A surfboard with a GraphQL logo leans against a palm tree on a beach. The text Upwind GraphQL API Support appears against a blue sky backdrop, with waves and sandy shore in the background.

Extending our API Security Support for GraphQL Endpoints

Denise Ashur March 28, 2024

Extending our API Security Support for GraphQL Endpoints

We are excited to announce a significant new capability in our API Security tab, aimed at providing unprecedented visibility into GraphQL-based APIs.

GraphQL is an open-source data query and manipulation language for APIs, along with a runtime for executing queries. It’s a powerful alternative to REST that enables efficient and flexible data aggregation from multiple sources through a single HTTP endpoint. This approach simplifies data management, but also introduces unique API security challenges. 

API-catalog_-copy-1024x577

Traditional cloud security tools often treat GraphQL interactions monolithically, aggregating data across all queries into a single “GraphQL API.” This approach overlooks the detailed metrics from the query level— metrics that provide insights that are critical for effective API security.

With this extended support for GraphQL HTTP endpoints, Upwind provides the next level of visibility – now showing you not only GraphQL usage overall, but going deeper to provide visibility into individual queries, so you can understand and secure their usage as individual APIs. 

API-catalog_-1-1024x579

With Upwind’s GraphQL support you can:

  • See requests traffic over-time to GraphQL on an aggregate and per-query basis
  • View schema on a per-query level
  • Go beyond service communication to see the individual GraphQL query requests and responses 
API-catalog_-copy-2-e1711602168614-1024x580

This capability not only gives you increased visibility and context into GraphQL, it also allows you to rapidly identify abnormal API communication and proactively guard against threats or suspicious API communications. 

To learn more about Upwind’s API Security, visit the Upwind Documentation Center (login required) or send us a message at [email protected]

Contents

Further Reading

Upwind-Sentinel

Upwind for Microsoft Sentinel – Available on Marketplace and Security Store

Security teams should not have to switch between tools to understand what is happening across their cloud environments. That’s why we’re excited to announce that the Upwind solution for Microsoft Sentinel is now available through the Microsoft Marketplace and the Microsoft Security Store. The integration brings Upwind security data directly into Microsoft Sentinel, helping security…
You Can't Crowdsource Your Way to a Live Adversary

You Can’t Crowdsource Your Way to a Live Adversary

Bug bounty programs were built on a single assumption: that finding a vulnerability was the hard, scarce, expensive part worth paying for. That assumption held for about a decade, then AI erased it. When anyone can point a model at your code and receive a plausible-looking finding back in seconds, a crowd of finders stops…
arrayref Supply Chain Attack

arrayref Supply Chain Attack: A One-Line Build Dependency Ran a Backdoor During cargo build

Key Takeaways Executive Summary arrayref 0.3.10 is a hijacked release of a widely used Rust utility crate that added one dependency, proc-macro1, whose build script downloaded and executed a remote binary at compile time. The release was live on crates.io for 86 minutes on August 20, 2026, alongside [email protected] and [email protected] published from the same…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS