API penetration testing

Check what an API allows, not just what it returns.

REST and GraphQL testing focused on object-level access and token boundaries.

From A$6,000 ex GST for one API with under 50 endpoints.

Manually verified findings.

  • OSCP-certified testers
  • Written testing boundaries
  • Actionable remediation
What we test

A scope with a purpose.

Object and function access

Whether changing an identifier crosses a role or tenant boundary.

Tokens and input handling

Authentication flows, token expiry and unsafe data exposure in responses.

Workflow and integration abuse

Multi-step operations, GraphQL access patterns and webhooks.

Before testing

What we need from you

  • An OpenAPI specification, Postman collection or endpoint inventory.
  • Example requests and test tokens for each role.
  • API versions, rate limits and integration ownership.
Use the scoping checklist
After testing

What you can act on

  • Reproducible request and response evidence.
  • Affected endpoints and role combinations.
  • Server-side remediation guidance and stated coverage limits.

Reporting and retest terms are agreed in writing. The record separates verified fixes from outstanding work.

Limits matter

What this test does not cover

  • Load testing and destructive rate-limit testing.
  • Attacks against an integration provider.
  • The web interface. Scope it separately.
The deliverable

See what you will receive

A 19-page illustrative report built from synthetic findings, not a client report. It shows scope, evidence, severity rationale and the retest record.

See sample report

Questions before you book

Practical answers.

Can you test without API documentation?

Yes, but discovery takes time and makes coverage less predictable. We agree the discovered endpoint inventory and name the blind spots rather than implying complete coverage.

What does a penetration test cost?

From A$7,500 ex GST for one web application with its API and two user roles. That covers five testing days, the report and a retest of critical and high findings. More applications, endpoints or cloud accounts give an indicative range. The price is fixed once scope is agreed, in writing, before work starts.

How long will it take?

Testing effort and elapsed delivery time are different. We agree both after reviewing the scope, access readiness and your deadline. Leave time for remediation and a focused retest.

Ready to price your test?

The sample report is illustrative, built from synthetic findings. It is not a client report.

Get instant quote

Last reviewed: