What a webhook is, and how to test one with curl

A webhook is an address on the internet that receives a notice when something happens in another application. Instead of asking every minute “any news?”, the application knocks on your door and hands over the data. You can test any webhook with curl, a command-line program that makes HTTP requests.

How it works

Role Who What it does
Sender The application where the event happens (a shop, a form, a payment service). When something happens, it sends a request to an address you gave it, usually with the data as JSON.
Receiver Your program (n8n, a PHP file on your site, an application). Has a public address, reads the request and replies with a status code.
Reply The receiver. A code such as 200 says “got it”. Many senders try again if they do not get one.

Testing with curl, step by step

1 Have the webhook address. It has to be public and, normally, HTTPS. A localhost address will not do: the sender, out on the internet, cannot reach your computer.
2 A plain request, to see whether the address answers: curl -i https://n8n.asuaempresa.ao/webhook/your-path. The -i shows the status code and the reply headers.
3 A request with data, the way the sender would send it: curl -i -X POST https://n8n.asuaempresa.ao/webhook/your-path -H "Content-Type: application/json" -d '{"name":"test"}'.
4 Read the status code in the table below.
5 See whether the receiver logged the request. In n8n, in the executions list; in your own code, in the error log.

What the code means

Code Means
200 or 201 Received. If the rest fails, it fails inside the receiver.
301 or 302 The address redirects. Many senders do not follow redirects: use the final address.
401 or 403 Authentication is missing, or a firewall blocked it. See why your IP gets blocked.
404 That path does not exist. On an n8n, it is nearly always the test address out of use or the workflow inactive: n8n webhooks.
405 The method is wrong (GET instead of POST, or the other way round).
500 The receiver got it and fell over. Look at the error on its side. website errors explained.
502 or 504 A proxy in the middle could not reach the receiver, or it took too long.

With no reply at all, the problem is earlier: the domain name, the port or the firewall. See which ports are open.

An open webhook is an open door. Whoever knows the address can send you whatever they like. Always check who sent it (a secret in a header, a signature) before acting, and never trust the content as if it were your own. And be ready to get the same notice twice: senders repeat themselves.
You can receive webhooks on an ordinary website: a PHP file that reads the request body (php://input) and stores or handles it. For workflows across several applications n8n is more comfortable, on a VPS; see what n8n is. For Meta’s, webhooks from Meta.

Need a server with a public address to receive webhooks?

See the VPS servers

SEE ALSO

n8n webhooks: test URL and production URL

Receiving messages: Evolution API webhooks

Website errors explained: 500, 403, 404, 508 and what to do

RECOMMENDED PRODUCT

Web hosting with cPanel

Domain and SSL included, daily backups and the panel you already know. from $6.59/mo (3-year plan, with coupon)

See plans
  • 0 Users Found This Useful
Was this answer helpful?