GraphQL Query Validator
Check a GraphQL query before sending it. Without a schema, the validator checks syntax and document rules such as unused fragments, undefined variables and duplicate operation names. Paste a schema, as SDL or an introspection result, and it runs the full validation of the GraphQL specification: unknown fields and arguments, missing required arguments, wrong fragment types, and variables whose values do not match their declared types.
- Runs in your browser
- No sign-up
- Free to use
How to use GraphQL Query Validator
- Paste the query, mutation or subscription.
- Optionally paste the schema (SDL or introspection JSON).
- Optionally add the variables as JSON.
- Read the problems, each with its line and column.
GraphQL Query Validator features
Reference validation
graphql-js, the reference implementation, runs every specification rule.
Two schema formats
SDL type definitions or an introspection query result.
Variables
Checks that variable values match their declared types.
Schema-free checks
Syntax, fragments and variables even without a schema.
Query metrics
Operations, fragments, field count and nesting depth.
Local
Nothing is sent to your GraphQL server or ours.
When to use GraphQL Query Validator
- Finding the typo behind “Cannot query field … on type …” errors.
- Checking queries in a pull request against the current schema.
- Verifying variables before calling a production API.
- Spotting overly deep queries that a server might reject.
GraphQL Query Validator FAQ
How do I get the schema?
Many projects keep a schema.graphql file. Otherwise, run the standard introspection query against the server (if introspection is enabled) and paste the JSON result.
What is checked without a schema?
Syntax, unique operation and fragment names, unknown and unused fragments, fragment cycles, undefined and unused variables and duplicate arguments.
What does validation with a schema add?
Every field, argument, type condition and directive is checked against the schema, along with required arguments, leaf selections and type compatibility.
Are variables sent anywhere?
No. Variables are only checked against the declared types in your browser; no request is made.
Why warn about depth?
Deeply nested queries can be expensive, and many servers reject queries beyond a depth limit. The validator reports the depth so you can see it early.
Is this the same validation my server uses?
Servers built on graphql-js, such as Apollo Server and GraphQL Yoga, use the same rules. Other implementations follow the same specification but may add their own limits.
How GraphQL validation works
A GraphQL server processes a request in three stages: parsing the document, validating it against the schema, and executing it. Validation is defined precisely by the GraphQL specification as a set of rules, and a request that breaks any of them is rejected before any resolver runs. Running the same rules locally shows the errors before the request is sent, with exact positions.
Some rules only concern the document itself. Operation names must be unique, an anonymous operation must be the only one, every fragment that is spread must exist and every defined fragment must be used, fragments cannot spread each other in a cycle, and every variable used must be declared and every declared variable used. These checks need no schema and run as soon as you paste a query.
The schema adds the rules developers run into most. Every field must exist on the type it is selected from, arguments must exist and required ones must be present, objects must have sub-selections while scalars cannot, fragment type conditions must be possible, and argument and variable types must be compatible. Error messages from graphql-js include suggestions, such as “Did you mean email?”, for likely typos.
Variables are validated separately at execution time. The validator coerces the variables you provide against each operation’s declared types, so a string passed where an Int is expected, or a missing non-null variable, is reported just as a server would report it.
The schema can be pasted as SDL or as the JSON result of an introspection query, which is what tools such as GraphiQL and Apollo use to learn a schema. Everything runs in your browser with the bundled reference implementation; no request is sent to any GraphQL server.