Reg. No. 40203410806 VAT LV40203410806

Theme

Book a consultation Book

2.02 Application security

API Security Testing

Manual testing of REST, GraphQL and gRPC APIs against the OWASP API Security Top 10, with emphasis on object- and function-level authorisation and multi-step abuse cases.

API vulnerabilities often depend on identity, object ownership, state and workflow logic and therefore cannot be found reliably by automated scanning alone. We review the API specification and test authentication, authorisation, object identifiers, input handling, rate limits and business processes across REST, GraphQL and gRPC.

Coverage includes the OWASP API Security Top 10, such as BOLA, BFLA, broken authentication, mass assignment, SSRF, excessive data exposure and unrestricted resource consumption. Confirmed abuse cases can be converted into regression tests, and fixes are re-tested.

OWASP API Top 10
every risk tested, API1–API10
BOLA
the #1 API risk — and the one scanners miss

01

How it works

  1. 01

    Scoping & discovery

    Inventory endpoints from OpenAPI/GraphQL specs, traffic and source; map authentication, roles and trust boundaries.

  2. 02

    Automated baseline

    Schema-aware scanning and fuzzing to clear known issues and surface candidates for manual testing.

  3. 03

    Manual exploitation

    Business-logic, BOLA/BFLA, auth-bypass, mass-assignment and SSRF testing with chained, multi-identity exploits.

  4. 04

    Reporting & enablement

    Exploitability-ranked findings with proof of impact, remediation guidance and developer walkthrough.

  5. 05

    CI regression & retest

    Wire abuse cases into the pipeline as regression tests and re-test remediated code to confirm closure (optional).

02

Packages

Essential
Focused test of a single critical API or service against the OWASP API Top 10.
Comprehensive Popular
Full API estate testing with business-logic depth and CI-integrated regression tests.
Enterprise
Ongoing API security program with continuous testing and developer enablement.

03

Frequently asked questions

How is API security testing different from a standard web application pen test?

A web-application test includes the browser-facing application, while a dedicated API assessment concentrates on REST, GraphQL or gRPC interfaces and their authentication, authorisation, data handling and business logic. We use available schemas and test different roles, object access and multi-step workflows that may not be reachable through the user interface. The two scopes can be combined where the application and API form one attack surface.

Why can’t an automated scanner find these issues?

Scanners are useful for known vulnerability patterns and some configuration errors, but authorisation and business-logic flaws require an understanding of who should be allowed to perform each action on each object. We manually vary identities, state and request sequences to determine whether access controls hold across realistic workflows.

What do you need from us to start?

Ideally, provide an OpenAPI/Swagger or GraphQL schema, test accounts for each relevant role, authentication-flow documentation and a staging or production-safe environment. If no specification exists, we can reconstruct much of the surface from application traffic or source code, although this may increase effort and leave undocumented endpoints harder to confirm.

Do you help us prevent the same issues from recurring?

Yes. Where technically suitable, validated abuse cases can be converted into regression tests for your CI/CD pipeline. We also re-test remediated code and explain the root cause and recommended control pattern to the development team.

Can this support PSD2, NIS2 or DORA compliance?

It can provide technical evidence relevant to PSD2 or open-banking security, NIS2 risk-management measures and DORA resilience testing, depending on the organisation and scope. Findings can be mapped to the OWASP API Security Top 10 and agreed control requirements. The test supports compliance evidence but does not by itself establish legal compliance.

04

Helpful tools

05

All services

Scope a test

[email protected] +371 2256 5353

Direct access to a senior specialist · Reply within 24 hours · NDA available on request