All skills
apollographql avatar

/apollo-router

@f13ff34 official
by Apollo GraphQLapollographql/skills115 stars
13

Version-aware guide for configuring and running Apollo Router for federated GraphQL supergraphs. Generates correct YAML for both Router v1.x and v2.x. Use this skill when: (1) setting up Apollo Router to run a supergraph, (2) configuring routing, headers, or CORS, (3) implementing custom plugins (Rhai scripts or coprocessors), (4) configuring telemetry (tracing, metrics, logging), (5) troubleshooting Router performance or connectivity issues, (6) securing the graph with JWT, declarative field-level authorization directives, or persisted-query safelisting, (7) managing router.yaml as version-controlled config with CI/CD validation.

Use this Skill: https://skilld.dev/gh/apollographql/skills/apollo-router

This session only. Nothing lands on disk.

referencesheaders.md

≈1.2k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Header Configuration

Configure how the Router handles HTTP headers for requests to subgraphs and responses to clients.

Header Propagation

Pass headers from client requests to subgraph requests.

Propagate All Headers

headers:
  all:
    request:
      - propagate:
          matching: ".*"  # Regex pattern

Propagate Specific Headers

headers:
  all:
    request:
      # Propagate by exact name
      - propagate:
          named: Authorization

      # Propagate by pattern
      - propagate:
          matching: "^x-.*"  # All x-* headers

      # Rename while propagating
      - propagate:
          named: Authorization
          rename: X-Auth-Token

Per-Subgraph Headers

headers:
  # Default for all subgraphs
  all:
    request:
      - propagate:
          named: Authorization

  # Override for specific subgraph
  subgraphs:
    products:
      request:
        - propagate:
            named: Authorization
        - propagate:
            named: X-Products-Key

Inserting Headers

Add static or dynamic headers to subgraph requests.

Static Headers

headers:
  all:
    request:
      - insert:
          name: X-Router-Version
          value: "1.0"

      - insert:
          name: X-Api-Key
          value: ${env.API_KEY}  # From environment

Dynamic Headers from Context

headers:
  all:
    request:
      # Insert from request context
      - insert:
          name: X-Request-Id
          from_context: request_id

      # Insert from response context (for response headers)
      - insert:
          name: X-Trace-Id
          from_context: apollo_telemetry::trace_id

Removing Headers

Remove headers before sending to subgraphs or clients.

headers:
  all:
    request:
      # Remove specific header
      - remove:
          named: Cookie

      # Remove by pattern
      - remove:
          matching: "^x-internal-.*"

Response Headers

Configure headers sent back to clients.

headers:
  all:
    # Response headers to clients
    response:
      # Propagate from subgraph response
      - propagate:
          named: X-Cache-Status

      # Insert static header
      - insert:
          name: X-Powered-By
          value: "Apollo Router"

      # Remove sensitive headers
      - remove:
          named: X-Internal-Debug

Default Headers

Headers sent to subgraphs by default:

Header Description
Content-Type application/json
Accept application/json
apollographql-client-name Client name (if provided)
apollographql-client-version Client version (if provided)

Complete Example

headers:
  all:
    request:
      # Propagate auth
      - propagate:
          named: Authorization

      # Propagate custom headers
      - propagate:
          matching: "^x-custom-.*"

      # Add router metadata
      - insert:
          name: X-Router-Request-Id
          from_context: request_id

      # Remove cookies (not needed by subgraphs)
      - remove:
          named: Cookie

    response:
      # Add cache headers
      - insert:
          name: Cache-Control
          value: "private, max-age=60"

      # Propagate trace ID
      - propagate:
          named: X-Trace-Id

  subgraphs:
    products:
      request:
        # Additional header for products
        - insert:
            name: X-Products-Version
            value: "v2"

    legacy-service:
      request:
        # Rename header for legacy service
        - propagate:
            named: Authorization
            rename: X-Legacy-Auth

Header Order

Operations execute in order. Later operations can override earlier ones:

headers:
  all:
    request:
      # First: propagate all
      - propagate:
          matching: ".*"
      # Then: remove sensitive ones
      - remove:
          matching: "^x-internal-.*"
      # Finally: add new ones
      - insert:
          name: X-Router
          value: "true"

Environment Variable Expansion

headers:
  all:
    request:
      - insert:
          name: X-Api-Key
          value: ${env.API_KEY}

      - insert:
          name: X-Environment
          value: ${env.ENVIRONMENT:-development}  # With default

Common Patterns

Authentication Propagation

headers:
  all:
    request:
      - propagate:
          named: Authorization
      - propagate:
          named: Cookie

Request Tracing

headers:
  all:
    request:
      - propagate:
          named: X-Request-Id
      - propagate:
          named: X-Correlation-Id
      - insert:
          name: X-Router-Trace
          from_context: apollo_telemetry::trace_id

Multi-Tenant Headers

headers:
  all:
    request:
      - propagate:
          named: X-Tenant-Id
      - propagate:
          named: X-Organization-Id

Source: SKILL.md on GitHub

2 warnings16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill is a configuration generator and guide for Apollo Router. It implements robust security best practices by default, including environment variable interpolation for sensitive data, disabling developmental features (introspection/sandbox) in production, and providing a validation checklist. No malicious patterns, data exfiltration, or unauthorized command execution risks were found.

  • Socket16d

    1 alert: gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    26/26 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at f13ff34. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 4 months ago
What it can do
Runs commands
metadata
{
  "author": "apollographql",
  "version": "2.5.0"
}
All 1 allowed tools
Bash(router:*) Bash(./router:*) Bash(rover:*) Bash(curl:*) Bash(docker:*) Read Write Edit Glob Grep
Other metadata
compatibility
Linux/macOS/Windows. Requires a composed supergraph schema from Rover or GraphOS.
  • apollo-router
  • graphql
  • federation
  • routing
  • yaml
  • telemetry
  • authentication
  • cors

README badge

README badge for apollographql/skills/apollo-router

Generates version-aware Apollo Router configuration (v1.x or v2.x) for federated GraphQL supergraphs, handling routing, authentication, CORS, telemetry, and connectors. Use this skill to set up Router with JWT auth, traffic shaping, operation limits, or to troubleshoot connectivity and performance issues.

Generated from the current SKILL.md.

Does this skill support both Router v1 and v2?
Yes. The skill generates version-correct YAML for both v1.x and v2.x, which have incompatible config schemas. You must select your target version before generating any config.
Can I use this skill to configure Connectors?
Yes, but only for Router v2. Connectors (REST API integration) are a v2-only feature available in GA. The skill will not offer Connectors as an option if you select v1.
What do I need before I can run the generated config?
You need either a composed `supergraph.graphql` file from Rover or GraphOS access via `APOLLO_KEY` and `APOLLO_GRAPH_REF`. The skill assumes you have reachable subgraphs and will validate the config against the Router binary if available.
Does this skill help with response caching?
Yes, but only for Router v2.6.0 and later. The skill requires you to identify which subgraphs serve user-specific data and how you identify users before generating cache config, to prevent data leakage.
Will the skill validate my generated config?
Yes. After generating or editing config, the skill runs a checklist and attempts to validate against `router config validate` if the Router CLI is available. It will report pass/fail for each checklist item.

Generated from the current SKILL.md. These answers refresh after source changes.