1. Home
  2. Services
  3. Penetration testing

API penetration testing

APIs carry your most sensitive data and are often the least visible part of your attack surface. We map every endpoint, then test each one across user roles for broken object-level and function-level authorization, mass assignment, and excessive data exposure.

What we test

  • Broken object level authorization (BOLA / IDOR)
  • Broken function level authorization and privilege escalation
  • Authentication: JWT, OAuth 2.0, OpenID Connect, and API keys
  • Mass assignment and excessive data exposure
  • Rate limiting and unrestricted resource consumption
  • GraphQL introspection, batching, and query depth abuse
  • Injection and SSRF through API parameters
  • Undocumented, deprecated, and shadow endpoints

How we approach it

We work from your OpenAPI spec, Postman collection, or GraphQL schema, and fill gaps by observing real client traffic. Each endpoint is called as every role and as no one, and we chain calls together to reach data that a single request would not expose.

What you get

  • Executive summary written for leadership and customers
  • Technical findings with CVSS scores, evidence, and reproduction steps
  • Specific remediation guidance for each finding
  • One retest of reported findings within 90 days, with an updated report
  • Attestation letter you can share with customers and auditors

Typical use cases

  • Public, partner, or customer-facing APIs
  • Mobile apps and single-page apps backed by an API
  • Multi-tenant SaaS platforms
  • Integrations that handle payments, health, or personal data

Tell us what you need tested.

Send a few details and we'll set up a short scoping call, then follow up with a fixed-fee proposal.

Request a quote