). O envelope não é o payload cru da Meta: se a Meta mudar o formato, a sua integração não quebra. Headers de assinatura: X-Connect-Signature-256, X-Connect-Timestamp, X-Connect-Delivery-Id (esta entrega a este endpoint; mantém-se entre novas tentativas), X-Connect-Event. Deduplique pelo id do envelope (evt_…): é o mesmo em todas as novas tentativas e em todos os seus endpoints, e uma reentrega da Meta não gera outro. Numa mensagem, data.message.id (o id do WhatsApp) também serve.
O envelope que enviamos por POST ao seu endpoint
{
"id": "evt_7f3a1b2c9d4e5f6a7b8c9d0e1f2a3b4c",
"type": "message.received",
"version": "1",
"createdAt": "2026-08-06T00:31:22.461Z",
"connection": {
"id": "conn_4eede070e5a84d1590bdce2ea1d837bc",
"phoneNumber": "+5493510000000",
"externalId": "farmacia-lopez"
},
"sequence": 12345,
"data": {
"message": {
"id": "wamid.HBgL…",
"from": "5493511234567",
"type": "text",
"text": {
"body": "hola"
}
},
"contacts": [
{
"wa_id": "5493511234567",
"profile": {
"name": "Ana"
}
}
]
}
}Cabeçalhos
| Header | O que é |
|---|---|
X-Connect-Event | The event type (e.g. message.received) — branch on this. |
X-Connect-Delivery-Id | This delivery to this endpoint, stable across retries. To deduplicate events, use the envelope id (evt_…): a Meta re-delivery does not produce a new one. |
X-Connect-Timestamp | Unix seconds; part of the HMAC. Reject deliveries older than ~5 min. |
X-Connect-Signature-256 | sha256=HMAC(secret, timestamp + '.' + rawBody). Verify before trusting the body. |
X-Connect-Token | Optional static header (if you enabled one) — your tool's native Header Auth checks it. |
connection vem SEMPRE como objeto, mas os seus campos são null em eventos de alcance de conta (usage.threshold_reached) e em webhook.test.
Como AUTENTICAR a entrega (header estático vs assinatura): veja o módulo 'Autenticar o webhook'. Usa n8n? O workflow importável está em Integrações.