Per the Wiz API reference: match the path to how base_url was registered so the composed URL contains exactly one /graphql.

Context: Problem: Calls to the Wiz API fail with 404. Wiz exposes exactly one GraphQL endpoint. If the connector was registered with base_url https://api.YOUR-DC.app.wiz.io (no path suffix), call with path /graphql. If base_url already ends in /graphql, call with path / instead - otherwise the client composes .../graphql/graphql and Wiz returns 404. The first successful call against a new connector confirms which split applies; reuse that path for every call in the session.