The GraphQL connector is a Palantir-provided driver for GraphQL.
To create a new GraphQL source, follow the standard setup flow for Palantir-provided drivers, then use the sections below for GraphQL-specific configuration and networking. For the complete property reference, see the official GraphQL driver documentation ↗.
| Capability | Status |
|---|---|
| Exploration | 🟢 Generally available |
| Batch syncs | 🟢 Generally available |
| Incremental | 🟢 Generally available |
| OAuth 2.0 authentication | 🟢 Generally available |
| Table exports | 🟢 Generally available |
The properties below are mandatory or recommended.
| Property | Required? | Description | Default |
|---|---|---|---|
URL ↗ | Mandatory | Specifies the endpoint URL of the GraphQL service. | https://api.example.com/graphql |
AuthScheme ↗ | Recommended | Specifies the authentication method to use when connecting to remote services. | Basic |
InitiateOAuth ↗ | Recommended | Specifies the process for obtaining or refreshing the OAuth access token, which maintains user access while an authenticated, authorized user is working. | REFRESH |
OAuthClientId ↗ | Recommended | Specifies the client ID (also known as the consumer key) assigned to your custom OAuth application. This ID is required to identify the application to the OAuth authorization server during authentication. | — |
OAuthClientSecret ↗ | Recommended | Specifies the client secret assigned to your custom OAuth application. This confidential value is used to authenticate the application to the OAuth authorization server. | — |
Password ↗ | Recommended | Specifies the password of the authenticating user account. | — |
User ↗ | Recommended | Specifies the user ID of the authenticating GraphQL user account. | — |
The table below lists the domains that the source must be able to access to run.
For each domain, add a corresponding egress policy. If the source is hosted on-premises and not directly reachable from Foundry, use an agent proxy egress policy instead. The agent host itself must also be able to reach the listed domains. See using an agent as a proxy for details.
| Domain | Required |
|---|---|
| <URL> | Always |
| <OAuthRequestTokenURL> | If using AuthScheme=OAuth and OAuthVersion=1.0 |
| <OAuthAuthorizationURL> | If using AuthScheme=OAuth |
| <OAuthAccessTokenURL> | If using AuthScheme=OAuth |
| <OAuthRefreshTokenURL> | If using AuthScheme=OAuth and OAuthVersion=2.0 |
| cognito-idp.<AWSCognitoRegion>.amazonaws.<TLD> | If AuthScheme=AwsCognitoBasic,AwsCognitoSrp, AWSRegion Mappings |
| cognito-identity.<AWSCognitoRegion>.amazonaws.<TLD> | If AuthScheme=AwsCognitoBasic,AwsCognitoSrp, AWSRegion Mappings |
This connector supports OAuth 2.0 authentication. Follow the OAuth 2.0 guidance for Palantir-provided drivers to configure and authorize the connection.
This connector supports table exports. Learn how to set up a table export.