

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
We are starting to see projects that use GraphQL APIs instead of SOAP or REST. Does WebInspect support scanning of GraphQL APIs? If so, any suggestions on how to configure the scan?
Thanks!
Accepted Solutions

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
@bn_pep Currently we do not support GraphQL in the same manner as SOAP or REST. Please contact support and request an Enhancement Request be opened. Our PM is interested in hearing about customers that are using GraphQL for user stories. You can open a support request via the Customer Portal - https://softwaresupport.softwaregrp.com/

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
@bn_pep Currently we do not support GraphQL in the same manner as SOAP or REST. Please contact support and request an Enhancement Request be opened. Our PM is interested in hearing about customers that are using GraphQL for user stories. You can open a support request via the Customer Portal - https://softwaresupport.softwaregrp.com/

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
This question came up in a customer call yesterday, and we passed the same request along to the PM JR.
Even without formal support today, there is an opportunity here if you can formulate your GraphQL queries in Postman. That way you could then take advantage of WebInspect's current Postman integration to operate the API effectively for scanning.
-- Habeas Data
Micro Focus Fortify Customers-Only Forums – https://community.softwaregrp.com/t5/Fortify/ct-p/fortify


- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
That's the approach I'm trying. I'm not too familiar with GraphQL, so I'm trying to get up to speed on it. If I can get a Postman collection working, then it will be easy to use it with WebInspect.