
An exposed Evolution API is an open door to your WhatsApp number: whoever reaches it and holds the key sends messages in your name. You protect it with four things: a strong, secret key, HTTPS in front, the right ports closed and nothing extra exposed (database, Redis). The order matters: do them before linking a number you care about.
Step by step
|
|
|
|
|
|
| Docker gets around many firewalls. When you publish a port, Docker edits the network rules itself, and an ordinary firewall may not hide it. Do not assume the port is closed: confirm it from outside, from another computer. See ports and firewall on a VPS. |
What each measure protects against
| Measure | Against what |
| A strong key | Anyone who guesses or finds the default one. |
| HTTPS | Anyone listening on the network between your server and whoever calls the API. |
| A local-only port | Anyone scanning the internet for open ports. |
| A closed database | Anyone trying to get straight at the data and the sessions. |
| A secret on the webhook | Anyone who finds your receiver’s address and invents messages. |
After installing
|
|
|
| The risk is not only technical. Whoever has the key has the number, and a number used to send junk to others is a banned number. For context, see the risks of WhatsApp for business. VPS security is yours, as the Support Policy explains. |
|
Want help choosing the server this will run on? Open a support ticket |
|
SEE ALSO |
RECOMMENDED PRODUCT Web hosting with cPanel Domain and SSL included, daily backups and the panel you already know. from $6.60/mo (3-year plan, with coupon) See plans |
- 0 Users Found This Useful











