API Penetration Testing
Role-by-role testing of your REST, GraphQL, SOAP and XML APIs — the broken-authorisation and data-exposure flaws that are the leading cause of API breaches.
What's covered
-
Object-level authorisation (BOLA/IDOR)
Can one user read or change another user's records by changing an ID?
-
Function-level authorisation
Can a low-privilege user reach admin-only operations?
-
Authentication & tokens
API keys, JWTs, OAuth flows and token handling.
-
Data exposure
Endpoints returning more data than the client needs, and mass-assignment flaws.
-
Input validation
Injection and unexpected input across every parameter.
-
Rate limiting & abuse
Resource exhaustion and business-logic abuse of your endpoints.
A clear, transparent process
Scope
Get an instant estimate, then a short call to confirm targets, timing and rules of engagement.
Test
Hands-on testing by an experienced consultant, with critical issues flagged to you as they're found.
Report
A clear report: executive summary, risk-rated findings, evidence and practical fixes.
Retest
We check your fixes and confirm they work.
Common questions
Which API types do you test?
REST/JSON, GraphQL, SOAP and XML. Mixed estates are fine — we test them together.
What do you need from us?
Documentation and, ideally, a working collection (Postman, SoapUI or similar) plus test accounts for each role. The more roles we can log in as, the more authorisation testing we can do.
How is API testing priced?
By the number of endpoints, parameters and user roles. The instant estimate tool gives a guide, then we confirm scope with you.
Can you test an API behind a mobile app?
Yes. We can test an API on its own, or as part of a mobile app engagement.
Ready to get started?
Get an instant estimate for your apis and web services test, or book a free consultation.