API penetration testing

Check what an API allows, not just what it returns.

REST and GraphQL testing focused on object-level access and token boundaries.

Human-led testing.
Manually verified findings.

  • OSCP-certified testers
  • Written testing boundaries
  • Actionable remediation
What we investigate

A scope with a purpose.

Object and function access

Whether changing an identifier crosses a role or tenant boundary.

Tokens and input handling

Authentication flows, token expiry and unsafe data exposure in responses.

Workflow and integration abuse

Multi-step operations, GraphQL access patterns and webhooks.

Before testing

What we need from you

  • An OpenAPI specification, Postman collection or endpoint inventory.
  • Example requests and test tokens for each role.
  • API versions, rate limits and integration ownership.
Use the scoping checklist
After testing

What you can act on

  • Reproducible request and response evidence.
  • Affected endpoints and role combinations.
  • Server-side remediation guidance and stated coverage limits.

Reporting and retest terms are agreed in writing. The record separates verified fixes from outstanding work.

Limits matter

What this test does not cover

  • Load testing and destructive rate-limit testing.
  • Attacks against an integration provider.
  • The web interface. Scope it separately.
Instant quote

Get an instant quote in 2 minutes

Answer four questions. The indicative price updates as you go. Prices are ex GST.

Indicative until we confirm scope in writing, within one business day. We use your details only to reply. See our Privacy notice.

Questions before you book

Practical answers.

Can you test without API documentation?

Yes, but discovery takes time and makes coverage less predictable. We agree the discovered endpoint inventory and name the blind spots rather than implying complete coverage.

What does a penetration test cost?

From A$7,500 ex GST for one web application with its API and two user roles. That covers five testing days, the report and a retest of critical and high findings. More applications, endpoints or cloud accounts give an indicative range. The price is fixed once scope is agreed, in writing, before work starts.

How long will it take?

Testing effort and elapsed delivery time are different. We agree both after reviewing the scope, access readiness and your deadline. Leave time for remediation and a focused retest.

An API is rarely the whole scope. The interface in front of it is web application penetration testing, a native client is mobile application penetration testing, and the account underneath is cloud penetration testing. Bring an OpenAPI specification and two accounts per role, for the reasons set out in how to scope a penetration test.

Request a quote

Send the starting point from this page.

Only your email is required. Scope and fee are agreed in writing.

Your enquiry

Request a quote

Only your email is required. Scope and fee are agreed in writing.

An enquiry, not an instant quote or a booking. We reply within one business day. We use your details only to reply. Our Privacy notice names every processor.

Last reviewed: