GET /api/query
Run a Cypher query from a URL parameter, for quick checks and pasteable links. Reference with code in five languages.
GET /api/query Documentation
GET /api/query runs the same query functionality as POST /api/query, with the Cypher passed as the q URL parameter. It is handy for quick checks and links you can paste into a browser.
GET is single-statement only: it takes no parameters object and does not run ;-separated batches. Use POST for anything real: it avoids URL-encoding the whole query, has no URL length limit, and carries parameters cleanly. Use GET for one-off reads and debugging.
The parameter is q, not query. A GET with no q, including one that sends ?query= instead, answers 400 missing-query-parameter.
Base URL: https://graph.whisper.security. Authentication is shared across the API and covered on the API Reference index.
Request
| Part | Value |
|---|---|
Query parameter q | The Cypher query, URL-encoded. Required. |
Query parameter timeout | Optional. Milliseconds to allow for this query; a value above what your access allows is lowered, not honored. |
Query parameter projectionFull | Optional, default false. Set true to include the reconciled threat-verdict properties in whole-node projections; see POST /api/query. |
X-API-Key header | Your API key. Sign in to get one. Without one the query runs with reduced access. |
User-Agent header | Recommended. Send a descriptive value that names your client. |
Call it
curl -s -A "whisper-client/1.0" \
-H "X-API-Key: $WHISPER_API_KEY" \
"https://graph.whisper.security/api/query?q=RETURN%201%20AS%20n"The response is the same envelope as POST:
{"columns": ["n"], "rows": [{"n": 1}], "statistics": {"rowCount": 1, "executionTimeMs": 0}}
Errors are the same application/problem+json documents as on POST, keyed on the type slug; see Errors. For the full request body, parameter binding, and batch statements, see POST /api/query. For graph-wide counts, see GET /api/query/stats.