# Cannot connect to GraphQL endpoint

**URL:** <https://discuss.dgraph.io/t/cannot-connect-to-graphql-endpoint/15609>\
**Category:** GraphQL\
**Tags:** kind:question\
**Created:** [September 19, 2021, 9:12am UTC](https://discuss.dgraph.io/t/cannot-connect-to-graphql-endpoint/15609 "2021-09-19T09:12:44Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![khoi-fish](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/khoi-fish/32/8883_2.png) [@khoi-fish](https://discuss.dgraph.io/u/khoi-fish)\
**Post date:** [September 19, 2021, 9:12am UTC](https://discuss.dgraph.io/t/cannot-connect-to-graphql-endpoint/15609/1 "2021-09-19T09:12:44Z")

</div>

Hey all

I’ve done a really basic installation of DGraph that looks a little something like this:

1. Spun up a DigitalOcean droplet
2. Installed Docker
3. Ran `dgraph/dgraph:latest` with docker-compose

My docker compose file looks like:

```auto
version: "3.2"
services:
  zero:
    image: dgraph/dgraph:latest
    volumes:
      - /mnt/volume_xxxxx:/dgraph
    ports:
      - 5080:5080
      - 6080:6080
    restart: on-failure
    command: dgraph zero --my=zero:5080
  alpha:
    image: dgraph/dgraph:latest
    volumes:
      - /mnt/volume_xxxxx/dgraph:/dgraph
    environment:
      DGRAPH_ALPHA_ACL: secret-file=./secret_file
      DGRAPH_ALPHA_SECURITY: whitelist=10.0.0.0/8,172.0.0.0/8,192.168.0.2/16
    ports:
      - 8080:8080
      - 9080:9080
    restart: on-failure
    command: dgraph alpha --my=alpha:7080 --zero=zero:5080
  ratel:
    image: dgraph/ratel:latest
    ports:
      - 8000:8000
    command: dgraph-ratel

```

I’m able to connect to the Ratel UI via [http://xxx.xxx.xx.xxx:8000](http://xxx.xxx.xx.xxx:8000) and play around just fine, however I cannot connect via [https://play.dgraph.io/](https://play.dgraph.io/)

Additionally, opening up the GraphQL endpoint in Altair (via browser extension) or any other GraphQL UI doesn’t work either.

Am I missing something? Any help is appreciated.

---

<div class="post-metadata">

**Author:** ![star](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/star/32/8877_2.png) [@star](https://discuss.dgraph.io/u/star)\
**Post date:** [September 19, 2021, 9:25am UTC](https://discuss.dgraph.io/t/cannot-connect-to-graphql-endpoint/15609/2 "2021-09-19T09:25:13Z")

</div>

Try whitelist=0.0.0.0/0  
More precisely whitelist=\*.dgraph.io

---

<div class="post-metadata">

**Author:** ![khoi-fish](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/khoi-fish/32/8883_2.png) [@khoi-fish](https://discuss.dgraph.io/u/khoi-fish)\
**Post date:** [September 19, 2021, 5:26pm UTC](https://discuss.dgraph.io/t/cannot-connect-to-graphql-endpoint/15609/3 "2021-09-19T17:26:04Z")

</div>

@star no luck. The whitelist doesn’t seem to like `*.dgraph.io`. I also tried specifically both `0.0.0.0/0` and `172.67.72.127` and it still doesn’t work.

---

<div class="post-metadata">

**Author:** ![khoi-fish](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/khoi-fish/32/8883_2.png) [@khoi-fish](https://discuss.dgraph.io/u/khoi-fish)\
**Post date:** [September 19, 2021, 6:24pm UTC](https://discuss.dgraph.io/t/cannot-connect-to-graphql-endpoint/15609/4 "2021-09-19T18:24:15Z")

</div>

After some more debugging, it looks like it’s a CORS issue. Now to figure out how to fix that… 🤔

---

<div class="post-metadata">

**Author:** ![khoi-fish](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/khoi-fish/32/8883_2.png) [@khoi-fish](https://discuss.dgraph.io/u/khoi-fish)\
**Post date:** [September 22, 2021, 12:49am UTC](https://discuss.dgraph.io/t/cannot-connect-to-graphql-endpoint/15609/5 "2021-09-22T00:49:56Z")

</div>

Anyways finally had some time to take another crack at this. I notice the CORs issues were due to `Referrer-Policy: no-referrer-when-downgrade`.

I figured it was because I was connecting from [https://play.dgraph.io/](https://play.dgraph.io/) to [http://xxx.xxx.xx.xxx:8000](http://xxx.xxx.xx.xxx:8000), meaning, it went from HTTPS to HTTP, so the referrer header was lost due to the policy.

To fix this, I went ahead and set up my server with a domain and SSL cert. After doing so, connecting from [https://play.dgraph.io/](https://play.dgraph.io/) to [https://my-domain.com/dgraph](https://my-domain.com/dgraph) totally works as expected.

And also consequently, connecting from a GraphQL client (like Altair) works as well 👍

---

<div class="post-metadata">

**Author:** ![MichelDiz](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/micheldiz/32/11873_2.png) [@MichelDiz](https://discuss.dgraph.io/u/MichelDiz)\
**Post date:** [September 22, 2021, 2:59am UTC](https://discuss.dgraph.io/t/cannot-connect-to-graphql-endpoint/15609/6 "2021-09-22T02:59:32Z")

</div>

More about this

> [@Ratel and Chrome issue](http://discuss.hypermode.com/t/ratel-and-chrome-issue/14732):
>
> Be aware of these changes in your browser. Today Chrome blocks requests on HTTPS pages for services that are HTTP. This started in the first half of this year. Not all Chromium-based browsers have this security measure. To workaround this, you have to run both Ratel and the cluster with TLS enabled. Or use another browser that doesn’t have this limitation. This also affects the Tour. You can also run a Ratel image locally with no HTTP to connect your your NON-HTTPS Dgraph cluster. By the way,…
