API Penetration Testing
Testing the REST and GraphQL endpoints your web app, mobile app and partners depend on — where authorization, not the perimeter, is the control that matters.
What it covers
APIs have quietly become the largest attack surface most organizations have, and the most under-tested. There is no UI to constrain what an attacker sends, so the endpoint itself has to enforce every rule. Broken object-level authorization — an id in a request accepted without an ownership check — is the single most common serious finding, and it is invisible to a scanner. We test against the OWASP API Security Top 10.
What we test
Every engagement is scoped to your environment, but these are the areas a API test engagement covers.
Broken object-level authorization (BOLA)
Whether changing an identifier in a request returns data that belongs to someone else.
Broken function-level authorization
Whether a standard user can call the endpoints meant for admins or other roles.
Token scope and lifetime
How access and refresh tokens are issued, scoped, and whether they can be replayed or extended.
Mass assignment
Whether extra fields in a request can set attributes the client was never meant to control.
Rate limiting and resource abuse
Enumeration, credential stuffing and the denial-of-wallet risks specific to APIs.
How the engagement runs
The same defensible sequence every time.
Scoping and a fixed-price quote, reconnaissance and threat modeling, manual exploitation with same-day escalation of critical findings, a report your engineers and auditors can both use, and a free retest once fixes ship.
API test, answered
Do you test GraphQL as well as REST?
Yes. GraphQL introduces its own issues — introspection exposure, nested-query abuse, and authorization applied per-resolver — and we test for all of them alongside REST.
Can you test undocumented APIs?
Yes. We work from whatever you have — an OpenAPI spec, a Postman collection, or traffic captured from the app — and enumerate what documentation misses.
Explore related services
Web Application Penetration Testing
Broken access control, cross-tenant authorization, and the business logic flaws no scanner has a signature for.
Network Penetration Testing
Credential paths, lateral movement, privilege escalation, and whether segmentation holds under pressure.
Cloud Penetration Testing
Over-broad IAM, exposed storage, metadata service access, and escalation from one compromised workload.
Ready to scope a API test?
A 30-minute call gets you a fixed price and a start date, usually within the hour.