A Hacker's Guide to Shopify's GraphQL API (APAC)

Logo
Presented by

Jennifer Newton, Senior Application Security Engineer at Shopify

About this talk

Shopify uses GraphQL for both their developer-facing and undocumented APIs. They noticed that bugs in new functionality can go unreported. Learn how the team created the roadmap for researchers on how to effectively discover new functionality in Shopify APIs, and how they can get started testing it.
Related topics:

More from this channel

Upcoming talks (0)
On-demand talks (123)
Subscribers (11890)
HackerOne pinpoints the most critical security flaws across an organization’s attack surface with continual adversarial testing to outmatch cybercriminals. HackerOne’s Attack Resistance Platform blends the security expertise of ethical hackers with asset discovery, continuous assessment, and process enhancement to reduce threat exposure and empower organizations to transform their businesses with confidence. Customers include Citrix, Coinbase, Costa Coffee, General Motors, GitHub, Goldman Sachs, Hyatt, Microsoft, PayPal, Singapore’s Ministry of Defense, Slack, the U.S. Department of Defense, and Yahoo. In 2023, HackerOne was named a Best Workplace for Innovators by Fast Company.