Application security

API Penetration Testing

Testing the REST and GraphQL endpoints your web app, mobile app and partners depend on — where authorization, not the perimeter, is the control that matters.

Overview

What it covers

APIs have quietly become the largest attack surface most organizations have, and the most under-tested. There is no UI to constrain what an attacker sends, so the endpoint itself has to enforce every rule. Broken object-level authorization — an id in a request accepted without an ownership check — is the single most common serious finding, and it is invisible to a scanner. We test against the OWASP API Security Top 10.

Scope

What we test

Every engagement is scoped to your environment, but these are the areas a API test engagement covers.

Broken object-level authorization (BOLA)

Whether changing an identifier in a request returns data that belongs to someone else.

Broken function-level authorization

Whether a standard user can call the endpoints meant for admins or other roles.

Token scope and lifetime

How access and refresh tokens are issued, scoped, and whether they can be replayed or extended.

Mass assignment

Whether extra fields in a request can set attributes the client was never meant to control.

Rate limiting and resource abuse

Enumeration, credential stuffing and the denial-of-wallet risks specific to APIs.

Methodology

How the engagement runs

The same defensible sequence every time.

Scoping and a fixed-price quote, reconnaissance and threat modeling, manual exploitation with same-day escalation of critical findings, a report your engineers and auditors can both use, and a free retest once fixes ship.

1
Scoping & rules of engagement
Fixed-price quote in ~1 hour
2
Reconnaissance & threat modeling
Prioritize the paths that matter
3
Manual exploitation
Same-day critical escalation
4
Reporting
CVSS v3.1, reproduction, control mapping
5
Remediation retest
Included in the engagement
Questions

API test, answered

Do you test GraphQL as well as REST?

Yes. GraphQL introduces its own issues — introspection exposure, nested-query abuse, and authorization applied per-resolver — and we test for all of them alongside REST.

Can you test undocumented APIs?

Yes. We work from whatever you have — an OpenAPI spec, a Postman collection, or traffic captured from the app — and enumerate what documentation misses.

Ready to scope a API test?

A 30-minute call gets you a fixed price and a start date, usually within the hour.