# Altair GraphQL Client: a cross-platform GraphQL IDE that also ships as Express middleware

> Altair is an MIT-licensed GraphQL client written in TypeScript, distributed as a desktop app, browser extension and embeddable middleware. It fits teams that want an in-app GraphQL explorer without standing up a separate service.

**altair-graphql/altair** — ✨⚡️ A feature-rich GraphQL Client for all platforms.

- Repository: https://github.com/altair-graphql/altair
- Website: https://altairgraphql.dev
- Stars: 5,434 · Forks: 403
- Language: TypeScript
- License: MIT
- Published: 2026-09-22 · Updated: 2026-09-22 · Language: en
- Canonical page: https://hysenlabs.com/projects/altair-graphql-altair

## What Altair GraphQL Client does that a terminal curl cannot

A GraphQL request is a POST with a JSON body, so curl can send one. What curl cannot do is keep a schema, a set of variables, per-environment headers and a history of past responses in one place while you iterate on a query. Altair is built around that iteration loop. The README describes it as a "feature-rich GraphQL Client IDE for all platforms" and says it helps you "debug GraphQL queries and implementations". The repository topics list fragments, subscriptions, a GraphQL editor and the GraphiQL lineage, so the scope is query authoring and response inspection rather than schema design.

The audience is narrower than the tagline suggests. If you only ever fire one query against a local server, a browser tab on the server's own GraphQL endpoint is enough. Altair earns its place when a team has several environments, a schema that changes, and people who need to reproduce each other's requests. The Express, Fastify and Koa examples under examples/ point at the second audience: developers who want the client served from their own application rather than installed by every engineer.

## The three delivery shapes and how they change the data flow

Altair is not one program. The repository layout shows at least three ways the same client reaches a user, and the choice changes where requests originate.

The desktop build is the most direct: the client runs locally and sends requests straight to your GraphQL endpoint. Nothing sits between the two, so CORS and authentication behave exactly as they would from any HTTP client on that machine. The Cargo.toml workspace points at packages/altair-tauri/src-tauri, so a Tauri shell is part of the build graph alongside the Electron lineage implied by the desktop-apps topic.

The browser extension is the second shape. The README links a Chrome Web Store listing and a Mozilla Add-on listing. Here the request originates from the extension's context, which matters for cookie-based auth and for endpoints that restrict origins.

The third shape is the one worth understanding before you commit. The npm badge in the README points at altair-express-middleware, and examples/ contains express-v4, fastify-v5 and koa-v3 directories. In this mode the client is served by your own server, so requests to your GraphQL endpoint come from the same origin. That removes a class of CORS problems and lets you gate the explorer behind whatever session logic the host application already has. The cost is that the explorer is now part of your deployment: it ships with your server, it consumes your server's resources, and its availability is your availability.

The repository is a pnpm and Turbo workspace (pnpm-workspace.yaml, turbo.json), with the root package named @altairgraphql/root at version 8.5.9. That version tracks the latest release, v8.5.9, published on 2026-08-16.

## Installing Altair and serving it from an Express app

The README does not give a step-by-step install for the desktop or extension builds; it points readers at the documentation site and at the store listings. What the repository does show is the middleware path, and that is the one you can reproduce from the files here.

The root package.json declares an engines field of node >= 22, so check that first. The workspace uses pnpm, and the Dockerfile pins PNPM_VERSION to 9.15.0. Installing with a different major version is possible but is not what the build files describe.

For the middleware, the README's badge links to the altair-express-middleware package on npm, and the repository keeps working examples under examples/express-v4, examples/fastify-v5 and examples/koa-v3. Those example directories are the place to copy a mount pattern from, because the README itself does not print one. The Dockerfile documents how the workspace installs and builds:

```bash
pnpm install --frozen-lockfile
pnpm turbo run build --filter=@altairgraphql/api..
```

That filter builds the API package and its dependencies. It is the hosted-service build, not a self-hosted client.

If you would rather run the whole stack through Compose, the repository's compose.yaml defines a single service named server, built from the Dockerfile in the current directory, with NODE_ENV set to production and port 3000 mapped to 3000. The commented-out block below it shows how a PostgreSQL service would be added, but it is commented out, so the default file starts only the one service. The Dockerfile's build stage uses node:24.14.0-alpine and pins PNPM_VERSION to 9.15.0.

## Where Altair is the wrong tool

The repository's deployment section is the clearest limitation, and it is easy to misread. The Dockerfile, compose.yaml, render.yaml and the DigitalOcean and Vercel buttons all describe building and deploying the Altair API, the backend behind altairgraphql.dev. The Vercel button asks for JWT_ACCESS_SECRET, EVENTS_JWT_ACCESS_SECRET, JWT_REFRESH_SECRET, Google OAuth credentials, Postgres credentials and STRIPE_SECRET_KEY. Those are secrets for running a hosted product with accounts and billing. If your goal is a GraphQL client for your team, building this image gets you nothing you can use; you want the desktop build or the middleware.

A second limitation is documentation depth in the repository itself. The README delegates to altairgraphql.dev/docs and does not document the middleware options, the environment variable list for the client, or a rollback procedure for the hosted API. Anyone evaluating the project from the repository alone will find the surface described but not the details.

A third is the Node floor. The engines field requires Node 22 or later at the workspace root. Teams on an older LTS line cannot build the workspace without changing that constraint, and the Dockerfile's choice of node:24.14.0-alpine as the default NODE_VERSION suggests the build is exercised against a much newer runtime than the minimum.

Finally, the name is a genuine obstacle. Searching for Altair returns eyewear, a star, an anime character, a 1975 microcomputer and several unrelated companies. If you are writing onboarding notes or internal documentation, link the documentation site rather than the bare word.

## Altair against GraphiQL and against a general API client

The two realistic alternatives differ in kind, not degree.

GraphiQL is the reference implementation the GraphQL ecosystem grew around, and the repository's own topics list graphiql alongside altair. GraphiQL is a React component you embed in a page you control; it is deliberately minimal, and its behaviour is tied to the version of the component you render. Altair's approach is the opposite: it is a full application with its own persistence, tabs, environments and history, and the middleware exists so you can drop that whole application behind a path on your server. If you want a thin explorer that looks like part of your product, GraphiQL is the closer fit. If you want the same tool your engineers use on the desktop to also be reachable in staging, Altair's middleware shape is the reason to pick it.

A general-purpose HTTP client such as Postman or Insomnia takes a third approach. It treats GraphQL as one content type among many, so the schema-aware autocompletion and fragment handling that Altair builds around are shallower. The trade is breadth: a general client also covers your REST endpoints. Altair's topics list fragments and graphql-subscriptions, which is where a general client tends to fall short.

The honest summary is that Altair's differentiator is the middleware, not the editor. Plenty of tools edit GraphQL. Fewer let you serve the editor from the same Express process that serves the API.

## Maintenance, licence and what upgrading costs

The repository is not archived. The last push was on 2026-08-16, which is recent enough that the project is being touched, and the release cadence supports that: v8.5.9 on 2026-08-16, v8.5.7 on 2026-06-06 and v8.5.4 on 2026-06-04. The gaps are uneven, with two releases three days apart in June and then a two-month gap, so do not read the cadence as a schedule.

The licence is MIT, declared in both the root package.json and the repository metadata. For most teams that means you can embed the middleware in a commercial product without a copyleft obligation. MIT does not settle trademark use, and it does not cover the hosted API's terms; the README's sponsorship and Open Collective sections describe funding, not licensing. Nothing here is legal advice.

Upgrade cost is driven by the workspace toolchain rather than the client itself. The root package.json pins eslint to 8.18.0 and eslint-config-prettier to 8.5.0, uses Turbo 2.x, and relies on pnpm catalogs (the catalog: specifiers for TypeScript, Vitest and Playwright). If you consume only the published altair-express-middleware package, none of that reaches you. If you fork or build the workspace, you inherit the whole toolchain, including the node >= 22 requirement and the pnpm version pinned in the Dockerfile. The Cargo.toml workspace adds a Rust toolchain requirement for the Tauri desktop target, which is a real cost for a JavaScript team that only wants the middleware.

## Conclusion

Adopt Altair if you already run an Express, Fastify or Koa server and want a GraphQL explorer reachable from the same origin, or if you need a desktop client for query work. Do not adopt it expecting a maintained API service: the repository's own Docker and Compose files build the altairgraphql.dev API, not a self-hosted client, and the README documents no rollback path for the hosted service. Verify first that your Node version satisfies the engines field (node >= 22), that pnpm 9.15.0 matches your toolchain, and that the package you install is the one you actually want, since the repository publishes several under the same organisation.

## FAQ

### How do I use Altair GraphQL Client with my own server?

The README's npm badge points at the altair-express-middleware package, and the repository ships working examples under examples/express-v4, examples/fastify-v5 and examples/koa-v3. You mount it on a path in your existing app, and the Altair interface is then served from your own origin. The README does not list the middleware's option names, so check the package page for those.

### How do I install Altair GraphQL Client?

The README does not give install steps for the desktop or browser builds; it links the documentation site and the Chrome Web Store and Mozilla Add-on listings. For the middleware path, the README's badge points at the altair-express-middleware package on npm. The workspace itself is built with pnpm, and the root package.json requires Node 22 or later.

### Does Altair GraphQL Client run on all platforms?

The README describes it as a GraphQL client IDE "for all platforms" and links a Snapcraft badge alongside the Chrome and Firefox listings, so Linux, browser and desktop distribution are all represented. The repository also contains a Tauri target under packages/altair-tauri/src-tauri. The README does not enumerate supported operating system versions.

### Is Altair GraphQL Client free to use in a commercial product?

The repository declares the MIT licence in both the root package.json and the repository metadata, which permits commercial embedding. The README also describes sponsorship tiers on Open Collective, which is funding rather than licensing. Trademark use and the hosted API's terms are separate questions the repository does not answer.

### Can I self-host the Docker image in the Altair repository?

The Dockerfile and compose.yaml build the Altair API, the backend behind altairgraphql.dev, not a self-hosted client. The Vercel deployment button requires JWT secrets, Google OAuth credentials, Postgres credentials and a Stripe key. If you want a client for your team, use the desktop build or the Express middleware instead.

## Sources

- [altair-graphql/altair on GitHub](https://github.com/altair-graphql/altair)
- [License: MIT](https://github.com/altair-graphql/altair/blob/master/LICENSE)
- [Project website](https://altairgraphql.dev)
- [README](https://github.com/altair-graphql/altair/blob/master/README.md)
- [Releases](https://github.com/altair-graphql/altair/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/altair-graphql-altair
