Skip to content

Home » Penetration testing » API penetration testing

API penetration testing

Book a call

What is API penetration testing?

API penetration testing tests the interfaces your applications, partners and mobile apps talk to, on their own terms rather than through a browser. Incursion tests REST, GraphQL and SOAP APIs for UK organisations, either as a standalone engagement or alongside the web or mobile application that uses them.

What we test

Authentication and token handling: API keys, OAuth flows, JWT validation, expiry and revocation.

Authorisation: broken object-level and function-level access, the most common and most serious API flaw.

Input handling and injection across every endpoint and parameter, including those not in the documentation.

Rate limiting, mass assignment, excessive data exposure and improper error handling.

Business logic across sequences of calls, not just individual endpoints.

Testing against the OWASP API Security Top 10, from documentation (OpenAPI, Postman collections) and from traffic where documentation is incomplete.

Why it matters

APIs are now where the data is. A web front end can look secure while the API behind it hands out other customers’ records to anyone who changes an ID in a request. Because APIs are built for machines, they are often tested less than the user interface, and the flaws in them are frequently simpler and more damaging.

How we run it

01

Scoping. Your account manager and an active penetration tester work with you to agree the scope of your test on a scoping call. The quote is fixed to it.

02

Testing. A named, suitably qualified consultant does the work, and you get a direct line to them before, during and after the engagement. Critical and high-risk issues are verified and reported immediately.

03

Reporting. Easily digestible summaries sum up the whole engagement and support detailed technical findings, written so your team can replicate and fix them. Delivered within 5 working days.

04

Free retesting. One day of free retesting for every five days of consultancy, taken within 90 days of report delivery, so you can be sure the fixes worked.

Scoping notes

Send us your API documentation and a set of credentials for each role. If documentation is thin we can work from traffic captures or from the client application. Standalone API tests are often the right choice for organisations whose customers integrate directly, or where the mobile and web front ends share one back end.

What you get

A named consultant with a UK Cyber Security Council professional title, who scoped the work and delivers it.

A report within 5 working days: executive summary, technical summary, and observation, impact and remediation for every finding.

Immediate notification of critical and high-risk issues, once we have verified them.

Free retesting: one day for every five days of consultancy, within 90 days of the report.

A walkthrough call with the consultant for your team, on request, at no extra cost.

Frequently asked questions

Is an API test different from a web application test?

Yes. A web application test approaches the system through the browser; an API test approaches it directly, endpoint by endpoint, including endpoints the front end never calls. If you have both, testing them together is more efficient and finds more.

Do you need our API documentation?

It helps a lot. OpenAPI/Swagger specs or Postman collections let us cover every endpoint. Without them we can still test from traffic, but coverage depends on what the client application exercises.

Can you test an API that is only used internally?

Yes. Internal APIs are often the least protected because they were never expected to be reached, and that assumption fails the moment something else on the network is compromised.

Ready to scope a test?

Book a call. Our sales team will set it up and handle the proposal; an active penetration tester agrees the scope with you. No obligation.