GraphQL security

In GraphQL the client decides the shape and depth of every query, which moves a lot of control from the server to the caller.

That is the point of it and it means the server cannot predict cost. A single query can request deeply nested relationships that expand into an enormous amount of work. Depth limits, complexity analysis and cost budgets are not optional extras here; they are what replaces the constraint a fixed endpoint provided.

Checked against the primary source.

More on API security