GraphQLSAFE
Model Context Protocol server for GraphQL
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://smithery.ai/server/mcp-graphql)
A Model Context Protocol server that enables LLMs to interact with GraphQL APIs. This implementation provides schema introspection and query execution capabilities, allowing models to discover and use GraphQL APIs dynamically.
Usage
Run mcp-graphql with the correct endpoint, it will automatically try to introspect your queries.
Environment Variables (Breaking change in 1.0.0)
Note: As of version 1.0.0, command line arguments have been replaced with environment variables.
Examples
# Basic usage with a local GraphQL server
ENDPOINT=http://localhost:3000/graphql npx mcp-graphql
# Using with custom headers
ENDPOINT=https://api.example.com/graphql HEADERS='{"Authorization":"Bearer token123"}' npx mcp-graphql
# Enable mutation operations
ENDPOINT=http://localhost:3000/graphql ALLOW_MUTATIONS=true npx mcp-graphql
# Using a local schema file instead of introspection
ENDPOINT=http://localhost:3000/graphql SCHEMA=./schema.graphql npx mcp-graphql
# Using a schema file hosted at a URL
ENDPOINT=http://localhost:3000/graphql SCHEMA=https://example.com/schema.graphql npx mcp-graphqlResources
- graphql-schema: The server exposes the GraphQL schema as a resource that clients can access. This is either the local schema file, a sc
5d4522339e76OBSERVED · 2026-10-01Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mcp-graphql -- npx -y [email protected]
{
"mcpServers": {
"mcp-graphql": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (2)
2 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
introspect-schema | read | Introspect the GraphQL schema, use this tool before doing a query to get the schema information if you do not have it available as a resource already. |
query-graphql | read | Query a GraphQL endpoint with the given query and variables |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
readFileSync(join(__dirname, "../../package.json"), "utf-8"),
graphql, @graphql-tools/schema, @types/bun, biome, graphql-yoga
Gates applied: no_behavioural_pass.
5d4522339e76full audit observations/trust-audit/mcp-server/blurrah__graphql.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-01 | 5d4522339e76 | SAFE | B | 89 | first audit |
Questions
What is the GraphQL MCP server?
Model Context Protocol server for GraphQL
What tools does GraphQL expose?
2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is GraphQL safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does GraphQL need?
No credential environment variables were found in its source, so it appears to need none.
How does GraphQL run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-graphql at 2.0.4.
How current is this page?
The grade is for one exact copy of the source (5d4522339e76), read on 2026-10-01. The repository is watched and re-audited when it changes.