Modes¶
GraphQLer's work is split into two phases, compilation and fuzzing, selected with --mode.
| Mode | Needs --url |
What it does |
|---|---|---|
compile |
yes | Introspection → parsing → dependency resolution → dependency graph → chains |
compile-graph |
yes | Compilation without chain generation |
compile-chains |
no | (Re-)generate chains from an already compiled graph |
fuzz |
yes | Execute compiled chains and run detectors |
run |
yes | compile then fuzz |
idor |
yes | Re-run only the IDOR chains |
single |
yes | Run one query or mutation |
Compile¶
Runs the full compilation pipeline: introspection → parsing → dependency resolution → dependency graph → fuzzing chains.
- Compiled schema files are written to
<SAVE_PATH>/compiled/. - A dependency graph image is written to
<SAVE_PATH>/dependency_graph.png. - Fuzzing chains are written to
<SAVE_PATH>/compiled/chains/.
These files are human-readable and can be edited before fuzzing. Any UNKNOWNS in the compiled YAML files can be marked manually; unmarked nodes are still fuzzed, just without a dependency chain.
To also generate IDOR candidate chains, pass a secondary token:
python -m graphqler --mode compile --url <URL> --path <SAVE_PATH> --idor-auth 'Bearer <SECONDARY_TOKEN>'
Compile-graph¶
Runs introspection, parsing and dependency resolution, then stops before chain generation. Use it to refresh the schema and graph, then run compile-chains separately.
Compile-chains¶
Regenerates chains under compiled/chains/ from the graph already on disk. No --url is required and no network requests are made — useful for trying --disable-mutations or other chain settings without hitting the API again.
Fuzz¶
Requires a compiled <SAVE_PATH>. While fuzzing, request counts are shown in the console. Results go to:
<SAVE_PATH>/stats.txtandstats.json— status codes, coverage and vulnerabilities<SAVE_PATH>/logs/fuzzer.log— every request and response<SAVE_PATH>/detections/— one folder per finding
If IDOR chains were generated during compile, they are executed automatically as part of fuzzing.
Run¶
Runs compile and then fuzz.
IDOR¶
python -m graphqler --mode compile --url <URL> --path <SAVE_PATH> --idor-auth 'Bearer <SECONDARY_TOKEN>'
python -m graphqler --mode fuzz --url <URL> --path <SAVE_PATH>
# Optional: re-run only the IDOR chains
python -m graphqler --mode idor --url <URL> --path <SAVE_PATH>
The idor mode re-executes only the IDOR chains, without regular fuzzing — handy for re-testing after a fix. See IDOR & UAF chains.
Single¶
Runs a single node. <NODE_NAME> must be a query or mutation name from the compiled schema.
Common options¶
| Option | Purpose |
|---|---|
--auth 'Bearer <TOKEN>' |
Primary Authorization header. Repeatable as profile=token for multiple profiles. |
--config <FILE> |
Use a specific TOML configuration |
--proxy http://127.0.0.1:8080 |
Send requests through Burp, ZAP, etc. |
--disable-mutations |
Only generate and run Query chains |
--subscriptions |
Also fuzz subscriptions over WebSocket |
--max-iterations N |
Sweep all chains N times |
The complete list is in the CLI reference.