A principled approach to GraphQL query cost analysis
Alan Cha, Erik Wittern, Guillaume Baudart, James C. Davis, Louis Mandel, Jim Alain Laredo
Abstract
The landscape of web APIs is evolving to meet new client requirements and to facilitate how providers fulfill them. A recent web API model is GraphQL, which is both a query language and a runtime. Using GraphQL, client queries express the data they want to retrieve or mutate, and servers respond with exactly those data or changes. GraphQL's expressiveness is risky for service providers because clients can succinctly request stupendous amounts of data, and responding to overly complex queries can be costly or disrupt service availability. Recent empirical work has shown that many service providers are at risk. Using traditional API management methods is not sufficient, and practitioners lack principled means of estimating and measuring the cost of the GraphQL queries they receive.
In this work, we present a linear-time GraphQL query analysis that can measure the cost of a query without executing it. Our approach can be applied in a separate API management layer and used with arbitrary GraphQL backends. In contrast to existing static approaches, our analysis supports common GraphQL conventions that affect query cost, and our analysis is provably correct based on our formal specification of GraphQL semantics.
We demonstrate the potential of our approach using a novel GraphQL query-response corpus for two commercial GraphQL APIs. Our query analysis consistently obtains upper cost bounds, tight enough relative to the true response sizes to be actionable for service providers. In contrast, existing static GraphQL query analyses exhibit over-estimates and under-estimates because they fail to support GraphQL conventions.
• Security and privacy → Denial-of-service attacks; • Software and its engineering → Domain specific languages.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e2b43522-6ce1-409e-8da2-1b95e1eeaa53Cited by top-tier papers4
- Exploiting Input Sanitization for Regex Denial of ServiceEfe Barlas, Xin Du, James C. DavisICSE 2022 · 16 citations
- GraphQLify: Automated and Type Safety-Preserving GraphQL API AdoptionSaleh Amareen, Arif Rahman, Sazzadur Rahaman, Amiangshu BosuFSE 2026
- Improving Developers' Understanding of Regex Denial of Service Tools through Anti-Patterns and Fix StrategiesSk Adnan Hassan, Zainab Aamir, Dongyoon Lee, James C. Davis et al.S&P 2023
- ORFA: Exploring WebAssembly as a Turing Complete Query Language for Web APIsYuhao Gu, Chunyu Chen, Jiangsu Du, Xiaoxi Zhang et al.WWW 2025
Related papers
- GQL and SQL/PGQ: Theoretical Models and Expressive PowerAmélie Gheerbrant, Leonid Libkin, Liat Peterfreund, Alexandra RogovaVLDB 2025 · 16 citations
- Skyler: Static Analysis for Predicting API-Driven Costs in Serverless ApplicationsBernardo Ribeiro, Mafalda Ferreira, José Fragoso Santos, Rodrigo Bruno et al.ASPLOS 2026
- Flexible and Expressive Typed Path Patterns for GQLWenjia Ye, Matías Toro, Tomás Díaz, Bruno C. d. S. Oliveira et al.OOPSLA 2025 · 1 citation
- Detecting locations in JavaScript programs affected by breaking library changesAnders Møller, Benjamin Barslev Nielsen, Martin Toldam TorpOOPSLA 2020 · 32 citations
- Adaptive Text2GQL: Integrating Structural Twig Linking and Evolutionary In-Context LearningFang Niu, Chaokun Wang, Hang Zhang, Songyao WangACL 2026
