The challenge behind the engagement.
API penetration testing targets the interfaces behind your applications and integrations, where the biggest risk is one account reaching another account’s data. Working from your interface specifications and sample requests, we test whether each role and tenant can reach only the records and actions it should, by hand. We then work authentication and token handling, the process that issues and checks those access tokens. We probe requests that let a caller set fields they should not, abuse of rate limits and heavy operations, requests that trick the server into reaching internal systems, misconfiguration, and forgotten or undocumented endpoints. You receive an authorization matrix showing what each role and object can reach, findings backed by request and response evidence and rated for severity, and a retest after you remediate.
For platform and backend teams exposing APIs to partners, mobile apps, or other services. Common when a new public API launches, when a partner integration goes live, or when a customer’s due diligence asks specifically about API authorization.
What we do.
What you can use.
Collect specs and accounts
We ask for your interface specifications and schema, sample request collections, and test accounts across every role and tenant. We confirm the addresses for each environment, how access tokens are issued, and the rate limits to expect, so testing does not trip production throttles.
Attack authorization by hand
We test object-level and function-level access across roles and tenants, token and authentication flaws, requests that set fields a caller should not, rate-limit abuse, requests that trick the server into reaching internal systems, and forgotten endpoints. For query-based interfaces we add checks on how much a single request can expose.
Deliver the authorization matrix and retest
You receive an authorization matrix showing what each role and object can reach, findings rated for severity with request and response evidence, and fixes written for the service owners. We retest remediated findings and issue a shareable attestation letter.
Who it’s for.
When you need it.
- Platform and backend teams exposing APIs to partners, mobile apps, or other services
- Organizations running multi-tenant APIs where object-level authorization decides data separation
- Teams publishing REST, GraphQL, or gRPC services behind role-based access
- Businesses whose integrations move regulated or high-value data between systems
- A new public API or partner integration is about to go live
- A customer due-diligence review asks specifically about API authorization and tenant isolation
- GraphQL, new endpoints, or additional tenants were added since the last test
- An application test flagged authorization gaps that warrant deeper API coverage
What the scope can include.
- 01
Test object-level and function-level access across roles and tenants
- 02
Review token handling, authentication, and session flaws per endpoint
- 03
Probe requests that set unauthorized fields and abuse of heavy operations
- 04
Check server-side request abuse, misconfiguration, and forgotten endpoints
- 05
Exercise how much a single query-based request can expose or consume
What it typically costs.
One rate: $150/hour.
Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and reporting, plus a retest of your fixes, included. Find the size closest to yours.
One interface with up to about 25 functions and one or two user types
About 20–32 hours25 to 100 functions with several user types or customer accounts
About 40–60 hoursMore than 100 functions across several interfaces, partners, and customer accounts
About 64–100 hours- Number of functions (endpoints) and request types
- Number of user types and customer accounts to keep separate
- How sign-in and access tokens are issued
- Quality of the documentation you can provide
Ranges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.
What you take forward.
- Authorization matrix per role and object across the tested interfaces
- Findings documented with request and response evidence for each interface
- Per-interface fixes for the service owners, with severity ratings and forgotten endpoints listed
- Retest of remediated API findings with fresh request and response evidence
Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.
Before we get started.
Do you test every style of interface we expose, not just standard web APIs?
Yes. We test standard web interfaces as well as query-based and streaming ones. Query-based interfaces get specific attention, because a single request can pull far more data than intended if access is not checked at every level. Whatever the style, give us the schema or specification for each service and we build coverage around it.
How do you find undocumented endpoints?
We start from the specification you provide, then look beyond it. Watching real client traffic, reviewing client-side and mobile code, probing predictable routes, and comparing environments all surface forgotten endpoints the specification omits. Undocumented routes are exactly where access-control gaps tend to hide, so we treat the specification as a starting point, not the boundary.
- NIST SP 800-115: Technical Guide to Information Security Testing and Assessment
- OWASP Web Security Testing Guide
- OWASP Top 10 API Security Risks – 2023
- Common Vulnerability Scoring System version 4.0: Specification Document
- NIST SP 800-82 Rev. 3: Guide to Operational Technology (OT) Security
- Penetration Testing - Amazon Web Services (AWS)
