API
Penetration Testing

Security testing of your REST, GraphQL, SOAP, and gRPC APIs against the OWASP API Security Top 10 — broken object-level authorisation, mass assignment, and the data-exposure flaws automated tools routinely miss.

Overview

Your APIs are the real attack surface.

Modern applications are mostly API. They carry your most sensitive operations and data — and authorisation flaws at the API layer are now the single most exploited class of web vulnerability.

We test your APIs the way an attacker would: enumerating endpoints, abusing object and function-level authorisation, chaining business logic, and probing for data exposure the UI never reveals. Every finding is manually verified and scored with CVSS, with a free retest within 60 days.


Coverage

What we test.

Full coverage of the OWASP API Security Top 10 and the abuse cases unique to your business logic.

Methodologies: OWASP API Top 10 OWASP WSTG CWE Top 25 CVSS v3.1 PTES

FAQ

API penetration testing FAQ

The questions we're asked most about scope, cost, and timing.

How much does an API penetration test cost?
An API penetration test typically costs €2,000–3,500 for a small API and €4,000–7,000 for a larger API with many endpoints and roles. Use our online estimator for a tailored figure.
How long does an API penetration test take?
Most API tests take 3 to 8 working days of active testing plus reporting, depending on endpoints and authorisation complexity.
What is tested in an API penetration test?
The OWASP API Security Top 10 — BOLA/IDOR, broken authentication, excessive data exposure, mass assignment, rate-limiting bypass, and injection — across REST, GraphQL, SOAP, and gRPC.
Do you test REST and GraphQL APIs?
Yes — REST, GraphQL, SOAP, and gRPC, including schema introspection, query batching abuse, and authorisation flaws specific to each style.
How is API testing different from web application testing?
Web testing focuses on the front end; API testing targets the endpoints directly — per-object authorisation, data exposure, and logic abuse the UI never exposes. Many engagements include both.
What do you need to scope an API test?
API documentation (OpenAPI/Swagger, Postman collection, or similar), example requests, and test credentials for each role. The more complete the docs, the deeper the test.
Can you test undocumented or internal APIs?
Yes — we can work from traffic captures and discovery where documentation is incomplete, though good docs make testing more thorough.
Do you test authentication and SSO flows?
Yes — token handling, OAuth/OIDC, JWT validation, and session management are core parts of an API test.
Will testing affect our rate limits or data?
We agree rules of engagement up front and avoid destructive actions; testing against staging or test tenants is preferred where available.
Can you test the API and the web app together?
Yes — and we often recommend it, since combined testing catches issues that span both layers.

Related services

Explore more.

Ready to secure your APIs?

A 30-minute scoping call costs nothing. A breach costs considerably more.

Book a meeting Send an email