Manual assessment of REST and GraphQL APIs for broken access control, authorization flaws, and logic issues that automated scanning tools typically miss.
APIs fail differently than traditional web apps. These are the categories we test on essentially every engagement.
IDOR-style access across endpoints, and whether admin or privileged functions are reachable by a standard authenticated user.
JWT validation and signature checks, API key exposure, OAuth flow abuse, and rate limiting on authentication endpoints.
Chaining calls in an unintended order, mass assignment on write endpoints, and excessive data exposure in API responses.
Injection via API parameters, GraphQL introspection abuse, and query depth or complexity attacks against GraphQL endpoints specifically.
Send over your API documentation, the compliance driver behind it, and your timeline, and you'll get a proposal back directly.