Creating an Inclusive Django Community with Kenya Phelps
Published July 15, 2026
This video features Syrus Akbary at DjangoCon US 2016 in Philadelphia, Pennsylvania, USA.
A New Look Into APIS - Graphene by Syrus Akbary
REST API's have been with us a long time. It's time to ask if we can create better API's with new paradigms. We will discuss new ways to query and manipulate data so that our code becomes simpler and easier to scale.
GraphQL is a query language created by Facebook in 2012 which provides a common interface between the client and the server for data fetching and manipulations. We will do a quick overview of GraphQL and focus later on Graphene, the main GraphQL framework for Python.
Graphene allows us to reuse our existing Django Models to create schemas quickly and easily. We would like to think of it as the next natural step from the Django Rest Framework.
This talk was presented at: https://2016.djangocon.us/schedule/presentation/38/
LINKS:
Follow DjangCon US 👇
https://twitter.com/djangocon
Follow DEFNA 👇
https://twitter.com/defnado
https://www.defna.org/
Syrus Akbary explains how GraphQL addresses common REST API problems such as multiple requests, under-fetching and over-fetching, changing server-side endpoints, and weakly enforced input and output types. GraphQL lets clients request exactly the fields and relationships they need, validates queries against an introspectable schema, and returns data shaped like the query. He introduces Graphene, a Python implementation that defines GraphQL schemas with a small amount of code, then shows how it integrates with Django models, permissions, authentication, and different database backends through resolvers and middleware.
Summarised automatically from the transcript.
Automatically transcribed, so expect mistakes in names and technical terms.
Speaker 1: Come on, no.
Speaker 2: Today I will be speaking about Graphene. Graphene is a new way that allows us to create APIs very, very easily. Before I start, I would like to give a quick introduction about myself. As I said, I'm serious like developer. I've been working with backend and frontend for almost 10 years Right now, uh right now I'm working at a firm uh in charge of the data communication between services using GraphQL. If you find this talk interesting, just let me know. We are hiring a lot of people We will be welcome to hire more. You might know some of my packages or you might not. I did PyJ, which is a template template engine for Python. Validate email, validate an email
Speaker 2: and like other packages. You can check other projects that I did in it have slash zero sac vary. Today I will be doing a quick introduction about graphene. But before that I will review a little bit like what is REST, what we can improve from REST. From there we will go to GraphQL. how what GraphQL makes better than Rust and then to Graphene which is a framework for using GraphQL in Python. And then from there we can see how we can use Graphene with Django very very easily So first slide. What is a typical Django structure? A typical Django structure is using Django in our backend for our models and also admin for the admin admin
Speaker 2: panel. And usually we used to have server-side Django templates. So was Django the one who was in charge of rendering the layout. However, in the past years We also have desktop web apps which are powered by React and Angular and mobile apps and the way they communicate with Django is through some APIs. So for communicating between these desktop web apps or mobile web apps with our Django backend , there was a dominant architecture, which was REST. How many of you know what what is REST or are already been using Django Restrain Warrior in their applications? Oh, that's a lot. Perfect. You will love graphene.
Speaker 2: So I will do a very quick example about REST. Imagine we want to create a conference application where we have talks and we have speakers. And these talks have a title on it, have a time schedule, so when the talk is happening, and also we have the user model, which have a name and have an avatar. And talk have a speaker which is a user and we can get the talks of a user uh which is referencing the talk model So if we want to create this conference application and we want to get all the talks, what is the title for each talk? What is the name and the avatar of the speaker of each of the talks More or less, this is how we have to do it in a poor REST
Speaker 2: approach. So we load the schedule, the schedule will return a list of talks, a list of IDs, then we load we load we load the detail of each talk It also will return us like the title of the talk and probably the ID of the speaker. And from the idea of the speaker we will fetch again the user information from this ID. As we can see we are we are making almost 70 TP requests for just filling one view. And this is not performant at all. But before going forward on that What are the main points about in that we have to deal about using a part of using WebS? We have to deal with API version. We have to deal with input validation. That means if we if we want to create a user or we want to filter or do pagination, we have to make sure, for example, for pagination that we receive an integer
Speaker 2: and not a string. We have to make sure that the output reflects the types that we want. Also, we have to deal with data under fetching or overfetching That means like a model have a lot of fields and some views doesn't want all the fields loaded, right? Like sometimes we just want the name of a user and not anything else We have to deal with network errors and with network latency. For the first three bullet points, we can see the Django Rest framework solves this in a partially good way But what about the last three? What about if we want to specify what is the data we want? How we can solve that?
Speaker 2: So I usually I usually a good way of solving that is gluing everything together, all these 7-8 CTP endpoints, into one. So we will create a new endpoint which is alt-out talks with username and not a target, for example And it's very normal that after some time we can get questions like, oh, could you please add an option to get the data back without this field but without another extra field for the new view that I'm creating? And because of that, we can see that the logic of fetching is moved from the client who previously knows what we want to the server, which isn't now the one responsible of knowing what the client wants. And because of that, each time the client wants to fetch more or less data, we have to go back to the server and change the logic there
Speaker 2: And it's not very scalable. Why? Because if you imagine we have a lot of clients and we just change a little bit the logic there, we always have to go back to the server to change and restart and everything. And it's not performing, it's not the best way that we can do that. Because of that reason, a lot of companies start investing a lot of time in how we can improve this process. One of these companies was Facebook, who presented GraphQL one year ago, but they've been using GraphQL since three years ago, I think. And what is GraphQL? GraphQL is a way that let us define or query the data we want. So let's go to the hello world of GraphQL. This is the hello world. In this case, I'm just getting the name of my user.
Speaker 2: As we can see, this GraphQL query is very similar to JSON. And the GraphQL response or the JSON response that we will get from requesting this is just like the query we are doing but filled with data. So we can think of GraphQL like the JSON we want to fetch, but without anybody, just the keys. So going to a more complicated example, we want to get my name, but also my talks the title of each of the talks that I'm doing and the time of like when the talk is happening. I bet you can already guess what will be the response of that It's just the data we are requesting but fill. Like the JSON the graphQL for it we are requesting fill with data
Speaker 2: And it's very intuitive knowing what we are querying because the response will look exactly like the query we are doing. So let's see how we can create a GraphQL schema based on that. We have to create the root query, which is the type that we hit when we first query. This query this query type has the me field on it. The me field is returning a user type. User type have name, name field and talks on it, and talks is returning a list of Oh, sorry. A list of talks. And talk have a title and a time on it. So what are the real advantages of graph law? We have query evaluation. If a client do a query that we don't expect, for example, it's querying a field that doesn't exist, it will throw an error.
Speaker 2: But not only that, GraphQL is strictly tight, both input and output So if we expect to receive a number and we receive a string, it will show an error without executing anything. And also for the output. So if we expect or the client expects to receive uh inteher, for example, for a page, then it should receive it and it will check it always But not only that, we we will not have the problem of data under fetching or over fetching. Why? Because it's the client now the one who knows what it wants. And then the client decides how much data it wants to receive. Also, we have introspection. But what I mean with introspection? What I mean is actually the client could see what are all the types that are living in our schema
Speaker 2: universe and could see like the description or what are the relation between them. Uh going back oh sorry. Going back to introspection Another powerful powerful thing about introspection is it let us have validation without querying and it lets us have, for example, an IDE for query that I will show you later and it makes things very very easy. Also, we have the resolver context. So each time we are resolving a field, we know what is its point. For example, if I fetch in my talks, I know that I'm fetching the talks from my user and I can act accordingly. Also, we will have only one round trip for data fetching, so we will not have anymore the point
Speaker 2: of network latency or HTTP errors. Okay. Another cool thing is we have GraphQL in a lot of languages. Not just JavaScript, which was the main implementation that Facebook did. We have GraphQL in Python, we have GraphQL in Ruby and Rails, we have GraphQL in Go, in LXER, and in almost any language you can imagine now. But let's go deeper into the one for Python. Graphene. Graphene is a framework I created for using GraphQL in Python very, very easily. So it's the main way of using GraphQL in Python. So what I I'm gonna give some data about Grafine. It's the most graphical repository outside Facebook. We have right now around 770 stars.
Speaker 2: It's used across 20 companies more or less in production, African is included. It has a very large community and this let us fix things or improve very, very fast. And not only that, we support from Python 2. 6 to Python 3 very easily, like without any change in our code. And it's fully compatible from Django 1. 6 plus So going back to our model, we have we want to create our conference application and we have talks, the talk model and the user model with the following fields that I described before If we want to create or we want to implement the following uh a graphical schema that could execute this query, this is how we have to do it in Python.
Speaker 2: So we create the query type which is inerting from graphene object type and defines the mean field which is referencing that user. The user is another graphene type. Object type that have a name which is a string and talks which is a list of talk. And talk is just another object type we have title and time on it. Title is a string, time is a daytime. So we can see that with just nine lines of code we can define a world schema universe and it's very easy to follow it One thing I'm more proud of is the playground. The playground let us query or play with Graphene or GraphQL in Python very easily. So you can actually go in your computers, go to this URL and play with it by yourself.
Speaker 2: I'm gonna do a very quick demo about how it works. So first we import graphine because we need it. This is using PyPy. js which let us have a Python interpreter in our browser So we create the user type, we have a string on it, a name which is a string. We have the query type which is another object type of GraphQL. This query type has the me field on it. Which is referencing the user. And then we create the schema. And we define which is the root query type. Which in this case is the query after the query class that we define in Python. So if we try to execute the following query, we want to get my name. Right now we execute, of course, it will return null because we don't
Speaker 2: we are not defining how we want how we are resolving this thing So if we do if we create the following function, resolve me, and we can say like okay, each time you are requesting a user, just return a user with the name zero sec variety And we query it again, we can see how we fetch the data we want. But not only that, let's complicate it a little bit so we can make the previous example that I was talking before. So we will we want to create the talk type The talk the talk type will have a title, which is a string, and we have a speaker which is referencing the user. In this case we can use the same Django reference with the strings and it will map to the correct class.
Speaker 2: In this also we are adding the talks field which is a list Not reference the cost the class type. So right now if we want we are not requesting the talks field, so we are fetching the same data, but if we want to fetch the talks on the the title of the talks we can see how now it receives like an empty empty list. In this case I'm just saying like okay I'm creating or I'm returning this user we have this call to me If we execute this again, we can see how right now it fetches the data for each of the talks. But let's complicate it again a little bit. We want to query not just like a random user, but we want to query, for example, a user given an ID.
Speaker 2: So we are saying we create a user field in the query and we say we want we have the ID argument which is a string And also we are defining how we want to resolve a random user, even an ID. So I'm creating here a dictionary of users, which in this case is just like a mapping with an ID and the correct object type. or the co uh the correct um instance. And let's try it and see how it works. So for example with me I'm just returning I'm just gonna get the user with the ID
Speaker 2: one I'm gonna execute it and see how it works. Okay, it works perfectly, it's the same way And also I'm defining how we want to resolve a user. So we get the ID from the arguments, ID. And now We can execute again, but now we can change from me to user. And if we execute this query, it will return null because we are not giving there any ID. But actually, I'm here and putting like some random data. Okay, so here if we specify an argument, for example, the I D. We can say for the ID1 is fetching Zero Sag Barry, which is me and myself, for the IT
Speaker 2: ID2 is fetching the the Peter user So this is more or less how the playground looks like. But let's go a little bit deeper. I have zero minutes, but I will try to go fast A little bit deeper about like how graphene works with Django. Let's see we have these models in our Django application. So we have the user model, which have a name which is a chart field, an avatar which is an image field, and a top model which have a title, time and a reference to a speaker. A very good thing about Graphene is we can actually map automatically from our Django models to GraphQL types. So we don't have to type again and again the same things. So let's see how it would look like.
Speaker 2: Actually we create a class user. If you already have been using Django Rest framework, it's very similar to the serializers. So we specify which model we want. In this case, each of these types will get the fields from the Django model. And we can also specify For example, which fields we want to map into GraphBook. So for user we just want the ID, name and avatar. We don't want the password, we don't want any other field. And for the talk, we want to exclude the ID I always wanted to do a demo but I don't have time. So last slide, why you should use graphene in your backend. Why graph GraphQL or Graphene is better. The first thing is much easier to maintain than REST APIs. You will have one documentation and UI for free.
Speaker 2: Given the introspection, you can recreate the documentation from the schema universe you have. So you don't need to spend any time more in documentation or in the ID. It's everything already opened. Also, you can have a very quick integration with your front frontend with React thanks to React relay library by Phaser. And as you have seen, have seamless integration with Django. But overall, the most important thing is the development process will be much faster. Basing our own experience, we lower the times by the development time by two or three. And that's quite important. Why? Because we don't need to go back to the server always, each time we want to fetch different things.
Speaker 3: Graphene is a service I know that can be used on the web. Can Graphene also be run on a Neo4j database in my own data center?
Speaker 2: Yeah, it could be run like in any data set. Like it could be run in Django, it could be run like actually one guy built uh graphene integration with Google App Engine and you can build with almost anything you want want. It's transparent. Like if you want to build another tool on top of that, it's very easy. So it's not required to use Django or no. Like you have the tools for doing this with Django. But actually you can integrate with Flask or Google App Engine or almost anything you want.
Speaker 4: Hi, thank you for your talk. Does the graphene library have a sense of permissioning where a user might have access to some data but not others?
Speaker 2: Yes, actually there is one thing that I didn't cover today because I didn't have enough time, which is middleware. Middleware catches time we are resolving appeal, for example, talks for a user and we can check there If a user has permissions for getting the talks of another user. So yeah, we can add like permissions very easily. And for example, with Django Guardian, I'm planning of open sourcing another thing that we are using today. So it's very easy to add permissions on top of that and see what user what the user is capable of getting or receiving.
Speaker 5: Don't we go to 540 today? So we have 10 more minutes? Yeah, that's fine enough. That's what the schedule says.
Speaker 6: Okay. Um I'm fine with that. If you uh we have more questions.
Speaker 7: Hi, yes, thanks for your talk. Very interesting. My question is specifically around, you know, like in the example the data was defined in the query file. Yes. Um at what point do you uh put that data into like some kind of graph database or like how how does that generate IDs
Speaker 2: In the resolver method you can you can decide how you want to face the data. So actually if you want I can give you a very if you visit my GitHub, like GitHub slash serious activity, I just the last repo I created like an example of what I did using Django. And you can check there that we have a result method and we want to, for example, get certain tasks for our user. And in the resolver method, we define how we want to fetch this data. So actually there you can specify how you want to do the integration with Nyan or for J or anything. Actually GraphQL have nothing to do with graphs Like have to do with graphs in the way that you have types and you have relation between types. But other than that, you can do integration with a SQL database or NoSQL or whatever.
Speaker 2: Thank you. Can you put the slides with your information back up?
Speaker 8: In the second demo that you didn't have time to show, you're gonna show how the uh graphene query models to map to Django models um similar to the rest uh framework. Um does that have support for the Postgres, the new Postgres fields like the JSON and the right field?
Speaker 2: Yes, actually it does. Like it not only have support with the latest uh Postgres fields, but also it have support for example with SQL Alchemy. at any moment you want to move. But it's yeah, it's it's very easy to add integrations with these things. Like we have support with JSON, HStore and Arite like that
Speaker 1: Hi. Um in the kind of hard-coded example, the query object kind of like drilled down to define the relations. Explicitly? When you integrate with Django, um
Speaker 8: will a GraphQL query kind of like do those joins under the hood automatically for you
Speaker 2: Yes, actually there is a very good example I recommend you to check, which is a Star Wars API example. If you go to graphenepython. org, there is a button there which is like check out checkout or Star Wars whatever. All the relations and all the things there will be automatically done without anything in your site. And actually you can check the source code.
Speaker 6: Questions anyone else? Let's make this the last one, I think. Uh mine was very related to the permissions one.
Speaker 8: I was just wondering about auth, if that even is a thing with the grappling stuff.
Speaker 2: Yes, actually like you can check very easily like what is The context of each type you are you are requesting. In the case of the Django integration, the context will be the request context. So you can check there each time you are resolving something what is the user who is requesting data And from there you can do whatever thing you want with permissions or add a middleware or whatever. It's very, very easy.
Speaker 6: All right, let's have a hand for Cirus Sakai.
GraphQL lets the client specify exactly which fields it needs, avoiding under-fetching and over-fetching. It also provides schema-based input and output validation, introspection, and typically allows the data to be fetched in one round trip.
Discussed at 7:59Graphene is a Python framework for building GraphQL APIs. It lets developers define GraphQL types and schemas with relatively little Python code and supports Django as well as other integrations.
Discussed at 9:33You define object types such as users and talks, give their fields GraphQL types, and create a root query type that exposes them. Graphene can represent the example schema in about nine lines of Python.
Discussed at 11:07Graphene can automatically map Django models to GraphQL types, similarly to how Django REST Framework maps models to serializers. You can select the model fields exposed through GraphQL or exclude fields such as passwords and IDs.
Discussed at 16:34The speaker says Graphene is easier to maintain because introspection provides documentation and a query UI, and it integrates smoothly with Django and React Relay. In his experience, avoiding repeated server changes can reduce development time by two or three times.
Discussed at 17:20Yes. Graphene is independent of Django and can be integrated with Neo4j, SQL, NoSQL, Flask, Google App Engine, or other data sources through resolver methods.
Discussed at 18:16Middleware can inspect each field as it is resolved and check whether the requesting user may access the data. In Django, tools such as Django Guardian can be used to implement these permissions.
Discussed at 18:51The resolver method determines how each field's data is fetched, so it can contain the integration with Neo4j, SQL, NoSQL, or another backend. GraphQL itself does not require a graph database; its 'graph' refers to related types and fields.
Discussed at 20:03Yes. The speaker says Graphene supports newer PostgreSQL field types, including JSON, HStore, and array fields, and also has integrations such as SQLAlchemy.
Discussed at 21:25In the Django integration, the resolver context contains the request context, including the user making the request. Resolvers or middleware can inspect that user and apply authentication or permission logic.
Discussed at 22:46Note: We understand that names change, people change, and bodies change. We respect each individual's journey and privacy. If you have any concerns about a video or need us to remove content, please don't hesitate to contact us. We will handle your request with care and promptly address any issues.
Published July 15, 2026
Published July 15, 2026
Published July 15, 2026
Published July 15, 2026
Published July 15, 2026
Published July 14, 2026