Looking for a penetration test? Fixed-scope engagements for SOC 2, ISO 27001 & HIPAA.Get a quote today →
Request a Quote
Services

API Security Testing

Manual assessment of REST and GraphQL APIs for broken access control, authorization flaws, and logic issues that automated scanning tools typically miss.

At a Glance
Typical Duration1–2 Weeks
Delivery FormatWritten Report + Walkthrough Call
Best ForREST & GraphQL APIs, Mobile Backends
FrameworksSOC 2, ISO 27001, PCI-DSS

Coverage across your API surface

APIs fail differently than traditional web apps. These are the categories we test on essentially every engagement.

01

Broken Object & Function Level Authorization

Core Coverage

IDOR-style access across endpoints, and whether admin or privileged functions are reachable by a standard authenticated user.

  • Every endpoint mapped against every role, not just the ones in the provided documentation
02

Authentication & Token Handling

Core Coverage

JWT validation and signature checks, API key exposure, OAuth flow abuse, and rate limiting on authentication endpoints.

  • Token expiry, revocation, and refresh flow tested directly
03

Business Logic Across Endpoints

Core Coverage

Chaining calls in an unintended order, mass assignment on write endpoints, and excessive data exposure in API responses.

  • Includes internal and partner-facing endpoints, not only what's documented for public consumption
04

Schema & Input Validation

Core Coverage

Injection via API parameters, GraphQL introspection abuse, and query depth or complexity attacks against GraphQL endpoints specifically.

  • REST and GraphQL tested with methodology specific to each, not one generic checklist

What to expect

What's Included

  • Full endpoint enumeration, not limited to what's in your API documentation
  • Both REST and GraphQL testing methodology where your API uses both
  • Testing against staging or a dedicated environment to avoid production side-effects
  • Manual verification of every finding before it reaches the report

Deliverables

  • A fixed price agreed before testing starts
  • Reproduction steps (including request/response examples) for every finding
  • Severity ratings mapped to CVSS
  • One retest included once fixes are deployed

Ready to scope an API test?

Send over your API documentation, the compliance driver behind it, and your timeline, and you'll get a proposal back directly.