← All services
Penetration testing service
API Penetration Test
REST and GraphQL testing against the OWASP API Top 10, with particular attention to object-level authorisation — the flaw class that most often survives a web app test.
What the test covers
- Broken object-level and function-level authorisation across every endpoint
- Authentication and token handling, including JWT implementation review
- Mass assignment and excessive data exposure
- GraphQL introspection, query depth and batching abuse
- Rate limiting and resource consumption controls
- Input validation and injection across all parameters
Deliverables
- Executive summary
- CVSS-scored findings with working requests and responses as evidence
- Endpoint-by-endpoint coverage table
- Prioritised remediation roadmap
- One retest round with a signed closure letter
Out of scope
- Load and stress testing
- Upstream services outside your control