Skip to content
Vaptiq logo mark — V orientationVAPTIQ
All services

[ Applications ]

API Penetration Testing

REST, GraphQL and gRPC tested at the object level, where the flaws actually are.
Typical duration
4-8 days
Starting price
Scoped
You provide
Spec or collection, plus per-role tokens

[ 01 / The engagement ]

An API has no UI to constrain it, which means the client-side guardrails a web tester relies on simply are not there. We work from your spec, or rebuild one if you do not have it, and test every endpoint against every role, hunting broken object-level authorisation, mass assignment and the undocumented endpoints that never made it into the gateway policy.

[ 02 / Coverage ]

What we test, in practice.

This is the working checklist, not a marketing list. Anything your scope adds gets written into the engagement letter before we start.

Methodology

OWASP API Security Top 10OWASP ASVS
  1. 01Broken object and function level authorisation (BOLA / BFLA)
  2. 02Mass assignment and over-permissive serialisation
  3. 03GraphQL introspection, depth abuse and batching attacks
  4. 04Rate limiting, quota bypass and resource exhaustion
  5. 05JWT handling: algorithm confusion, claim tampering, revocation
  6. 06Undocumented, deprecated and shadow endpoints
  7. 07Gateway policy gaps and direct-to-origin access

[ 03 / What you get ]

Four things land at the end of every engagement.

Technical report

Every finding with CVSS v4.0 score, evidence, reproduction steps and a specific fix, written for the engineer who has to close it.

Executive summary

Two pages your board can read. Risk in business terms, with the three things that matter most called out.

Letter of attestation

A shareable document proving the test happened and what it covered, for customers and auditors who should not see the full report.

Free retest

Once you have fixed things, the same tester verifies each finding and reissues the report. Included for 90 days.

[ 04 / Questions ]

Before you commit.

No. We will build a working map from traffic capture and client bundles during recon. It adds about a day, and you keep the spec afterwards.

We agree thresholds before we start and stay under them. If testing a limit is itself in scope, we do that in a named window with your on-call aware.

Scope a api penetration testing.

Send us the target and the deadline. You get a written scope and a fixed price, usually within one working day.