Skip to content
v1.0.0

Scripts

Enabling scripts, writing a pre-request and a post-response script, and reading the script output. Narrated, with sound. The dark and light versions follow the site's theme.

A request can have a pre-request and a post-response JavaScript script, under Scripts beside Variables and Headers. They are off until you turn on Enable scripts for that tab. Opening a saved request that has scripts never enables them, and neither does importing a file, so you can read them first.

// pre-request: runs after {{variables}} are filled in, before the request is sent
gql.request.headers['authorization'] = 'Bearer ' + gql.env.get('token');
gql.request.variables.page = 2;
const r = await gql.fetch('https://auth.example.test/token', { method: 'POST', body: '{}' });
gql.env.set('token', r.json().token);
// post-response: runs once, after the first result (a subscription's first event)
gql.env.set('userId', gql.response.data.me.id);
console.log('stored', gql.env.get('userId'));

gql.response is { status, durationMs, headers, data, errors, extensions }.

{{variables}} are resolved first, then the pre-request script may edit the resolved gql.request.headers and gql.request.variables (headers must stay strings), then the request is validated and sent. A value stored with gql.env.set applies to the next request, not this one’s endpoint or fields. History keeps the request as typed, with its placeholders.

gql.env.set writes to the active environment (or the globals when none is active), keeps a variable’s secret flag, and shows up in Manage environments like a manual edit.

console.log, info, warn and error, and script errors with their line number, appear in a Script output block above the response. A script that throws or times out never blocks the run or hides the response.

  • 5 s per script. A runaway loop is stopped and the next run works.
  • 50,000 characters of source and 200 output lines.
  • At most 20 gql.fetch calls per script, each limited to 10 s, http(s) URLs only, a 5 MB response, and no cookies unless the tab’s Send cookies is on.
  • Only gql, console and the standard JavaScript built-ins exist: no window, DOM, chrome, storage or timers.

Scripts run in a Worker inside a sandboxed extension page with its own opaque origin, whose content security policy forbids every network request, so gql.fetch is the only way out. Scripts can’t read other tabs, collections, history or chrome.*.

Saving a request saves its scripts, and exporting a collection writes them as written, so remove any secrets first.