Offensive Security

API Penetration Testing

Your API is the part behind the screens that holds the data. We talk to it directly, the way an attacker would, instead of going through your app and following its rules.

Coverage

What we test

The final scope follows your application and its risks. These are the areas this assessment normally covers.

  • Authentication

    How tokens, keys and sessions are issued, validated, refreshed and revoked, and what happens when one is absent, expired or altered.

  • Authorisation

    Whether an endpoint enforces the caller's role on every method it exposes, not only on the ones the official client uses.

  • Object-level access control

    Whether an authenticated caller can read or change another user's or another tenant's objects by changing an identifier.

  • Input handling

    Injection, type confusion, mass assignment, and parameters an endpoint accepts but was never meant to.

  • Rate limiting

    Whether limits exist on the endpoints that need them, and whether they can be bypassed or exhausted.

  • API business logic

    Sequences and state transitions the client enforces politely and the API does not enforce at all.

Next step

Scope the right amount of testing

You do not need to choose a service before contacting us. Describe the application and we will map the work to it.

How testing worksAssessments and pricing

Ask about api testing

Send a paragraph about what you built. We will tell you what is worth testing.