Skip to main content

Fast async GraphQL endpoint scanner

Project description

GraphRecon 🔎

GraphRecon is a fast, asynchronous GraphQL endpoint discovery tool.
It scans common and misconfigured API paths to identify exposed GraphQL endpoints.

Designed for:

  • Security researchers
  • Pentesters
  • Bug hunters

✨ Features

  • 🚀 Fully asynchronous (aiohttp + asyncio)
  • 🔍 Detects GraphQL via real GraphQL queries
  • 📍 Scans dozens of common GraphQL / API paths
  • 🧠 Prevents duplicate endpoint results
  • 🌐 Checks if the target is reachable
  • 🧪 Uses safe GraphQL payloads (__typename)
  • 📄 Optional GraphQL schema (introspection) fetching
  • ❓ Prompts the user before fetching schemas
  • 🧾 Lists discovered GraphQL types (Query / Mutation / Objects)
  • 📂 Bulk scanning from a target list file
  • 🎯 Clean and simple CLI usage

📦 Installation

pip (Windows, macOS, Linux)

pip install graphrecon

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

graphrecon-1.3.1.tar.gz (4.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

graphrecon-1.3.1-py3-none-any.whl (5.1 kB view details)

Uploaded Python 3

File details

Details for the file graphrecon-1.3.1.tar.gz.

File metadata

  • Download URL: graphrecon-1.3.1.tar.gz
  • Upload date:
  • Size: 4.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.11.7

File hashes

Hashes for graphrecon-1.3.1.tar.gz
Algorithm Hash digest
SHA256 8647cf7981ed7c4cfade0294ba5659b004f949ac96f8f77c5386a4a35151aae5
MD5 525f1b7e98fd1c3e5f897ec5d72847a8
BLAKE2b-256 5d9e810c85328318202e775335834181d99cb4c1d7a0e8ac2f97ceacb852e260

See more details on using hashes here.

File details

Details for the file graphrecon-1.3.1-py3-none-any.whl.

File metadata

  • Download URL: graphrecon-1.3.1-py3-none-any.whl
  • Upload date:
  • Size: 5.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.11.7

File hashes

Hashes for graphrecon-1.3.1-py3-none-any.whl
Algorithm Hash digest
SHA256 d3db5efe018f195f52c3789256a270676390c3b23c91eadae8143e71be7c6841
MD5 86425987da7492c559979c516e152c0e
BLAKE2b-256 d5916f1f707de51e4950715cbd47e35783e96876c73a6e079bd52dee1c851369

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page