GraphQL and REST: the key differences
REST builds an API around resources: each endpoint returns a fixed structure. GraphQL builds an API around data: the client describes the shape of the response inside the query.
# REST: GET /products/42 → returns all 50 fields
# GET /products/42/recommendations → a second request
# GraphQL: one request, only the fields needed
query {
product(id: "42") {
name
price
images { url }
recommendations(limit: 6) {
id
name
price
}
}
}
Important: GraphQL uses a single endpoint (
/graphql) for every query, which simplifies the API gateway but complicates HTTP caching — GET requests with a body are not cached by standard CDNs. The answer is persisted queries.
Strengths and limits
| Property | GraphQL | REST |
|---|---|---|
| Flexibility of the response | High — the client decides | Low — fixed by the server |
| Caching | Harder, needs persisted queries | Built-in HTTP caching |
| Learning curve | Steeper (schema, resolvers, typing) | Gentler |
| Suits | Complex frontends, mobile apps | Simple CRUD, webhooks |
| The N+1 problem | Present, needs DataLoader | Often absent |
GraphQL in headless e-commerce
Shopify, one of the largest platforms, moved its Storefront API to GraphQL as the primary interface. That means any headless store on Shopify talks to the catalogue, the basket and orders through GraphQL queries.
The typical architecture of a headless store with personalization:
Browser / app
↓ GraphQL
BFF (Next.js API routes)
↓ REST ↓ REST
Shopify API Personalization platform
The backend for frontend aggregates data from Shopify (the catalogue) and from the personalization platform (recommendations, the user’s segment), returning one response to the client through GraphQL.
Practical notes for e-commerce
Authorisation: GraphQL imposes no standard for authorisation — use HTTP headers exactly as you would with REST.
Rate limiting: harder in GraphQL, because one query can be cheap or expensive depending on its depth. Shopify, for instance, scores the cost of a query in abstract units by analysing the schema.
Documentation: GraphQL documents itself through the schema, which is a real advantage for teams integrating outside platforms.
Monitoring: standard application performance tools work with GraphQL, but for detailed analysis it is worth instrumenting individual resolvers rather than only total response time.