Supported by Curity Logotype

Session

query { __schema }: Everything You Wanted to Know About Hacking GraphQL (But Didn’t Know How To Query)

Heard about GraphQL but not sure how to approach its security? This talk breaks down everything you need to get started with GraphQL hacking. We’ll cover the essentials: understanding GraphQL’s core concepts, identifying vulnerabilities unique to its flexible nature (like information disclosure via introspection), and exploring how attackers abuse its power. Discover how modern AI tools can act as your hacking co-pilot, assisting in finding flaws even if you’re new to the game. We’ll bust the myth that GraphQL is inherently more secure and show you practical ways to test these APIs. This is your beginner’s guide, designed to empower you to confidently start exploring GraphQL vulnerabilities.

Smarter Tech Decisions Using APIs

Smarter Tech Decisions Using APIs

API blog

High impact blog posts and eBooks on API business models, and tech advice

API conferences

Connect with market leading platform creators at our events

API community

Join a helpful community of API practitioners

API Insights Straight to Your Inbox!

Can't make it to the event? Signup to the Nordic APIs newsletter for quality content. High impact blog posts on API business models and tech advice.

By clicking below, you agree that we process your information per the terms in our Privacy Policy.

Ranked #1 API blog on the web

Ranked #1 API blog on the web

Join Our Thriving Community

Become a part of our global community of API practitioners and enthusiasts. Share your insights on the blog, speak at an event or exhibit at our conferences and create new business relationships with decision makers and top influencers responsible for API solutions.