
Evolution API has a lot of settings, but only a handful decide whether the service is secure, whether it keeps its sessions and whether it accepts connections. This article says which ones and why. The exact names and allowed values change from version to version, so always check them against the example file and the project’s official documentation, and do not copy them from an old guide.
The ones you cannot leave undecided
| Setting | Why it matters |
The API key (AUTHENTICATION_API_KEY) |
It protects every request. Whoever has it sends messages from your number. Make it random and keep it in a password manager. |
| The database (PostgreSQL or MySQL) | Where instances and messages are kept. You pick the provider and give the connection address, user and password. They must match the database service in the compose file. |
| Redis | Many guides use it. If the example file includes it, the service must be able to reach it; if you drop it, switch it off in the same place and do not leave it half done. |
| The integration and its credentials | Baileys (QR) or the Cloud API. With the Cloud API the token and the rest of your Meta app details come in too, and they are secrets like the key. |
| The image version | Pick a specific version instead of always following the latest. That way you know what is running and can go back. |
| The volumes (in the compose file) | Not a setting, but they decide everything: without a persistent volume for the instances and the database, a restart wipes the sessions. |
Working with the settings file
|
|
|
|
| The settings file holds secrets. Never put it in a public repository, a screenshot or a support message. If the API key leaks, change it in the file, restart and update everything that uses it (n8n, your website, your scripts). |
Typical mistakes
| Mistake | Consequence |
| Leaving the example key in place | Anyone who reads the public documentation knows it. |
| Database password the same as the API key | One leak opens both doors. |
| No persistent volume | Sessions vanish at the first restart. |
| Always following the latest image | An automatic update can bring a Baileys version that will not connect. Pin the version and update when you decide to. |
| For what to change once the service is up, see securing Evolution API and Evolution API with PostgreSQL and Redis. If you need environment variables for your own application, see environment variables and secrets. |
|
Running Evolution API on a VPS and want more room for it? Have a look at the plans. See VPS servers |
|
SEE ALSO |
RECOMMENDED PRODUCT Web hosting with cPanel Domain and SSL included, daily backups and the panel you already know. from $6.59/mo (3-year plan, with coupon) See plans |
- 0 Users Found This Useful











