Prev Next

API / Apollo Gateway Interview questions

How does Apollo Gateway handle authentication and authorization?

Gateway doesn't implement auth logic out of the box — that responsibility is typically split between the gateway layer and each subgraph.

A common pattern: the gateway validates or parses the incoming token (a JWT, say) via a custom data source, and forwards the relevant claims to subgraphs as headers on each outgoing request. This is done by overriding buildService to return a custom RemoteGraphQLDataSource subclass with a willSendRequest hook that attaches those headers.

Each subgraph then enforces its own field- and type-level authorization using those forwarded claims, since it best understands its own domain's access rules — the gateway generally isn't in a position to know, for example, exactly which fields on a Reviews type require moderator access.

Where does Apollo Gateway typically hand off actual authorization decisions?
What is a common mechanism for forwarding auth claims from Gateway to subgraphs?

More Related questions...

What is Apollo Gateway? What is GraphQL Federation? What is a subgraph in Apollo Federation? What is a supergraph in Apollo Federation? What is the difference between Apollo Server and Apollo Gateway? What is Apollo Federation 2? What are entities in Apollo Federation? What is the @key directive used for? What is schema composition in Apollo Federation? What is managed federation? What is Apollo Studio / GraphOS? What is Rover CLI used for? What is a query plan? What are the main directives used in Apollo Federation? What is the difference between Apollo Gateway and Apollo Router? Why do we use Apollo Federation instead of GraphQL schema stitching? How does Apollo Gateway compose a supergraph? How does the @external directive work? How does the @requires directive work? How does the @provides directive work? What is the difference between @shareable and @override? When should you use Apollo Router instead of Apollo Gateway? How do you configure Apollo Gateway with Apollo Server? What happens when a subgraph is unavailable at runtime? How does Apollo Gateway handle authentication and authorization? Why doesn't Apollo Gateway support GraphQL subscriptions as robustly as Apollo Router does? What is the difference between Federation 1 and Federation 2? How do you debug query planning issues in Apollo Gateway? What is the difference between IntrospectAndCompose and managed federation in Apollo Gateway? How can you optimize Apollo Gateway performance? Explain the lifecycle of a GraphQL request through Apollo Gateway? Explain the internal working of entity resolution using _entities and reference resolvers? What is the difference between a monolithic GraphQL server and a federated Apollo Gateway architecture? How does Apollo Gateway handle errors returned by subgraphs? What is the purpose of the _service and _entities fields in a federated subgraph schema? How do you implement custom middleware or plugins in Apollo Gateway? What are contract variants in GraphOS? How do you handle the N+1 query problem when a field spans multiple subgraphs? What is the difference between @override and @external for migrating fields? How does Apollo Gateway / Router handle caching? Explain the execution flow of a federated query spanning three subgraphs? Which is better and why: Apollo Router or Apollo Gateway, for a high-throughput production system? How do you secure inter-service communication between the gateway and subgraphs? What are Automatic Persisted Queries (APQ) and how do they work with Apollo Gateway? How do you handle versioning and backward compatibility of subgraph schemas? What is the difference between self-hosted Apollo Router and the GraphOS Router (cloud)? How do you troubleshoot composition errors when publishing a new subgraph schema? Explain the internal working of query plan caching? How can you implement rate limiting at the Apollo Gateway or Router level? What is the future direction of Apollo Gateway compared to Apollo Router?
Show more question and Answers...


Comments & Discussions