Skip to main content

Fast async GraphQL endpoint scanner

Project description

GraphRecon 🔎

GraphRecon is a fast, asynchronous GraphQL endpoint discovery tool.
It scans common and misconfigured API paths to identify exposed GraphQL endpoints.

Designed for:

  • Security researchers
  • Pentesters
  • Bug hunters

✨ Features

  • 🚀 Fully asynchronous (aiohttp + asyncio)
  • 🔍 Detects GraphQL via real GraphQL queries
  • 📍 Scans dozens of common GraphQL / API paths
  • 🧠 Prevents duplicate endpoint results
  • 🌐 Checks if the target is reachable
  • 🧪 Uses safe GraphQL payloads (__typename)
  • 📄 Optional GraphQL schema (introspection) fetching
  • Prompts the user before fetching schemas
  • 🧾 Lists discovered GraphQL types (Query / Mutation / Objects)
  • 🎯 Clean and simple CLI usage

📦 Installation

pip (Windows, macOS, Linux)

pip install graphrecon

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

graphrecon-1.2.1.tar.gz (4.5 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

graphrecon-1.2.1-py3-none-any.whl (4.8 kB view details)

Uploaded Python 3

File details

Details for the file graphrecon-1.2.1.tar.gz.

File metadata

  • Download URL: graphrecon-1.2.1.tar.gz
  • Upload date:
  • Size: 4.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.11.7

File hashes

Hashes for graphrecon-1.2.1.tar.gz
Algorithm Hash digest
SHA256 bb1755e4038f3c83e782f8b73c496825ff882085552fabddcf126a83322c72dc
MD5 867517cd3198cd95d2b57be77668293b
BLAKE2b-256 173db3cec3c06dbd8fe92e3b195bbfe474366c1f62c9889df2de03533993760e

See more details on using hashes here.

File details

Details for the file graphrecon-1.2.1-py3-none-any.whl.

File metadata

  • Download URL: graphrecon-1.2.1-py3-none-any.whl
  • Upload date:
  • Size: 4.8 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.11.7

File hashes

Hashes for graphrecon-1.2.1-py3-none-any.whl
Algorithm Hash digest
SHA256 bda9bd848b38ed6e77cef7a7f86c0d5bd4c998b3bfaf1e9c553a33ed30d65592
MD5 57aade68ec08def68b7908f8392c3222
BLAKE2b-256 258a7de8bddcfcef18fdb6fd07e977fc508f4ada42132b4199bb6bbcde208967

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page