Add a API page that describes the GraphQL API. Also, make sure the API isn't allowing users to do malicious writes.