FAQ · Tools and setup

How do you set up an n8n webhook?

Add a Webhook node, match the HTTP method the sender uses, test with the test URL, then publish so the production URL runs. Here are the settings that matter, the mistakes that stop a webhook after launch, and when an n8n webhook is the right tool.

Key takeaways

  • Add a Webhook node as the first node, and match the sender's HTTP method.
  • Test with the test URL while listening; send the sender the production URL once the workflow is published.
  • Authenticate anything that carries personal or patient data; an IP allowlist returns 403 to other addresses.
  • The default payload limit is 16MB; self-hosted n8n can change it.

How do you set up an n8n webhook?

Add a Webhook node as the first node of a workflow, choose the HTTP method the sending system uses, copy the URL it gives you, and send a test event. Then publish the workflow so the production URL works without the editor open.

A webhook is how another system starts an n8n workflow: the other tool sends an HTTP request to a URL, and n8n runs the workflow with the data in that request. Setting it up correctly takes about ten minutes. Getting it to stay reliable takes the rest of this page.

Flow: sending system calls the webhook URL, the Webhook node starts the workflow, the steps run, and the Respond node returns a replyFlow: sending system calls the webhook URL, the Webhook node starts the workflow, the steps run, and the Respond node returns a reply Sending system Webhook node starts the run Your steps Respond Test URL: runs only while the editor listens Production URL: runs once the workflow is published
The webhook node is the trigger. The sending system calls its URL; the steps run; the response goes back to the sender.

What do you configure on the Webhook node?

Five settings matter: the HTTP method, the path, the response mode, authentication, and an optional IP allowlist. Set each one to match what the sending system does, not what is easiest to test.

  1. HTTP method. n8n accepts DELETE, GET, HEAD, PATCH, POST and PUT. Most form and booking tools send POST. Match the method the sender uses; a mismatch is one of the most common reasons nothing arrives.
  2. Path. Give it a descriptive name such as new-lead so you can tell webhooks apart in the executions list.
  3. Response mode. "Immediately" returns a short start message. "When Last Node Finishes" returns the last node's output. "Using 'Respond to Webhook' Node" lets you build the reply yourself. "Streaming response" sends output as it is produced, for compatible nodes. Pick the mode the sender expects: a form tool that waits for a 200 reply will time out or retry if the reply is slow.
  4. Authentication. Basic auth, header auth, JWT auth or none. Use header or JWT auth for anything that carries personal or patient data, and never leave a production webhook open to anyone who finds the URL.
  5. IP allowlist (optional). Enter the addresses the sender calls from. Requests from any other address get a 403 error, which also helps when you troubleshoot.

How do you test the webhook before it goes live?

Click "Listen for Test Event" in the editor, send a real request to the test URL, check that the fields arrived, then map them. Test with a record you can recognise, not a blank request.

The test URL shows incoming data in the editor, so you can see the exact fields the sender uses. Map each one to a step after the webhook. Then send a second test to confirm the mapping holds. Once the mapping is right, publish the workflow and switch the sender to the production URL. The production URL does not display data in the workflow canvas; check the Executions tab to see each run.

What breaks a webhook after it goes live?

Most failures are a changed field name, a sender that now uses a different method, an allowlist that no longer matches the sender, or a workflow that was never published.

  • Field names changed in the sender. The run succeeds but a later step gets empty values. Check the first execution after any change in the sending tool.
  • Wrong method. A GET where the sender posts (or the reverse) gets no run at all. Confirm it in the sender's logs.
  • Workflow not published. The production URL does nothing until you publish. The test URL works regardless, which is why a test can pass while the live system fails.
  • Retries creating duplicates. Many senders retry when they do not get a fast reply. Store the sender's record ID and skip records you have already processed.
  • Payload too large. The n8n webhook accepts up to 16MB by default. On a self-hosted instance the limit can be changed with the N8N_PAYLOAD_SIZE_MAX environment variable.

Is n8n's webhook the right choice for your flow?

Use an n8n webhook when the flow needs branching, retries, a custom API call or a longer chain of steps. For a single action between two apps, a native integration is often simpler.

An n8n webhook is a good fit when the data has to be reshaped, checked against another system, or sent to more than one place. Our n8n automation service builds and maintains these flows, including error alerts and logging. If you want to compare it with Zapier's version, read what a Zapier Catch Hook is, and n8n vs Zapier covers the trade-offs. For the setup side of your broader stack, see business process automation.

Sources and further reading

Screens and limits change between n8n versions. Check the current documentation on your instance before you rely on a limit here.

Want a webhook flow built and monitored?

Book a free 30-minute call. We map what each sender sends, build the webhook with authentication and error alerts, and hand over a list of every connection.

Get in touch

Tell us what you want to automate or build.

Send a few lines about your business and what is not working. We reply within one business day with next steps, or book a call if you would rather talk now.

  • Free 30-minute strategy call, no obligation
  • Written plan with scope and price before any build
  • Six months of maintenance included on every build
Alpit Patel
Alpit PatelFounder, Autoesta · HighLevel Certified Admin

With country code, so we can call you back.

We reply within one business day. Your details are used only to answer this enquiry. Privacy policy

Prefer to talk now? Book a free call

Book a Free Strategy Call