Offensive Security
API Penetration Testing
Your API is the part behind the screens that holds the data. We talk to it directly, the way an attacker would, instead of going through your app and following its rules.
Coverage
What we test
The final scope follows your application and its risks. These are the areas this assessment normally covers.
-
Authentication
How tokens, keys and sessions are issued, validated, refreshed and revoked, and what happens when one is absent, expired or altered.
-
Authorisation
Whether an endpoint enforces the caller's role on every method it exposes, not only on the ones the official client uses.
-
Object-level access control
Whether an authenticated caller can read or change another user's or another tenant's objects by changing an identifier.
-
Input handling
Injection, type confusion, mass assignment, and parameters an endpoint accepts but was never meant to.
-
Rate limiting
Whether limits exist on the endpoints that need them, and whether they can be bypassed or exhausted.
-
API business logic
Sequences and state transitions the client enforces politely and the API does not enforce at all.
Next step
Scope the right amount of testing
You do not need to choose a service before contacting us. Describe the application and we will map the work to it.
Ask about api testing
Send a paragraph about what you built. We will tell you what is worth testing.