API Security Testing
Manual testing of REST, GraphQL and gRPC APIs against the OWASP API Security Top 10, with emphasis on object- and function-level authorisation and multi-step abuse cases.
API vulnerabilities often depend on identity, object ownership, state and workflow logic and therefore cannot be found reliably by automated scanning alone. We review the API specification and test authentication, authorisation, object identifiers, input handling, rate limits and business processes across REST, GraphQL and gRPC.
Coverage includes the OWASP API Security Top 10, such as BOLA, BFLA, broken authentication, mass assignment, SSRF, excessive data exposure and unrestricted resource consumption. Confirmed abuse cases can be converted into regression tests, and fixes are re-tested.
- OWASP API Top 10
- every risk tested, API1–API10
- BOLA
- the #1 API risk — and the one scanners miss
How it works
-
01
Scoping & discovery
Inventory endpoints from OpenAPI/GraphQL specs, traffic and source; map authentication, roles and trust boundaries.
-
02
Automated baseline
Schema-aware scanning and fuzzing to clear known issues and surface candidates for manual testing.
-
03
Manual exploitation
Business-logic, BOLA/BFLA, auth-bypass, mass-assignment and SSRF testing with chained, multi-identity exploits.
-
04
Reporting & enablement
Exploitability-ranked findings with proof of impact, remediation guidance and developer walkthrough.
-
05
CI regression & retest
Wire abuse cases into the pipeline as regression tests and re-test remediated code to confirm closure (optional).
Packages
- Essential
- Focused test of a single critical API or service against the OWASP API Top 10.
- Comprehensive Popular
- Full API estate testing with business-logic depth and CI-integrated regression tests.
- Enterprise
- Ongoing API security program with continuous testing and developer enablement.
Frequently asked questions
How is API security testing different from a standard web application pen test?
A web-application test includes the browser-facing application, while a dedicated API assessment concentrates on REST, GraphQL or gRPC interfaces and their authentication, authorisation, data handling and business logic. We use available schemas and test different roles, object access and multi-step workflows that may not be reachable through the user interface. The two scopes can be combined where the application and API form one attack surface.
Why can’t an automated scanner find these issues?
Scanners are useful for known vulnerability patterns and some configuration errors, but authorisation and business-logic flaws require an understanding of who should be allowed to perform each action on each object. We manually vary identities, state and request sequences to determine whether access controls hold across realistic workflows.
What do you need from us to start?
Ideally, provide an OpenAPI/Swagger or GraphQL schema, test accounts for each relevant role, authentication-flow documentation and a staging or production-safe environment. If no specification exists, we can reconstruct much of the surface from application traffic or source code, although this may increase effort and leave undocumented endpoints harder to confirm.
Do you help us prevent the same issues from recurring?
Yes. Where technically suitable, validated abuse cases can be converted into regression tests for your CI/CD pipeline. We also re-test remediated code and explain the root cause and recommended control pattern to the development team.
Can this support PSD2, NIS2 or DORA compliance?
It can provide technical evidence relevant to PSD2 or open-banking security, NIS2 risk-management measures and DORA resilience testing, depending on the organisation and scope. Findings can be mapped to the OWASP API Security Top 10 and agreed control requirements. The test supports compliance evidence but does not by itself establish legal compliance.
Helpful tools
- Scope a test
Create a scoped brief in one minute
- Security maturity assessment
Assess your organization across six domains
All services
- AI & LLM Security
Assess the security and governance of AI systems.
- Secure Code Review & SAST
Find security defects in source code before release.
- DevSecOps & Secure CI/CD
Integrate repeatable security checks and enforcement into CI/CD.
Scope a test
[email protected] +371 2256 5353
Direct access to a senior specialist · Reply within 24 hours · NDA available on request