Grade your GraphQL schema's security posture
Paste the JSON result of an introspection query (data.__schema or bare __schema) — or, best-effort, exported SDL text. graphqlcheck statically checks it
against the OWASP GraphQL Cheat Sheet and OWASP API Security Top 10: introspection exposure,
sensitive field names, high-impact mutations, recursive-type depth risk, unpaginated list
complexity, stale deprecations, and auth-directive presence.
Paste-only — this tool never sends a request to any GraphQL endpoint. It only reads the text you paste below, entirely in your browser.
Load example: