Grade your GraphQL schema's security posture

Paste the JSON result of an introspection query (data.__schema or bare __schema) — or, best-effort, exported SDL text. graphqlcheck statically checks it against the OWASP GraphQL Cheat Sheet and OWASP API Security Top 10: introspection exposure, sensitive field names, high-impact mutations, recursive-type depth risk, unpaginated list complexity, stale deprecations, and auth-directive presence.

Paste-only — this tool never sends a request to any GraphQL endpoint. It only reads the text you paste below, entirely in your browser.

Load example:

graphqlcheck

Grade a GraphQL schema's security posture

by IntegrAuth