API Security Testing
APIs carry your most sensitive logic β and authorization is where they break. Dedicated testing for REST, GraphQL, and gRPC surfaces.
What we cover
- Broken object-level and function-level authorization (BOLA/BOPLA)
- Mass assignment and excessive data exposure
- Authentication: token design, lifetimes, and refresh handling
- Rate limiting, enumeration, and business-logic abuse
- GraphQL specifics: introspection, depth abuse, batching attacks
- Documentation-free testing when specs are missing or stale
How we test
Endpoints, parameters, and roles mapped from traffic, docs, or client code β even undocumented routes.
Every state-changing endpoint tested across roles and tenants: who can call what, and what comes back.
Business flows stress-tested: quotas, payments, workflows, and enumeration paths.
Findings with reproduction requests, severity, and fixes; free retest after remediation.
What you get
- Authorization matrix with every gap marked
- Technical report with reproducible request/response evidence
- Developer-ready fixes per endpoint
- Free retest of fixed findings
The engagement at a glance
A short conversation about your environment. You receive a written scope, timeline, and fixed quote β no obligation.
Testing begins only with your written permission and agreed rules of engagement. Always.
A calendar agreed before we start, with an agreed communication plan while testing runs.
A verification pass over everything you fix β included in the price, not an add-on.
See the full engagement process β and how pricing is scoped in our public pricing guide.
Related research from Hmmnm
Common questions
We have no API documentation β can you still test?
Yes. We reconstruct the surface from client traffic and application behavior. Undocumented endpoints are frequently where the interesting findings live.
Is this different from your web application testing?
It is a deeper pass on the API layer specifically. Many clients start with the web application test and add dedicated API testing when APIs are their product or primary surface.
GraphQL too?
Yes β introspection exposure, query depth abuse, batching-based rate-limit bypass, and per-field authorization gaps are all in scope.
Want this assessed for your environment?
A short scoping conversation is enough to get a fixed quote. No obligation β a researcher replies.
Start the conversation β