[ Applications ]
API Penetration Testing
- Typical duration
- 4-8 days
- Starting price
- Scoped
- You provide
- Spec or collection, plus per-role tokens
[ 01 / The engagement ]
An API has no UI to constrain it, which means the client-side guardrails a web tester relies on simply are not there. We work from your spec, or rebuild one if you do not have it, and test every endpoint against every role, hunting broken object-level authorisation, mass assignment and the undocumented endpoints that never made it into the gateway policy.
[ 02 / Coverage ]
What we test, in practice.
This is the working checklist, not a marketing list. Anything your scope adds gets written into the engagement letter before we start.
Methodology
- 01Broken object and function level authorisation (BOLA / BFLA)
- 02Mass assignment and over-permissive serialisation
- 03GraphQL introspection, depth abuse and batching attacks
- 04Rate limiting, quota bypass and resource exhaustion
- 05JWT handling: algorithm confusion, claim tampering, revocation
- 06Undocumented, deprecated and shadow endpoints
- 07Gateway policy gaps and direct-to-origin access
[ 03 / What you get ]
Four things land at the end of every engagement.
Technical report
Every finding with CVSS v4.0 score, evidence, reproduction steps and a specific fix, written for the engineer who has to close it.
Executive summary
Two pages your board can read. Risk in business terms, with the three things that matter most called out.
Letter of attestation
A shareable document proving the test happened and what it covered, for customers and auditors who should not see the full report.
Free retest
Once you have fixed things, the same tester verifies each finding and reissues the report. Included for 90 days.
[ 04 / Questions ]
Before you commit.
No. We will build a working map from traffic capture and client bundles during recon. It adds about a day, and you keep the spec afterwards.
We agree thresholds before we start and stay under them. If testing a limit is itself in scope, we do that in a named window with your on-call aware.
Often scoped together
All services →Web Application Penetration Testing
Manual testing of the application your customers actually log in to.
Mobile Application Penetration Testing
iOS and Android, tested on real devices, binary, traffic and backend.
Black Box Penetration Testing
We start with your domain name and nothing else, exactly like a real attacker.
Scope a api penetration testing.
Send us the target and the deadline. You get a written scope and a fixed price, usually within one working day.