# HTTP API

> Query WhisperGraph over REST: POST read-only Cypher to graph.whisper.security/api/query and read one JSON envelope of columns, rows, and statistics.

*Source: https://www.whisper.security/docs/cypher-api*

---
The Whisper API is one HTTP endpoint. `POST` a read-only Cypher query as JSON to `https://graph.whisper.security/api/query` and you get back columns and rows. There is no SDK to install and no session to manage; curl, fetch, or any HTTP client works as is. If you would rather stay in a terminal, the [CLI](/docs/cli) sends the same request.

The same endpoint serves every request, and every runnable example in these docs goes through it. A `GET` variant and a `/api/query/stats` endpoint exist for quick checks and graph-wide counts. Every successful query answers with the same three fields — `columns`, `rows` and `statistics` — and every failed one with an `application/problem+json` body keyed on a stable `type` slug; the [API Reference](/docs/cypher-api/reference) and [Errors](/docs/cypher-api/errors) carry the detail.

![Diagram: a POST to graph.whisper.security/api/query carries Content-Type: application/json, an X-API-Key header and a JSON body with query and parameters. A success answers 200 with columns, rows and statistics (rowCount, executionTimeMs). A failure answers with an application/problem+json body: type, title, status, detail and suggestions, each suggestion carrying a runnable rewrite.](https://whisper.cdn.prismic.io/whisper/TU9rx1x5Col6ld9g_whisper-api-request.svg "What does one request carry, and what comes back?")

## Try it

One request end to end: resolve `google.com` to its IP addresses over the `RESOLVES_TO` edge. Running it here needs an account, so [sign in](https://console.whisper.security/sign-in?redirect_url=https%3A%2F%2Fwww.whisper.security%2Fdocs%2Fcypher-api).

```whisper-quickstart
{
  "cypher": "MATCH (h:HOSTNAME {name: \"google.com\"})-[:RESOLVES_TO]->(ip:IPV4) RETURN ip.name AS ip LIMIT 5",
  "prompt": "Which IP addresses does google.com resolve to right now?",
  "restNote": "The Raw tab shows the exact JSON envelope the API returns: columns, rows, and statistics."
}
```

## Authentication

Send your key in the `X-API-Key` header. A request with no key still runs, with reduced access, so confirm the key was accepted before you debug a query. The other accepted header formats and that check are in the [API Reference](/docs/cypher-api/reference#authentication); the response headers are on [Errors](/docs/cypher-api/errors).

## Where next

The query language itself — its clauses, its functions and the rules that keep a
query fast — is the [Cypher](/docs/cypher) chapter.
