All skills
apollographql avatar

/rover

@9ccc6ed official
by Apollo GraphQLapollographql/skills115 stars
13

Guide for using Apollo Rover CLI to manage GraphQL schemas and federation. Use this skill when: (1) publishing or fetching subgraph/graph schemas, (2) composing supergraph schemas locally or via GraphOS, (3) running local supergraph development with rover dev, (4) validating schemas with check and lint commands, (5) configuring Rover authentication and environment, (6) exploring or searching a graph's schema for agent-driven discovery (rover schema describe / rover schema search).

Use this Skill: https://skilld.dev/gh/apollographql/skills/rover

This session only. Nothing lands on disk.

referencesconfiguration.md

≈1.4k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Rover Configuration

Installation, authentication, and environment configuration for Apollo Rover CLI.

Installation

macOS and Linux

# Install latest version
curl -sSL https://rover.apollo.dev/nix/latest | sh

# Install specific version
curl -sSL https://rover.apollo.dev/nix/v0.26.0 | sh

# Add to PATH (if not automatic)
export PATH="$HOME/.rover/bin:$PATH"

npm (Cross-platform)

# Global install
npm install -g @apollo/rover

# Project-local install
npm install --save-dev @apollo/rover
npx rover --version

Windows PowerShell

# Install latest
iwr 'https://rover.apollo.dev/win/latest' | iex

# Install specific version
iwr 'https://rover.apollo.dev/win/v0.26.0' | iex

Verify Installation

rover --version
rover --help

Authentication

Interactive Authentication

# Opens browser for authentication
rover config auth

Process:

  1. Browser opens to GraphOS Studio
  2. Log in or create account
  3. Authorize Rover
  4. Token saved to config file

API Key Authentication

# Set via environment variable (recommended for CI/CD)
export APOLLO_KEY=your-api-key

# Or configure directly
rover config auth --api-key your-api-key

Verify Authentication

# Check current authentication
rover config whoami

Output:

Authenticated as: user@example.com
Organization: My Org
API Key Type: User

Environment Variables

Core Variables

Variable Description Example
APOLLO_KEY API key for GraphOS user:gh.xxx:yyy
APOLLO_GRAPH_REF Default graph reference my-graph@production

Using Environment Variables

# Set in shell
export APOLLO_KEY=your-api-key
export APOLLO_GRAPH_REF=my-graph@production

# Use in commands
rover subgraph fetch $APOLLO_GRAPH_REF --name products

# Or commands auto-detect APOLLO_GRAPH_REF
rover subgraph fetch --name products

CI/CD Environment

# GitHub Actions
env:
  APOLLO_KEY: ${{ secrets.APOLLO_KEY }}
  APOLLO_GRAPH_REF: my-graph@production

steps:
  - run: rover subgraph check $APOLLO_GRAPH_REF --name products --schema ./schema.graphql
# CircleCI
environment:
  APOLLO_KEY: ${APOLLO_KEY}
  APOLLO_GRAPH_REF: my-graph@production

Configuration File

Rover stores configuration in ~/.rover/config.toml.

Location

# View config path
rover config list

# macOS/Linux: ~/.rover/config.toml
# Windows: %USERPROFILE%\.rover\config.toml

Structure

[profiles.default]
api_key = "user:gh.xxx:yyy"

[profiles.staging]
api_key = "user:gh.xxx:zzz"

Profiles

Use profiles for different environments or accounts.

Create Profile

# Create/update profile
rover config auth --profile staging

Use Profile

# Specify profile for command
rover subgraph fetch my-graph@staging --name products --profile staging

List Profiles

rover config list

Output Formats

Plain Text (Default)

rover subgraph fetch my-graph@production --name products

Output: Raw SDL schema

JSON

rover subgraph fetch my-graph@production --name products --format json

Output:

{
  "data": {
    "sdl": "type Product { ... }",
    "name": "products"
  },
  "error": null
}

Using with jq

# Extract just the SDL
rover subgraph fetch my-graph@production --name products --format json | jq -r '.data.sdl'

# Check for errors
rover subgraph check my-graph@production --name products --schema ./schema.graphql --format json | jq '.error'

Logging

Log Levels

# Increase verbosity
rover --log debug subgraph fetch my-graph@production --name products

# Available levels: error, warn, info, debug, trace

Environment Variable

export APOLLO_TELEMETRY_DISABLED=1  # Disable telemetry
export ROVER_LOG=debug              # Set log level

Telemetry

Rover collects anonymous usage data by default.

Disable Telemetry

export APOLLO_TELEMETRY_DISABLED=1

What's Collected

  • Command names (not arguments or schemas)
  • Rover version
  • OS type
  • Anonymous usage patterns

Proxy Configuration

HTTP Proxy

export HTTP_PROXY=http://proxy.example.com:8080
export HTTPS_PROXY=http://proxy.example.com:8080

No Proxy

export NO_PROXY=localhost,127.0.0.1,.internal.example.com

SSL/TLS Configuration

Custom CA Certificate

# Set CA bundle
export SSL_CERT_FILE=/path/to/ca-bundle.crt

# Or for curl-based operations
export CURL_CA_BUNDLE=/path/to/ca-bundle.crt

Disable SSL Verification (Not Recommended)

# For development only
export ROVER_SKIP_SSL_VALIDATION=1

Updating Rover

Check for Updates

rover update check

Update to Latest

# npm
npm update -g @apollo/rover

# curl (reinstall)
curl -sSL https://rover.apollo.dev/nix/latest | sh

Uninstalling

npm

npm uninstall -g @apollo/rover

Manual Installation

# Remove binary
rm -rf ~/.rover

# Remove from PATH (in .bashrc/.zshrc)
# Remove: export PATH="$HOME/.rover/bin:$PATH"

Troubleshooting

Authentication Issues

# Clear and re-authenticate
rm ~/.rover/config.toml
rover config auth

Network Issues

# Test connectivity
curl -I https://api.apollographql.com

# Check DNS
nslookup api.apollographql.com

Permission Issues

# Fix permissions (macOS/Linux)
chmod +x ~/.rover/bin/rover

Version Conflicts

# Check installed location
which rover

# Ensure correct version
rover --version

Source: SKILL.md on GitHub

1 alert16d5 checks · Risk HIGH
  • Gen Agent Trust Hub16d

    This skill provides a comprehensive guide for the Apollo Rover CLI. It contains installation instructions that involve downloading and executing remote scripts from Apollo's official domain. While these are remote code execution patterns, they are standard for this recognized vendor. The skill is susceptible to indirect prompt injection because it processes external GraphQL schema data without explicit boundary markers or sanitization.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: MEDIUM · 1 issue

  • Runlayer7mo

    6/6 files flagged

  • ZeroLeaks5mo

    1 finding · Score: 82/100

Signed by skilld at 9ccc6ed. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
What it can do
Runs commands
compatibility
Node.js v18+, Linux/macOS/Windows
metadata
{
  "author": "apollographql",
  "version": "1.1.2"
}
All 1 allowed tools
Bash(rover:*) Bash(npm:*) Bash(npx:*) Read Write Edit Glob Grep
  • CLI
  • graphql
  • apollo
  • rover
  • federation
  • schema
  • supergraph
  • graphos
  • subgraph

README badge

README badge for apollographql/skills/rover

Manages GraphQL schemas and federation via the Apollo Rover CLI, including publishing subgraphs, composing supergraphs, and validating schemas with check and lint commands. Designed for local schema exploration via piped commands (rover schema describe/search) and GraphOS integration workflows, with built-in support for federated and monograph architectures.

Generated from the current SKILL.md.

Does Rover work with both federated and non-federated GraphQL graphs?
Yes. Use `rover subgraph` commands for federated graphs and `rover graph` commands for monographs (non-federated graphs). Both workflows are supported.
How do I explore a large GraphQL schema without loading the entire SDL into context?
Pipe `rover graph fetch` into `rover schema describe` or `rover schema search` — these commands read the schema via stdin and return only a compact overview or search results, keeping context manageable.
What's the difference between `rover graph fetch` and `rover supergraph fetch`?
`rover graph fetch` returns the API schema (what you can query), while `rover supergraph fetch` returns the composed supergraph SDL with federation internals like `join__` and `link__`. Use the former for schema exploration and the latter for composition/router work.
Can Rover execute GraphQL queries, or does it only manage schemas?
Rover only manages and inspects schemas. To run a generated query, you must send it to the graph's endpoint separately using curl or another HTTP client.
Does this skill require a GraphOS account, or can I use Rover offline?
Most Rover commands (publish, fetch, check) require authentication with a GraphOS API key. Local composition with `rover supergraph compose` and schema exploration of local files work offline.

Generated from the current SKILL.md. These answers refresh after source changes.