Skip to content
Halberd Security
Authorised testing only. We test only with the owner's written authorisation, so scope is agreed before testing begins. Unauthorised testing is also illegal under the Computer Fraud and Abuse Act.

Service

GraphQL penetration testing for APIs that expose a single endpoint

GraphQL penetration testing adapts API testing to one flexible endpoint. So it focuses on authorisation inside resolvers, schema exposure and limits on expensive queries.

  • Named tester before day one
  • One retest within 30 days
  • OWASP WSTG and NIST SP 800-115
Graphql penetration testing: map the schema, test authorisation and report and retest

Why GraphQL penetration testing differs from REST testing

A REST API spreads functions across many endpoints. In contrast, GraphQL puts them behind one, and clients choose the shape of each response. Therefore access checks must work field by field.

Teams often secure the endpoint but not each resolver. As a result, a user may request fields they should never see.

What GraphQL penetration testing examines

The test starts with the schema. Then it checks how each type and field is protected.

  • Authorisation in resolvers and nested fields
  • Schema exposure in production
  • Limits on query depth and cost
  • Input handling in mutations
  • Error messages that reveal internals

GraphQL penetration testing readiness check

Tick what you can provide.

Your result appears here as you tick, so you can see what is still open.

Scoping GraphQL penetration testing

Schema size and roles drive effort. However, other factors matter too.

QuestionEffect on scope
How many types and mutations?Larger schemas take longer
How many user roles?Each role multiplies checks
Federated or single service?Federation adds boundaries
Public or private API?Public exposure widens risk

Authorisation and safety

Testing runs only under your written authorisation. Also, mutations can change data, so a staging environment is preferred.

Findings come with evidence and a fix. Guidance such as the OWASP GraphQL Cheat Sheet helps engineers apply them.

Fees and timing

GraphQL work falls within our published API range of $10,000 to $25,000. One retest within 30 days is included, and a named tester is confirmed before day one.

Also consider how clients are built. Because mobile apps ship with queries inside them, an attacker can read those queries and adapt them. So treat every field as reachable, whatever the official client requests. In addition, log unusual query shapes, because they often signal probing before an attack.

GraphQL penetration testing questions

Is GraphQL penetration testing part of API testing?

Yes, with extra checks for resolvers, schema exposure and query limits.

Do we need to share the schema for GraphQL penetration testing?

It helps, because grey-box testing covers more within the same time.

What does GraphQL penetration testing cost?

It falls within our API range of $10,000 to $25,000, depending on scope.

Is a retest included?

Yes. One retest within 30 days is included.

Related guides

Scope your GraphQL penetration testing

Tell us about the schema, roles and environments. We reply with a written estimate, usually within four working hours.

Get my estimate