All tools

Web Application

GraphQLmap / InQL / graphql-cop

Tooling for GraphQL introspection, query fuzzing, and misconfig checks.

intermediate
Linux
Enumeration
Exploitation

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

When

Target exposes GraphQL endpoint.

How

Try introspection; map schema; test authz on mutations/queries.

Why

GraphQL introduces unique authz and DoS issues.

Commands & usage

graphqlmap -u https://example.com/graphql
graphql-cop -t https://example.com/graphql

Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.

Tags

graphql
api

Related in Web Application