Awesome Lists

awesome-graphql-security

by Escape-Technologies

awesome listpushed over 2 years ago

A curated list of awesome GraphQL Security frameworks, libraries, software and resources

AI summary

API security toolkit

A curated list of security frameworks and tools for protecting GraphQL APIs

stars
305
forks
22
watching
10
awesome list
1
entries
45
View on GitHub

Embed the badge

Show how many awesome lists link to your project. The count updates automatically.

Awesome Lists badge
Markdown
[![Awesome Lists Badge](https://awesome.facts.dev/shield/Escape-Technologies/awesome-graphql-security/links.svg)](https://awesome.facts.dev/awesome/Escape-Technologies/awesome-graphql-security)
HTML
<a href="https://awesome.facts.dev/awesome/Escape-Technologies/awesome-graphql-security"><img src="https://awesome.facts.dev/shield/Escape-Technologies/awesome-graphql-security/links.svg" alt="Awesome Lists Badge" /></a>
Image URL
https://awesome.facts.dev/shield/Escape-Technologies/awesome-graphql-security/links.svg

What's in the list

45 links in 13 sections, with live GitHub stats.activeno commit in 2y

Defensive Security / Authentication & Authorization

  • GraphQL Shield

    GraphQL Shield helps you create a permission layer for your application

  • GraphQL Authz

    GraphQL authorization layer

Defensive Security / Continous Security Testing

  • Escape - GraphQL Security

    Continuous GraphQL Security Testing for Developers. Find and fix GraphQL security flaws in the CI/CD

  • GraphQL Cop

    Utility to run common security tests against GraphQL APIs that can be run inside CI/CD

Defensive Security / Middlewares

  • GraphQL Armor

    Highly customizable security middleware for Apollo GraphQL and Envelop servers

Defensive Security / Security Solutions

Neutral Security / Clients and IDEs

  • Postman

    Postman is an API platform for developers to design, build, test and iterate their APIs

  • Insomnia

    Design and test GraphQL APIs with ease

  • Altair

    GraphQL Client helps you debug GraphQL queries and implementations. Also distributed as a Browser Extension

  • Hoppscotch

    Online REST and GraphQL client

Neutral Security / Self-Discovery

  • GraphMan

    Generate a complete Postman collection from a GraphQL endpoint. Allows instant and easy discovery and exploration of the API

Neutral Security / Visualizers

  • GraphQL Visualizer

    Visualize GraphQL schema

  • Voyager

    Represent any GraphQL API as an interactive graph

  • GraphQL Inspector

    – Validate schema, get schema change notifications, validate operations, find breaking changes, look for similar types, schema coverage

  • GraphQL Rover

    GraphQL schema viewer for endpoints with introspection

  • CraftQL

    CLI GraphQL schema viewer, view schema diagram on the terminal or generate graphviz .dot format file

Offensive Security / Discovery

  • Graphinder

    Blazing fast GraphQL endpoints finder using subdomain enumeration, scripts analysis and bruteforce

  • Graphw00f

    GraphQL Server Engine Fingerprinting utility

  • Clairvoyance

    Patrial introspection fetcher when introspection is disabled

  • GraphQL Path Enum

    – Tool that lists the different ways of reaching a given type in a GraphQL schema

  • ShapeShifter

    Schema extraction to JSON file with introspection

  • Goctopus

    a GraphQL endpoint discovery and fingerprinting tool

Offensive Security / Exploitation

  • GraphCrawler

    A GraphQL automated security toolkit. Grab introspection, search for sensitive queries, and then test authorization

  • CrackQL

    GraphQL password brute-force and fuzzing utility

  • GraphQLMap

    A scripting engine to interact with a GraphQL endpoint for pentesting purposes

  • GraphQL.Security

    One-click quick security scan of your GraphQL endpoints. Free, no login required

  • GraphQL Threat Matrix

    GraphQL threat framework to research security gaps in GraphQL implementations

  • InQL

    A Burp Extension for GraphQL Security Testing

  • BatchQL

    GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations

  • GraphQL wordlist

    the only GraphQL wordlist for pentesting you'll ever need. Operations, field names, type names. It was collected on more than 60k distinct GraphQL schemas

Offensive Security / Vulnerable Applications

  • Damn Vulnerable GraphQL Application

    Damn Vulnerable GraphQL Application is an intentionally vulnerable implementation of Facebook's GraphQL technology, to learn and practice GraphQL Security

Resources / Academy

  • API Security Academy

    Hands-on learning about GraphQL. Each lesson is built around a WebContainer containing a live GraphQL application, so you'll not only understand why a vulnerability is risky, but also how to exploit it and, most importantly, how to fix it

Resources / Blogs

Resources / Vulnerabilities

More related projects

Add a GitHub project

Missing a project or an awesome list? Paste its GitHub URL and we fetch it right away.