Get a Demo
Under Attack?
A surfboard with a GraphQL logo leans against a palm tree on a beach. The text Upwind GraphQL API Support appears against a blue sky backdrop, with waves and sandy shore in the background.

Extending our API Security Support for GraphQL Endpoints

<br />
<b>Warning</b>:  Undefined variable $photo in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>33</b><br />
<br />
<b>Warning</b>:  Trying to access array offset on value of type null in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>33</b><br />
Denise Ashur March 28, 2024

Extending our API Security Support for GraphQL Endpoints

We are excited to announce a significant new capability in our API Security tab, aimed at providing unprecedented visibility into GraphQL-based APIs.

GraphQL is an open-source data query and manipulation language for APIs, along with a runtime for executing queries. It’s a powerful alternative to REST that enables efficient and flexible data aggregation from multiple sources through a single HTTP endpoint. This approach simplifies data management, but also introduces unique API security challenges. 

API-catalog_-copy-1024x577

Traditional cloud security tools often treat GraphQL interactions monolithically, aggregating data across all queries into a single “GraphQL API.” This approach overlooks the detailed metrics from the query level— metrics that provide insights that are critical for effective API security.

With this extended support for GraphQL HTTP endpoints, Upwind provides the next level of visibility – now showing you not only GraphQL usage overall, but going deeper to provide visibility into individual queries, so you can understand and secure their usage as individual APIs. 

API-catalog_-1-1024x579

With Upwind’s GraphQL support you can:

  • See requests traffic over-time to GraphQL on an aggregate and per-query basis
  • View schema on a per-query level
  • Go beyond service communication to see the individual GraphQL query requests and responses 
API-catalog_-copy-2-e1711602168614-1024x580

This capability not only gives you increased visibility and context into GraphQL, it also allows you to rapidly identify abnormal API communication and proactively guard against threats or suspicious API communications. 

To learn more about Upwind’s API Security, visit the Upwind Documentation Center (login required) or send us a message at [email protected]

401 Authorization Required

401 Authorization Required


nginx
Contents

Further Reading

Superhuman AI

Security AI Needs an Honest Scoreboard: What It’s Superhuman At, and Where It Comes Up Short

If you follow AI at all, you know the leaderboards. Every few weeks a model takes the top spot, and we all check where our favorite landed. But a leaderboard only tells you who's ahead, and it stays quiet about where any of those models still come up short. Which, conveniently, is the part that…
Focus Mode

Find What Matters with Upwind Focus Mode

Focus Mode is now available in the Upwind platform, giving security teams a faster, more focused way to work. Instead of navigating across the platform, you can switch to Focus Mode to slice and dice the Upwind platform by Vulnerability Management, Cloud Security Posture, Attack Surface Management, Administration, or Threats, and starting next week, AI…
Early Advisories

Introducing Early Advisories: Turn Emerging Threats into Action

We’re excited to introduce Early Advisories as part of the Upwind platform. Powered by Upwind's security research team, Early Advisories notify customers about emerging threats, including zero-days and supply chain attacks, before they receive a CVE identifier. Early Advisories are published directly into the Vulnerabilities module alongside CVE-based findings and automatically correlated with your live…