A Model Context Protocol (MCP) server for exposing GraphQL APIs as tools to AI agents. Provides introspection, schema searching, operation execution, and validation capabilities for GraphQL schemas.
Apollo MCP Server provides 4 tools for GraphQL introspection and execution. Tool naming follows the action-verb pattern (introspect, search, validate, execute) which is good. However, critical gaps exist: (1) Tool descriptions are present but generic and lack actionable context about when to use each tool vs alternatives; (2) No visible input/output schemas in the provided source code, cannot verify parameter types, constraints, or response structures; (3) No evidence of parameter descriptions or constraints; (4) The 'execute' tool is destructive (WRITE risk) but descriptions do not explicitly state mutation consequences or require confirmation patterns; (5) Error handling strategy is not visible in the provided source.
Execute a GraphQL operation against a configured GraphQL endpoint.
Introspect a GraphQL schema to retrieve its type definitions, fields, arguments, and other metadata.
Search a GraphQL schema for types, fields, and operations matching a query pattern.
Validate a GraphQL operation against the schema.
No input/output schemas visible in source code. Cannot verify parameter types, constraints, or response structures for any tool. Per HARD SCORING RULES, schema score must be 0 when not visible.
Tool descriptions lack actionable context. Descriptions are generic and do not explain WHEN to use each tool vs alternatives, WHAT parameters are required, or WHAT the response structure is. Example: 'Search a GraphQL schema for types, fields, and operations matching a query pattern' does not specify query format, return structure, or pagination.
'execute' tool is marked as WRITE (destructive) but description does not explicitly warn about mutations, irreversible consequences, or side effects. Per pattern:command-tool, destructive tools must state 'This modifies state' and consider confirmation patterns.
Inferred effective spec: 2025-06-18+.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 43 | 2025-06-18+ | v2 |
| 2026-03-09 | F | 33 | - | v1 |
No evidence of parameter descriptions or type constraints in source. LLMs cannot infer what 'schema' parameter in 'introspect' expects, what 'query' parameter in 'search' accepts, or what 'operation' parameter in 'validate' should contain.
No pagination or result-limiting strategy visible. For tools like 'introspect' and 'search' on large schemas, unbounded results could exceed context windows. No 'limit', 'offset', 'page', or 'total_count' fields evident.
No error handling guidance visible. If 'execute' fails to connect to a GraphQL endpoint or 'validate' rejects an operation, the response strategy is unclear, does it guide LLM recovery? Return raw server errors? Classify as retryable vs fatal?