lol nothing to do federation, and pulling 99% out of thin air. A LOT of GraphQL APIs out there actually use `/graphql` (Facebook, Shopify, GitHub, Walmart, Wayfair, first 5 that came to mind) on the same domain. You found an issue on gusto, that's OK, no need to generalize.
With GraphQL, people see it as a separate resource from the app, so they put it under a subdomain >99% of the time. Makes sense given how GQL is suppose to "federate".
With REST APIs, we far more often just serve it straight from the same app/same subdomain. Common in Rails.