APIs & web services

API Penetration Testing

Role-by-role testing of your REST, GraphQL, SOAP and XML APIs — the broken-authorisation and data-exposure flaws that are the leading cause of API breaches.

What we test

What's covered

  • Object-level authorisation (BOLA/IDOR)

    Can one user read or change another user's records by changing an ID?

  • Function-level authorisation

    Can a low-privilege user reach admin-only operations?

  • Authentication & tokens

    API keys, JWTs, OAuth flows and token handling.

  • Data exposure

    Endpoints returning more data than the client needs, and mass-assignment flaws.

  • Input validation

    Injection and unexpected input across every parameter.

  • Rate limiting & abuse

    Resource exhaustion and business-logic abuse of your endpoints.

How it works

A clear, transparent process

  1. Scope

    Get an instant estimate, then a short call to confirm targets, timing and rules of engagement.

  2. Test

    Hands-on testing by an experienced consultant, with critical issues flagged to you as they're found.

  3. Report

    A clear report: executive summary, risk-rated findings, evidence and practical fixes.

  4. Retest

    We check your fixes and confirm they work.

FAQ

Common questions

Which API types do you test?

REST/JSON, GraphQL, SOAP and XML. Mixed estates are fine — we test them together.

What do you need from us?

Documentation and, ideally, a working collection (Postman, SoapUI or similar) plus test accounts for each role. The more roles we can log in as, the more authorisation testing we can do.

How is API testing priced?

By the number of endpoints, parameters and user roles. The instant estimate tool gives a guide, then we confirm scope with you.

Can you test an API behind a mobile app?

Yes. We can test an API on its own, or as part of a mobile app engagement.

Ready to get started?

Get an instant estimate for your apis and web services test, or book a free consultation.

Get an estimate