Inspect compositions and the client schema in AxonMundi's self-hosted Cosmo Studio
Cosmo Studio is where you inspect the
axonmundi federated graph, its subgraphs, composition results, schema checks,
changelog, and client schema. Studio is an administration and inspection tool;
it does not authenticate router requests for you.
Open Studio, choose email sign-in, and complete the Okta redirect. That
browser session is separate from both a Prepared end-user bearer token and the
CLI's wgc auth login device flow.
After signing in, open the axonmundi graph in the default namespace. If the
graph or namespace is unavailable, request the least-privileged access needed
from the Studio or Platform owner. Do not use a shared account.
Before treating a subgraph publication as ready for clients:
Traffic-based analysis represents requests that have reached the router. It does not prove an unobserved frontend path is safe, so frontend and producer CI must still validate the operation documents they can ship.
Use Playground++ only for approved, non-sensitive requests. It is a GraphQL client, not an authorization proxy: querying protected fields requires the same short-lived Prepared access token used by the application.
X-WG-Include-Query-Plan: true to include the query plan.X-WG-TRACE: true to inspect Advanced Request Tracing.Tracing can expose subgraph timings, inputs, and outputs. Use synthetic or approved non-sensitive data only. Studio may retain query text and configured headers, so never save a bearer token to a shared or long-lived Playground session. Clear one-off headers after use.
For an authorized, temporary token workflow and endpoint details, see Explore the graph.
For Studio to accurately track traffic and protect against breaking changes,
always use named operations when writing queries, mutations, or
subscriptions (e.g., query GetUserProfile rather than an anonymous
query { ... }).
Client applications calling Mundi attach stable identification headers:
These headers allow Studio to associate observed operations with specific client releases so breaking-change checks are actionable. The client operation contract defines the complete validation and persisted-operations rollout path.