Penetration Testing / FOCUSED SERVICE

API Penetration Testing

Testing of the interfaces behind your applications and integrations, focused on whether each role and tenant can reach only the data and actions it should.

WHAT THIS SERVICE ADDRESSES

The challenge behind the engagement.

API penetration testing targets the interfaces behind your applications and integrations, where the biggest risk is one account reaching another account’s data. Working from your interface specifications and sample requests, we test whether each role and tenant can reach only the records and actions it should, by hand. We then work authentication and token handling, the process that issues and checks those access tokens. We probe requests that let a caller set fields they should not, abuse of rate limits and heavy operations, requests that trick the server into reaching internal systems, misconfiguration, and forgotten or undocumented endpoints. You receive an authorization matrix showing what each role and object can reach, findings backed by request and response evidence and rated for severity, and a retest after you remediate.

WHEN THIS IS THE RIGHT FIT

For platform and backend teams exposing APIs to partners, mobile apps, or other services. Common when a new public API launches, when a partner integration goes live, or when a customer’s due diligence asks specifically about API authorization.

THE WORK BEHIND THE SERVICE

What we do.
What you can use.

Collect specs and accounts

We ask for your interface specifications and schema, sample request collections, and test accounts across every role and tenant. We confirm the addresses for each environment, how access tokens are issued, and the rate limits to expect, so testing does not trip production throttles.

Attack authorization by hand

We test object-level and function-level access across roles and tenants, token and authentication flaws, requests that set fields a caller should not, rate-limit abuse, requests that trick the server into reaching internal systems, and forgotten endpoints. For query-based interfaces we add checks on how much a single request can expose.

Deliver the authorization matrix and retest

You receive an authorization matrix showing what each role and object can reach, findings rated for severity with request and response evidence, and fixes written for the service owners. We retest remediated findings and issue a shareable attestation letter.

IS THIS THE RIGHT ENGAGEMENT?

Who it’s for.
When you need it.

BEST SUITED FOR
  • Platform and backend teams exposing APIs to partners, mobile apps, or other services
  • Organizations running multi-tenant APIs where object-level authorization decides data separation
  • Teams publishing REST, GraphQL, or gRPC services behind role-based access
  • Businesses whose integrations move regulated or high-value data between systems
WHEN IT’S TIME TO ENGAGE
  • A new public API or partner integration is about to go live
  • A customer due-diligence review asks specifically about API authorization and tenant isolation
  • GraphQL, new endpoints, or additional tenants were added since the last test
  • An application test flagged authorization gaps that warrant deeper API coverage
AGREED AROUND YOUR ENVIRONMENT

What the scope can include.

  • Test object-level and function-level access across roles and tenants

  • Review token handling, authentication, and session flaws per endpoint

  • Probe requests that set unauthorized fields and abuse of heavy operations

  • Check server-side request abuse, misconfiguration, and forgotten endpoints

  • Exercise how much a single query-based request can expose or consume

TRANSPARENT PRICING

What it typically costs.
One rate: $150/hour.

Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and reporting, plus a retest of your fixes, included. Find the size closest to yours.

Small
$3,000–$4,800

One interface with up to about 25 functions and one or two user types

About 20–32 hours
Mid-size
$6,000–$9,000

25 to 100 functions with several user types or customer accounts

About 40–60 hours
Large
$9,600–$15,000

More than 100 functions across several interfaces, partners, and customer accounts

About 64–100 hours
WHAT MOVES THE PRICE
  • Number of functions (endpoints) and request types
  • Number of user types and customer accounts to keep separate
  • How sign-in and access tokens are issued
  • Quality of the documentation you can provide
TYPICAL TIMELINE

1–2 weeks

Get a fixed quote for your scope

Ranges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.

TANGIBLE DELIVERABLES

What you take forward.

  • Authorization matrix per role and object across the tested interfaces
  • Findings documented with request and response evidence for each interface
  • Per-interface fixes for the service owners, with severity ratings and forgotten endpoints listed
  • Retest of remediated API findings with fresh request and response evidence

Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.

SERVICE-SPECIFIC QUESTIONS

Before we get started.

Do you test every style of interface we expose, not just standard web APIs?

Yes. We test standard web interfaces as well as query-based and streaming ones. Query-based interfaces get specific attention, because a single request can pull far more data than intended if access is not checked at every level. Whatever the style, give us the schema or specification for each service and we build coverage around it.

How do you find undocumented endpoints?

We start from the specification you provide, then look beyond it. Watching real client traffic, reviewing client-side and mobile code, probing predictable routes, and comparing environments all surface forgotten endpoints the specification omits. Undocumented routes are exactly where access-control gaps tend to hide, so we treat the specification as a starting point, not the boundary.

REFERENCE POINTS
START AT THE SOURCE

Let’s find your next move.

A focused conversation. A clear scope. A practical path to stronger security.

Let’s talk security