Home
The dependency-aware GraphQL API security testing tool
GraphQLer dynamically tests GraphQL APIs. It reads the schema through introspection, works out which queries and mutations depend on which objects, and then executes requests in dependency order — so a createPost runs before the updatePost that needs its ID. The objects returned along the way are reused in later requests and fed to a suite of security detectors.
Key features¶
-
Dependency awareness
Builds a dependency graph from the schema and runs queries and mutations in their natural order.
-
Request generation
Generates valid queries and mutations, including fragments, unions, interfaces and enums.
-
Resource tracking
An objects bucket keeps every object seen in responses for reuse and reconnaissance.
-
Vulnerability detection
Injection, DoS, information disclosure, IDOR and use-after-delete checks, each with a reproducible request log.
-
Optional LLM assistance
Infer dependencies, classify IDOR/UAF chains and write a vulnerability report with any
litellmmodel. -
CLI, TUI and MCP
Drive it from the command line, an interactive terminal UI, Python, or an AI assistant over MCP.
At a glance¶
pip install GraphQLer
python -m graphqler --mode run --url https://example.com/graphql --auth 'Bearer <TOKEN>'
GraphQLer works in two phases connected by files on disk:
flowchart LR
API[(GraphQL API)] -->|introspection| C[Compile]
C -->|schema YAML, dependency graph, chains| D[(Output directory)]
D --> F[Fuzz]
F -->|requests| API
F -->|stats, logs, detections| D
- Compile — introspect the schema, resolve dependencies, draw the dependency graph and generate fuzzing chains.
- Fuzz — execute the chains, track objects, run detectors and record results.
Demo¶
Citation¶
If you use GraphQLer in research, please cite the paper on arXiv or the software via CITATION.cff.