Definition · Exposed Web Panels
What is GraphQL Introspection?
Introspection is part of the GraphQL specification. A client can send a query against the __schema and __type meta-fields and receive a machine-readable description of the entire API: types, fields, arguments, enum values, mutations and deprecation notes. It exists to support tooling — schema-aware editors, client code generation, documentation browsers and playground interfaces.
Why it matters when it is public
A GraphQL service exposes one endpoint, so an attacker cannot enumerate paths the way they would against a REST API. Introspection removes that obstacle entirely, replacing guesswork with a complete map — including internal-only mutations, administrative fields and types that the public client never touches. It turns API endpoint discovery from a search into a single request.
Related exposures travel with it. An interactive playground such as GraphiQL left reachable in production gives a query interface alongside the schema. Field suggestion messages — “Did you mean emailAddress?” — leak schema detail even when introspection is disabled, so both need turning off. Deeply nested and aliased queries also raise a denial-of-service concern that is independent of introspection, addressed with query depth and complexity limits.
Disabling it correctly
Disable introspection and field suggestions in production, remove the playground, and require authentication on the endpoint where the data warrants it. Internal developers keep the tooling by using a schema published through the build pipeline, or by enabling introspection only in non-production environments — which means those environments need their own protection, since a staging GraphQL host with introspection on describes the production schema just as well.
Note that introspection being disabled is not itself a security control for the underlying API. Authorisation must be enforced per field and per object; hiding the schema only slows discovery.
Related concepts
See API endpoint discovery, reconnaissance and security misconfiguration. The OWASP Top Ten and its API-specific companion list cover the authorisation failures introspection helps an attacker locate.