API Security Testing

APIs carry your most sensitive logic β€” and authorization is where they break. Dedicated testing for REST, GraphQL, and gRPC surfaces.

Why this matters: APIs are where applications quietly leak: one endpoint that trusts the client for authorization can expose every tenant’s data. Our published CVE breakdowns β€” password-reset flaws, authentication bypasses β€” mostly lived at the API layer. This service tests that layer on its own terms, not as an afterthought to a web app scan.

What we cover

  • Broken object-level and function-level authorization (BOLA/BOPLA)
  • Mass assignment and excessive data exposure
  • Authentication: token design, lifetimes, and refresh handling
  • Rate limiting, enumeration, and business-logic abuse
  • GraphQL specifics: introspection, depth abuse, batching attacks
  • Documentation-free testing when specs are missing or stale

How we test

1Surface mapping

Endpoints, parameters, and roles mapped from traffic, docs, or client code β€” even undocumented routes.

2Authorization matrix

Every state-changing endpoint tested across roles and tenants: who can call what, and what comes back.

3Logic & abuse cases

Business flows stress-tested: quotas, payments, workflows, and enumeration paths.

4Report & retest

Findings with reproduction requests, severity, and fixes; free retest after remediation.

What you get

  • Authorization matrix with every gap marked
  • Technical report with reproducible request/response evidence
  • Developer-ready fixes per endpoint
  • Free retest of fixed findings

The engagement at a glance

πŸ“ž Free scoping call

A short conversation about your environment. You receive a written scope, timeline, and fixed quote β€” no obligation.

✍️ Signed authorization

Testing begins only with your written permission and agreed rules of engagement. Always.

⏱️ Time-boxed delivery

A calendar agreed before we start, with an agreed communication plan while testing runs.

πŸ” Retest included

A verification pass over everything you fix β€” included in the price, not an add-on.

See the full engagement process β†’ and how pricing is scoped in our public pricing guide.

Related research from Hmmnm

Common questions

We have no API documentation β€” can you still test?

Yes. We reconstruct the surface from client traffic and application behavior. Undocumented endpoints are frequently where the interesting findings live.

Is this different from your web application testing?

It is a deeper pass on the API layer specifically. Many clients start with the web application test and add dedicated API testing when APIs are their product or primary surface.

GraphQL too?

Yes β€” introspection exposure, query depth abuse, batching-based rate-limit bypass, and per-field authorization gaps are all in scope.

Authorization first, always. Testing happens only with your written permission and agreed rules of engagement β€” the same ethics that govern responsible disclosure on this site.

Want this assessed for your environment?

A short scoping conversation is enough to get a fixed quote. No obligation β€” a researcher replies.

Start the conversation β†’