API Penetration Testing

Your APIs carry your most sensitive data — and they're where modern breaches happen. We manually test REST and GraphQL APIs for the authorisation flaws, logic abuse and data exposure that automated tools structurally cannot find.

What is an API penetration test?

An API penetration test is a manual, authorised attack against your application programming interfaces — the REST, GraphQL or gRPC endpoints behind your web and mobile apps. APIs fail differently from websites: the highest-impact API vulnerabilities are almost always authorisation flaws (can user A read user B's data?) and business logic abuse, neither of which automated scanners can meaningfully detect.

We test every endpoint, in every role, with the mindset of an attacker who has read your API like documentation — because that's exactly what real attackers do.

What we test

  • Broken object-level authorisation (BOLA/IDOR). The #1 API risk: accessing other users' and other tenants' objects by manipulating identifiers.
  • Authentication & token handling. JWT implementation flaws, API key exposure, OAuth flows, token scoping and expiry.
  • Broken function-level authorisation. Admin and internal endpoints reachable by regular users — or by no authentication at all.
  • Business logic & abuse cases. Race conditions, workflow bypasses, mass assignment, rate-limit gaps that enable enumeration and abuse.
  • GraphQL-specific issues. Introspection exposure, query depth/complexity abuse, field-level authorisation gaps and batching attacks.
  • Data exposure. Over-fetching, verbose errors, and responses that leak far more than the UI ever displays.

No API spec? No problem.

An OpenAPI/Swagger spec or Postman collection is the fastest way to scope an API test — but it's not required. We routinely map APIs by instrumenting the web or mobile apps that consume them, including decompiling Android and iOS applications to enumerate endpoints the documentation forgot.

How an engagement runs

Free 30-minute scoping call, fixed quote within one business day. Most API tests run 5–8 testing days. Critical findings are escalated in real time, and you receive an executive summary, full technical report, debrief call and a free 90-day retest of fixed issues. API tests pair naturally with a web application penetration test when one engagement can cover both.

FAQ

Frequently asked questions

How much does an API penetration test cost?

Most API penetration tests run 5–8 testing days, typically landing between AU$8,000 and AU$15,000 depending on the number of endpoints, roles and environments. We provide a fixed quote within one business day of a scoping call.

Do you need our API documentation to test?

It helps but is not required. An OpenAPI/Swagger spec or Postman collection speeds up coverage, but we routinely map undocumented APIs by intercepting the web and mobile applications that use them — including decompiling mobile apps to find endpoints that aren't documented anywhere.

How is API testing different from web application testing?

Web application tests focus on what a user can do through the interface; API tests attack the layer underneath, where authorisation mistakes and over-exposed data live. Many critical API flaws — like cross-tenant data access — are invisible from the UI. If your product has both, we usually recommend testing them together in one engagement.

Can you test GraphQL APIs?

Yes. GraphQL has its own failure modes — introspection exposure, field-level authorisation gaps, query complexity abuse and batching attacks — and we test all of them, alongside the standard authorisation and logic testing we apply to any API.

Will testing disrupt our production API?

We agree rules of engagement up front and test carefully, avoiding destructive operations and respecting rate limits. Most clients see no measurable impact. If you prefer, we can test a staging environment that mirrors production.

What do we receive at the end?

An executive summary, a technical report with reproduction steps and remediation guidance for every finding, a debrief call with your engineers, an attestation letter for customers and auditors, and a free retest of fixed issues within 90 days.

Contact

Talk to us

Tell us what you're trying to protect, secure or build. We'll come back with a plan.

Prefer to talk live? Book a call →

By submitting this form, you agree to our privacy policy.

Got an API that needs testing?

Drop your email and we'll come back with a plan within one business day.