# @envelop/operation-field-permissions

Latest version **9.2.1** (published 2026-09-16) · MIT license · 0 weekly downloads

## Install

```sh
npm install @envelop/operation-field-permissions
pnpm add @envelop/operation-field-permissions
yarn add @envelop/operation-field-permissions
bun add @envelop/operation-field-permissions
```

## Health

**Score 70/100 (B)** — status: active.

Positive: has types; esm support; no vulnerabilities; has provenance; recently updated; high maintenance score.

Warnings: low downloads.

## Facts

| | |
|---|---|
| Version | 9.2.1 |
| Published | 2026-09-16 |
| First published | 2021-06-30 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | bundled |
| Module format | ESM + CommonJS |
| Node | >=18.0.0 |
| Dependencies | 3 |
| Unpacked size | 15.3 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| Provenance | attested (GitHub Actions) |
| GitHub stars | 8529 |
| Author | Laurin Quast <laurinquast@googlemail.com.com> |
| Maintainers | dotansimha, enisdenjo, theguild-bot |

## Links

- npm: https://www.npmjs.com/package/@envelop/operation-field-permissions
- Repository: https://github.com/graphql-hive/graphql-yoga
- Homepage: https://github.com/graphql-hive/graphql-yoga/tree/main/packages/envelop/plugins/operation-field-permissions#readme
- npm.io page: https://npm.io/package/@envelop/operation-field-permissions

## Dependencies (3)

- [tslib](https://npm.io/package/tslib.md) ^2.5.0
- [@envelop/extended-validation](https://npm.io/package/@envelop/extended-validation.md) ^7.2.1
- [@whatwg-node/promise-helpers](https://npm.io/package/@whatwg-node/promise-helpers.md) ^1.2.4

## Recent versions

- 9.2.1 (latest) — 2026-09-16
- 10.0.0-alpha-20260929215310-f756e1d4981e8dd5ac5e128b5c2554893ae24a52 (alpha) — 2026-09-29
- 7.1.3-rc-20250306153119-ed3979491f3ac71caf439dd723f2d12d26b1000f (rc) — 2025-03-06
- 9.2.0 — 2026-08-19
- 10.0.0-alpha-20260420122826-afff629b648b45dc56cbf71f10a44eb4006be3c3 — 2026-04-20
- 9.1.2-alpha-20260220144136-711686b126e6dd25230f0bb3c500a7a031985b0e — 2026-02-20
- 9.1.2-alpha-20260220131826-1b3a1e9e27b8b8aa558355d0c2f0e695b96d70cb — 2026-02-20
- 9.1.2-alpha-20260220131728-1041a1750b5b3fc9b884e99d2faee0f168627271 — 2026-02-20
- 9.1.2-alpha-20260220131011-a35ff9b25933403c69d677eddc47f62e241284f2 — 2026-02-20
- 9.1.2-alpha-20260220130904-211898c307097b3cc67903d5c3c227f14d9682db — 2026-02-20
- 9.1.2-alpha-20260220130823-c2a2d78d42fdabd997939bf0acb354c3e2e12050 — 2026-02-20
- 9.1.2-alpha-20260220130803-9ecead51d07d2d27d2566b9dbae5e166a53b7f2c — 2026-02-20
- 9.1.2-alpha-20260220130406-9e30e6b21868124f2e95d8178dade31b122188f6 — 2026-02-20
- 9.1.2-alpha-20260220130319-b0b7578d1e4ea902b60dc0359460903320969daa — 2026-02-20
- 9.1.2-alpha-20260220130301-e72a8134fdf82c1a8d7f2dcae344f023f7e34876 — 2026-02-20
- … 1664 more at https://npm.io/package/@envelop/operation-field-permissions/versions

## README

## `@envelop/operation-field-permissions`

Disallow executing operations that select certain fields. Useful if you want to restrict the scope
of certain public API users to a subset of the public GraphQL schema, without triggering execution
(e.g. how [graphql-shield](https://github.com/maticzav/graphql-shield) works).

**Note:** This plugin and authorization on a resolver level (or via middleware) are complementary.
You should still verify whether a viewer is allowed to access certain data within your resolvers.

## Installation

```bash
yarn add @envelop/operation-field-permissions
```

## Usage Example

```ts
import { execute, parse, specifiedRules, subscribe, validate } from 'graphql'
import { envelop, useEngine, useSchema } from '@envelop/core'
import { useOperationFieldPermissions } from '@envelop/operation-field-permissions'

const getEnveloped = envelop({
  plugins: [
    useEngine({ parse, validate, specifiedRules, execute, subscribe }),
    useSchema(schema),
    useOperationFieldPermissions({
      // we can access graphql context here
      getPermissions: async context => new Set(['Query.greetings', ...context.viewer.permissions])
    })
    /* ... other envelops */
  ]
})
```

**Schema**

```graphql
type Query {
  greetings: [String!]!
  foo: String
}
```

**Operation**

```graphql
query {
  foo
}
```

**Response**

```json
{
  "data": null,
  "errors": [
    {
      "message": "Insufficient permissions for selecting 'Query.foo'.",
      "locations": [
        {
          "line": 2,
          "column": 2
        }
      ]
    }
  ]
}
```

---
_Source: https://npm.io/package/@envelop/operation-field-permissions · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
