@hongminhee洪 民憙 (Hong Minhee) this doesn't address serious concerns with GraphQL raised by the article I've linked. Both authorisation and rate limiting are crucial for client2server communication. You may achieve acceptable results using GraphQL with trivial well-behaved clients, in 2025 you can't assume every client is well-behaved. Bots will abuse the API no question, and without proper authorization and rate limiting it will bring servers down.
OpenAPI is much more flexible and doesn't have these issues.