Skip to content
MD-5

// API Pentest

API Penetration Testing

Testing of REST and GraphQL APIs for broken object-level authorization, auth flaws, mass assignment and data over-exposure.

Overview

APIs now carry most of the data in a modern application, and most of the serious findings. Mobile apps, single-page front-ends and partner integrations all talk to the same endpoints, and a single missing authorization check exposes every record behind it.

An API penetration test works through your endpoints methodically, as each type of caller, against the OWASP API Security Top 10, and reports exactly which requests break which rules.

Who this is for

  • Products with a mobile app or single-page front-end backed by an API
  • Companies exposing a public or partner API
  • Multi-tenant SaaS platforms where tenant isolation is critical

What gets tested

Authorization

  • Broken object-level authorization (BOLA / IDOR)
  • Broken function-level authorization across roles
  • Tenant isolation in multi-tenant APIs

Authentication & tokens

  • API key, OAuth 2.0 and JWT handling
  • Token validation, expiry and revocation
  • Credential and token leakage

Data handling

  • Excessive data exposure in responses
  • Mass assignment of protected properties
  • Injection through parameters, headers and bodies

Abuse resistance

  • Rate limiting and resource consumption
  • Sensitive business flows (sign-up, checkout, transfers)
  • GraphQL introspection, batching and query depth

What you receive

  • Executive summary and per-endpoint technical findings
  • Reproducible requests for every finding (ready for Burp Suite / curl)
  • Specific remediation guidance for your framework
  • Live readout call to walk your team through the results
  • Retest of fixed findings and an updated report
  • Letter of attestation you can share with customers and auditors

Standards followed

  • OWASP API Security Top 10 (2023)
  • OWASP WSTG
  • CVSS v3.1 / v4.0

Read the full testing methodology.

// Process

How the engagement runs

  1. 01 Day 0

    Scope

    A short call to agree targets, test type, dates and rules of engagement. You get a quote for that scope, then written authorization is signed before any testing starts.

  2. 02 Days 1 to 10

    Test

    Hands-on, tool-assisted testing aligned to OWASP and PTES, with every finding verified. Anything critical is reported to you immediately, not saved for the report.

  3. 03 +3 days

    Report

    A clear report: executive summary, then every finding with severity, evidence, reproduction steps and a specific fix. Followed by a readout call.

  4. 04 When you’re ready

    Retest

    Once fixes are in, we verify each one and issue an updated report and an attestation letter you can share with customers and auditors.

// FAQ

API Pentest questions

What do you need from us?

API documentation (OpenAPI/Swagger spec or a Postman collection), credentials for each role, and a test environment. Without documentation the test still works, but more time goes into mapping the API.

Can you test our GraphQL API?

Yes. GraphQL has its own failure modes (introspection exposure, batching attacks, and authorization enforced per resolver), which are covered alongside the usual API checks.

Should we test the web app and API together?

If your web app is a front-end for the same API, testing them together is usually cheaper than two separate engagements. We’ll scope it as one.

// Further reading

// Also available

Other services

Web App Pentest

An authenticated test of your web application against the OWASP Top 10 and the business-logic flaws scanners never find.

Network Pentest

External testing of everything you expose to the internet, and internal testing of what an attacker could reach once inside.

Vulnerability Assessment

A fast, affordable baseline: automated scanning across your estate with every result validated, so you get a list of real issues, not 400 pages of noise.