Disable GraphQL introspection
exposed-graphql
Introspection publishes every type, query and mutation your API supports. Turn it off in production so your schema is not a public document.
Why this matters
Your GraphQL endpoint has introspection enabled. The full schema is visible — reconnaissance data that maps your API but is not directly exploitable.
Frameworks
Express
- 1 Disable introspection in production
javascript
// Apollo Server
const server = new ApolloServer({
typeDefs,
resolvers,
introspection: process.env.NODE_ENV !== 'production',
});Does your app still have this?
Scan your domain