FuturByte

Hire GraphQL developers

GraphQL lets clients ask for exactly the data they need, and hiring for it means testing whether someone has solved the performance and authorisation problems that creates.

What GraphQL actually is

GraphQL is a query language and runtime for APIs, originally from Meta and now governed by a foundation. Instead of a set of endpoints each returning a fixed shape, a GraphQL server exposes a typed schema and clients ask for precisely the fields they want in a single request. The response mirrors the query.

The problems it addresses are real. A client needing data from several REST endpoints makes several round trips, and an endpoint designed for one screen returns too much for another. GraphQL removes both, which matters most for mobile clients on slow connections and for front ends that evolve faster than the back end can produce new endpoints.

What it does not do is remove work; it relocates it. Flexibility given to the client becomes complexity on the server, because any combination of fields a client can request is a query the server must satisfy efficiently and authorise correctly. Teams that adopt it expecting simplification, rather than a different distribution of the same difficulty, are usually the ones that regret it.

The part that separates seniors from mid-levels

The N plus one problem is the defining performance issue, and it is structural rather than incidental. Resolvers run per field per object, so a query fetching a list and then a related field on each item naturally produces one query per item. The solution is batching, typically through a data loader that collects requests within a tick and issues one query. A candidate who does not mention this when asked about performance has not run GraphQL under real load.

Authorisation is the second area and the one that causes security problems. In REST, an endpoint is a natural place to put a permission check. In GraphQL there is one entry point and a graph the client traverses, so a field reachable by an unexpected path can leak data. Authorisation has to happen at the field or resolver level, consistently, and reasoning about what is reachable from where is genuinely harder than in an endpoint-based design.

The third is that clients can write expensive queries, deliberately or accidentally. A deeply nested query, or one requesting a large list with nested relations, can be far more costly than anything a REST endpoint would permit. Production servers need query depth limits, complexity analysis, and frequently persisted queries so that only known operations are allowed. Without these, the API's flexibility is also its denial-of-service surface.

Where GraphQL is used

The label “GraphQL developer” covers several jobs that share a technology and little else. These are the settings the work usually turns up in, and the one you are hiring into should shape the whole process, because the judgement each demands is different.

Mobile back ends

Where round trips are expensive and over-fetching costs the user data and battery, which is GraphQL's strongest case.

Aggregation layers

A single API in front of several internal services, presenting one coherent graph to clients.

Multi-client products

Web, mobile and partner clients with different data needs served from one schema.

Content delivery

Headless content management systems, where GraphQL has become a common query interface.

Commerce storefronts

Product and catalogue queries where clients need varying shapes of the same underlying data.

Internal platform APIs

Federated graphs across an organisation, which is a substantial engineering commitment in its own right.

If a candidate's experience sits in a different row of that list from the work you have, that is not a reason to reject them, but it is the thing to probe. Ask what would be different about their approach in your setting. Someone who can answer that has transferable judgement. Someone who says it would be much the same has probably not thought about it.

Support status of the tools in this stack

GraphQL is a specification rather than a product, so what matters is the maturity of the server implementation and client tooling a team uses rather than a version of the language itself.

GraphQL itself is not versioned as a single product, so the useful equivalent is the support status of the tools a GraphQL developer works with daily. The table is read from public release data rather than written by hand, so it states what is supported now. It is worth having in front of you during an interview: asking which of these a candidate has upgraded, and what broke, gets you further than asking how many years they have used each.

Release and support status across the GraphQL toolchain
ToolLatest releaseRelease dateMaintained linesFurthest end-of-life date
Node.js26.10.02026-09-2262029-04-30
React19.3.02026-09-09none publishednone published
PostgreSQL18.62026-08-1152030-11-14
Redis8.10.22026-09-1752030-09-01
Kubernetes1.37.12026-09-2342027-10-28
Next.js16.3.62026-09-2212026-10-21

Source: endoflife.date public release data, read 2026-09-25. A tool with no published end-of-life dates sets its support boundary by ecosystem practice rather than by policy.

The practical use of this is in judging an estate rather than a person. A team running several of these past their support dates is usually not behind by accident; it is behind because upgrades were never anyone's job. That is worth knowing before you hire, because it tells you whether the first six months will be building new things or paying down what was deferred.

The toolchain around it

Nobody hires for GraphQL alone. The surrounding tools are where most of the day-to-day work happens, and a gap in any of them costs more time than a gap in the core library. This is the set that turns up most often on real job specifications alongside it.

A schema-first workflow
The schema as the contract between teams, versioned and reviewed.
Apollo Server, GraphQL Yoga or a language equivalent
The server implementation.
DataLoader or equivalent batching
The standard answer to the N plus one problem. Effectively mandatory.
Apollo Client, urql or Relay
Client-side caching and query management.
Code generation
Types generated from the schema for both client and server, which is much of the practical benefit.
Query depth and complexity limits
Protection against expensive queries, required in any public-facing deployment.
Persisted queries
Allowing only known operations, which also improves caching and reduces payload size.
Tracing per resolver
Field-level performance visibility, since a slow query can be one slow field.

Related skills that frequently appear on the same specification: Node.js, React, Next.js, TypeScript, React Native.

What to test in an interview

These are the topics that separate candidates in practice. Each one is given with why it discriminates, what a strong answer sounds like, and the response that should make you slow down. None of them requires a whiteboard.

The N plus one problem

The defining performance characteristic. Anyone who has run GraphQL seriously has met it.

Authorisation design

Where GraphQL creates genuine security risk relative to REST.

Protecting against expensive queries

An API that lets clients compose queries needs limits.

Error handling

GraphQL returns partial data with errors, which clients frequently mishandle.

Caching

GraphQL loses the HTTP caching that REST gets free, and this surprises people.

Schema design and evolution

The schema is a long-lived contract.

When REST would be better

Tests judgement rather than advocacy.

Warning signs in a GraphQL codebase

The fastest way to read a candidate is to ask what they have found wrong in code they inherited. These are the patterns that come up most often, what they cost, and what fixing them looks like. A developer who recognises three or four of these from their own experience is worth more than one who can recite the documentation.

No batching

Authorisation at the entry point only

Unlimited query complexity

Schema mirroring the database

Ignoring partial errors

Adopting GraphQL for a single client

What each level can own

Job titles are not comparable between companies, so it is more useful to describe levels by what a person can be left to own without supervision. These are the boundaries we use when we assess a GraphQL developer.

Junior
Writes resolvers and queries in an existing schema. Needs review on batching and authorisation.
Mid-level
Owns a domain of the schema including its resolvers, batching and permissions. Can diagnose a slow query to the field.
Senior
Owns schema architecture, the authorisation model, performance and abuse protection, and the client caching strategy.
Staff
Owns the graph across teams, federation if used, schema governance and the decision about whether GraphQL remains justified.

How the work is usually scoped

Team shape follows the kind of work, not the headcount you happen to have budget for. These are the shapes that come up most often and the constraint that actually governs each one.

GraphQL layer over existing services

Schema design for a new product

Performance remediation

Authorisation review

Federation adoption

Migration work you may actually be hiring for

A large share of GraphQL work is not new development. It is moving an existing system from one state to another while it stays in service. These are the migrations that come up most often, and each one asks for a different kind of experience from the person you hire.

REST to GraphQL

Resolvers without batching to data loaders

An ad hoc graph to a governed schema

A single graph to federation

Migration work rewards a different temperament from greenfield work. The useful question in an interview is not whether someone has done the specific migration you face, but whether they have ever run one incrementally: behind a flag, with both paths live, and with a way back. Developers who have only done big-bang cutovers tend to propose them again.

What a good brief for this role contains

Most of the time lost in hiring a GraphQL developer is lost before anyone is interviewed, in the gap between what the brief says and what the team actually needs. These are the points that, for this technology specifically, change who the right candidate is. A brief that answers them can be matched in days. One that does not produces a shortlist that looks reasonable and converts badly.

If you cannot answer some of these yet, that is normal and it is still worth writing down which ones are open. An unknown that is named can be worked around. An unknown that is papered over in a job specification turns into a rejected shortlist and a restart four weeks later.

What the US market pays for this work

GraphQL work is counted by the US Bureau of Labor Statistics under Software Developers. That classification is broader than the technology itself, so treat the figures as the shape of the market a GraphQL developer is hired into rather than as a rate card for the skill. Across the United States the Bureau counts 1,687,890 people in this occupation, with a median annual wage of $135,980.

US annual wages, Software Developers, May 2025
US annual wages, Software Developers, May 2025$135,980Median$82,460$214,67010th pct90th pctMiddle half $105K to $172K

The spread matters more than the midpoint. The 90th percentile is about 2.6 times the 10th, which is a wide band for a single occupation and tells you that the title on its own carries very little pricing information. Two people described as a GraphQL developer can sit at $82,460 and $214,670 in the same national dataset. When a budget is set from a median without asking which end of that range the work actually needs, the hire that follows is usually the wrong one in one direction or the other.

Related classifications are worth reading alongside it, because teams hiring for GraphQL frequently end up recruiting against these titles too:

US national wages, May 2025
OccupationEmployed25th percentileMedian75th percentile90th percentile
Software Developers1,687,890$105,210$135,980$171,980$214,670
Web Developers70,190$64,230$92,650$126,230$162,290

Source: BLS Occupational Employment and Wage Statistics, May 2025. Figures cover all US employers and are not FuturByte rates.

These are employer-side wage figures for people on a US payroll. They exclude employer taxes, benefits, recruitment cost and the months a seat sits empty, all of which are real and none of which appear in a salary line. The useful way to read the table is as the cost of the alternative you are comparing against, not as a number to match.

How US metro markets compare for this role

The same job is priced very differently across the country. Ranked by median annual wage for Software Developers, the gap between the highest and lowest of the 28 metro areas covered here is a factor of about 1.7. San Jose sits at the top with a median of $213,110; Pittsburgh sits at the bottom with $124,500. A budget built from a national median will be wrong in both of those markets, in opposite directions.

Median wage for software developers, by US metro area
Median wage for software developers, by US metro areaSan Jose, CA: $213,110San Jose, CASan Jose, CA$213,110San Francisco, CA: $186,640San Francisco, CASan Francisco, CA$186,640Seattle, WA: $167,280Seattle, WASeattle, WA$167,280New York, NY: $166,830New York, NYNew York, NY$166,830Boston, MA: $166,090Boston, MABoston, MA$166,090San Diego, CA: $163,270San Diego, CASan Diego, CA$163,270Los Angeles, CA: $160,920Los Angeles, CALos Angeles, CA$160,920Portland, OR: $156,000Portland, ORPortland, OR$156,000Washington, D.C.: $154,930Washington, D.C.Washington, D.C.$154,930Baltimore, MD: $138,900Baltimore, MDBaltimore, MD$138,900Denver, CO: $137,610Denver, CODenver, CO$137,610Charlotte, NC: $135,920Charlotte, NCCharlotte, NC$135,920Chicago, IL: $134,380Chicago, ILChicago, IL$134,380Austin, TX: $134,120Austin, TXAustin, TX$134,120Dallas-Fort Worth, TX: $133,290Dallas-Fort Worth, TXDallas-Fort Worth, TX$133,290Philadelphia, PA: $133,040Philadelphia, PAPhiladelphia, PA$133,040Atlanta, GA: $132,960Atlanta, GAAtlanta, GA$132,960Raleigh, NC: $132,770Raleigh, NCRaleigh, NC$132,770Miami, FL: $132,650Miami, FLMiami, FL$132,650Phoenix, AZ: $131,750Phoenix, AZPhoenix, AZ$131,750Minneapolis-St. Paul, MN: $130,920Minneapolis-St. Paul, MNMinneapolis-St. Paul, MN$130,920Detroit, MI: $130,760Detroit, MIDetroit, MI$130,760Tampa, FL: $130,450Tampa, FLTampa, FL$130,450Orlando, FL: $129,620Orlando, FLOrlando, FL$129,620Salt Lake City, UT: $129,600Salt Lake City, UTSalt Lake City, UT$129,600Houston, TX: $129,440Houston, TXHouston, TX$129,440Kansas City, MO: $124,990Kansas City, MOKansas City, MO$124,990Pittsburgh, PA: $124,500Pittsburgh, PAPittsburgh, PA$124,500
Software Developers by metro area, May 2025, ranked by median wage
Metro areaEmployedMedian wagevs US medianLocation quotient
San Jose, CA87,350$213,110+57%7.09
San Francisco, CA69,030$186,640+37%2.68
Seattle, WA92,770$167,280+23%4.10
New York, NY121,000$166,830+23%1.17
Boston, MA42,310$166,090+22%1.44
San Diego, CA20,610$163,270+20%1.23
Los Angeles, CA55,540$160,920+18%0.82
Portland, OR18,260$156,000+15%1.39
Washington, D.C.69,060$154,930+14%2.03
Baltimore, MD16,850$138,900+2%1.14
Denver, CO27,010$137,610+1%1.55
Charlotte, NC20,820$135,9200%1.41
Chicago, IL40,370$134,380-1%0.82
Austin, TX31,960$134,120-1%2.28
Dallas-Fort Worth, TX67,030$133,290-2%1.52
Philadelphia, PA28,480$133,040-2%0.91
Atlanta, GA36,300$132,960-2%1.16
Raleigh, NC12,580$132,770-2%1.56
Miami, FL18,900$132,650-2%0.62
Phoenix, AZ29,380$131,750-3%1.14
Minneapolis-St. Paul, MN27,410$130,920-4%1.29
Detroit, MI24,870$130,760-4%1.20
Tampa, FL14,230$130,450-4%0.91
Orlando, FL13,440$129,620-5%0.88
Salt Lake City, UT19,040$129,600-5%2.12
Houston, TX22,940$129,440-5%0.64
Kansas City, MO12,160$124,990-8%1.02
Pittsburgh, PA10,320$124,500-8%0.85

Location quotient compares how concentrated this occupation is in the metro against the national average. A value above 1 means the metro has more of this work than its size would predict.

The location quotient column is the more useful one for hiring. A high median tells you what a role costs; a high quotient tells you whether the people exist. San Jose, San Francisco, Seattle, Washington, D.C., Denver, Austin each have a quotient of 1.5 or above, meaning the work is concentrated there well beyond what the size of the local economy would predict. Those are the markets where a search is likely to be quick and competitive at the same time, and where a counter-offer is most likely to take a candidate off the table late in the process.

The opposite case is worth planning for too. In a metro with a low quotient, the total pool is small even when wages look reasonable, so the realistic options are to widen the search radius, accept a longer time to hire, or bring the capability in from outside the local market entirely. That last option is what most teams are weighing when they come to us.

Hiring risks worth naming

Every one of these has produced a bad hire somewhere. They are written down so that the process tests for them deliberately rather than discovering them in month three.

Client experience presented as server experience. Writing queries is not building a server. The hard parts are entirely on the server side.

No production load experience. Ask about the N plus one problem. Anyone who has run GraphQL at scale will answer immediately.

Weak authorisation thinking. The area where GraphQL creates real risk relative to REST, and where the failures have been public.

Adopting it without needing it. Ask when REST would be better. Someone with no answer may build complexity you gain nothing from.

Hiring GraphQL developers by metro area

Wages for this occupation vary more between US metro areas than most budget models assume. Each page below sets out the published employment and wage figures for that market, how it compares with the national picture, and what the local industry mix means for the kind of GraphQL developer who will be available.

Frequently asked questions

Should we use GraphQL or REST?

GraphQL when several clients with different data needs consume the same data, when round trips are expensive as on mobile, or when your front end evolves faster than your back end can add endpoints. REST when you have one client with stable needs, because it is simpler, caches naturally over HTTP, and has fewer ways to go wrong. Adopting GraphQL for a single web front end is a common way to buy complexity without the benefit.

Does GraphQL make our API faster?

It reduces round trips, which genuinely helps on high-latency connections. It does not make the server faster, and a naively implemented GraphQL server is usually slower than the REST endpoints it replaced because of the N plus one problem. The performance benefit is real on the client side and has to be earned on the server side.

Is GraphQL less secure than REST?

It is not inherently less secure and it is easier to get wrong. A single entry point exposing a traversable graph means authorisation must be applied consistently at field level, and a field reachable by an unexpected path can leak data. Combined with the need for query complexity limits, it asks more of the implementation than REST does.

Why is our GraphQL API slow?

Almost certainly the N plus one problem: resolvers issuing a database query per item rather than batching. Field-level tracing shows it immediately. The fix is a data loader, and the fact that it was not there from the beginning is the more interesting finding.

How do we cache GraphQL?

Not the way you cache REST, which surprises teams. Queries typically go over POST to one endpoint, so HTTP caching does not apply. The answers are normalised client-side caching, persisted queries that make requests cacheable, and server-side caching at the data layer rather than the response layer.

Should we adopt federation?

Only with several teams owning parts of one graph and a genuine need for a unified API across them. It is a substantial organisational and technical commitment, with its own tooling, governance and failure modes. For a single team it adds complexity with no benefit, and it is frequently adopted aspirationally.

Can clients write queries that break our server?

Yes, and that is the main thing to design against on a public endpoint. A deeply nested or broad query can be extremely expensive. Depth limits, complexity scoring and, where the clients are yours, persisted queries that allow only known operations are the standard protections and should be in place before launch rather than after an incident.

Do we need GraphQL-specific developers?

Less than you might expect. A strong back-end developer learns the server side quickly, and the genuinely hard parts, namely data access performance, authorisation and abuse protection, are ordinary back-end skills applied to a different shape. Test those rather than testing GraphQL familiarity.