GraphQL Security Research Material
GraphQL Security Toolkit

With the increasing popularity of GraphQL technology, we will be using this repository to publish scripts and other resources that can facilitate security testing efforts.

GraphQL Official Logo

GraphQL Introspection

A tool to query a GraphQL endpoint with introspection in order to retrieve queries & mutations

Author: Paolo Stagno (@Void_Sec)

Usage: $python -t -o report.html

The resulting HTML page will contain details for available queries and mutations, as shown here: