Skip to content

Home

GraphQLer

The dependency-aware GraphQL API security testing tool

PyPI Docker python3.12 arXiv MIT License

GraphQLer dynamically tests GraphQL APIs. It reads the schema through introspection, works out which queries and mutations depend on which objects, and then executes requests in dependency order — so a createPost runs before the updatePost that needs its ID. The objects returned along the way are reused in later requests and fed to a suite of security detectors.

Get started View on GitHub

Key features

  • Dependency awareness


    Builds a dependency graph from the schema and runs queries and mutations in their natural order.

    Modes

  • Request generation


    Generates valid queries and mutations, including fragments, unions, interfaces and enums.

  • Resource tracking


    An objects bucket keeps every object seen in responses for reuse and reconnaissance.

    Output files

  • Vulnerability detection


    Injection, DoS, information disclosure, IDOR and use-after-delete checks, each with a reproducible request log.

    Detectors

  • Optional LLM assistance


    Infer dependencies, classify IDOR/UAF chains and write a vulnerability report with any litellm model.

    LLM features

  • CLI, TUI and MCP


    Drive it from the command line, an interactive terminal UI, Python, or an AI assistant over MCP.

    Interactive TUI

At a glance

pip install GraphQLer
python -m graphqler --mode run --url https://example.com/graphql --auth 'Bearer <TOKEN>'

GraphQLer works in two phases connected by files on disk:

flowchart LR
    API[(GraphQL API)] -->|introspection| C[Compile]
    C -->|schema YAML, dependency graph, chains| D[(Output directory)]
    D --> F[Fuzz]
    F -->|requests| API
    F -->|stats, logs, detections| D
  1. Compile — introspect the schema, resolve dependencies, draw the dependency graph and generate fuzzing chains.
  2. Fuzz — execute the chains, track objects, run detectors and record results.

Demo

Citation

If you use GraphQLer in research, please cite the paper on arXiv or the software via CITATION.cff.