In-depth penetration testing for APIs REST, GraphQL and gRPC, with full OWASP API Top 10 coverage.

Offensive security assessments built for production APIs. Cross-tenant BOLA, BFLA, BOPLA, mass assignment, rate limit bypass, GraphQL introspection abuse, alias overload, query depth bombs and batch attacks. The same methodology our researchers use in international bug bounty programs.

  • Mutual NDA within 24h
  • Retest included
  • Direct contact with the researcher

Why APIs

API attacks are different — and scanners miss them

On the web, an attacker has to deal with HTML, JavaScript, browser sessions and CSRF tokens. In an API, none of that exists. The attack is direct, programmatic and scalable: enumerate endpoints, fuzz IDs, confuse types, abuse batching, exploit object-by-object authorization.

This attack pattern dominates modern breaches. The three bug classes that show up most often in bug bounty programs today are:

  • BOLA — user A can read or edit user B's data by swapping the ID in the URL or the request body
  • BFLA — a regular user can call an admin endpoint because authorization was only enforced in the frontend
  • BOPLA — a user can read or modify a property that should be hidden (price, role, isAdmin, payment_status)

Automated scanners catch none of these. Only a researcher who creates two accounts, maps roles × endpoints × verbs and attacks every combination by hand will find them.

Scope

What our API penetration testing covers

OWASP API Security Top 10 (2023)

  • API1 BOLA — Broken Object Level Authorization on every endpoint that takes an ID
  • API2 Broken Authentication — JWT, OAuth, API keys, secret rotation, recovery flows
  • API3 BOPLA — unauthorized reads and writes of object properties (mass assignment)
  • API4 Unrestricted Resource Consumption — rate limiting, query budget, file size, batching
  • API5 BFLA — Broken Function Level Authorization on administrative endpoints
  • API6 Unrestricted Access to Sensitive Business Flows — abuse of legitimate flows (bulk purchasing, mass scraping)
  • API7 SSRF — Server-Side Request Forgery via URL parameters in the body or query string
  • API8 Security Misconfiguration — permissive CORS, missing headers, insecure defaults
  • API9 Improper Inventory Management — exposed v1/v2/staging/admin endpoints
  • API10 Unsafe Consumption of APIs — trusting a partner without validating its responses

REST-specific

  • Verb tampering — GET/POST/PUT/DELETE/PATCH on endpoints that only validate one verb
  • Path parameter pollution — duplicating parameters to confuse the parser
  • HTTP/2-specific attacks — H2.CL and H2.TE request smuggling
  • Content-Type confusion — application/json vs. application/xml to bypass authorization

GraphQL-specific

  • Introspection abuse — schema leaks even with introspection “disabled”
  • Field suggestion mining — extracting the schema from error messages
  • Alias overload — N requests in a single query to bypass rate limiting
  • Query depth bombs — DoS via deeply nested queries
  • Batch query abuse — an array of operations in a single request
  • BOPLA in nested fields — requesting a private field inside a public object
  • Mutation chaining — race conditions via parallel mutations
  • Apollo Federation — pivoting between subgraphs

gRPC-specific

  • Exposed reflection API — schema leakage
  • Message field abuse — optional fields that become a pivot
  • Streaming RPC — backpressure DoS, out-of-order messages
  • gRPC-Web bridge — behavioral differences between native gRPC and the HTTP bridge
  • Metadata propagation — abusing metadata to inject auth

Webhooks (inbound and outbound)

  • SSRF via the webhook callback URL configured by the customer
  • Replay attacks on outbound webhooks
  • HMAC signature bypass (timing, length extension, algorithm downgrade)
  • Webhook forgery — forging a callback that looks legitimate
  • Race conditions in callbacks (a duplicate callback causing double processing)

Methodology

A proprietary Auth Matrix — roles × endpoints × verbs

API penetration testing demands combinatorial coverage. An API with 100 endpoints, 5 roles and 5 verbs has 2,500 combinations to test. Doing that by hand isn't feasible. Doing it with a scanner leaves gaps.

Our proprietary Auth Matrix automatically maps:

  • Every endpoint available in the API (REST + GraphQL operations)
  • Every HTTP verb supported on each endpoint
  • Every role defined in the product (admin, owner, member, viewer, guest, anonymous)
  • The expected response for each role × endpoint × verb combination

When the result differs from what's expected — a regular user gets a 200 on an admin endpoint, a viewer manages to PATCH a resource that should be read-only — we've found a BFLA or BOPLA. A researcher validates every anomaly by hand, builds a reproducible PoC and calibrates severity.

Pricing

API penetration testing pricing

ScenarioPrice rangeCoverage
Small API (up to 50 endpoints, 1 role)Sprint (25h): US$ 3,750 to US$ 6,250OWASP API Top 10 + baseline authentication checks
Mid-sized API (50–200 endpoints, multi-tenant)Deep Dive (50h): US$ 7,500 to US$ 12,500+ full Auth Matrix + webhooks
Enterprise API (REST + GraphQL + gRPC + webhooks)Full Scope (100h+): from US$ 15,000White box + integrations + threat modeling
Recurring, sprint-alignedPTaaS: on requestContinuous pentesting + monitoring of new endpoints

Every engagement gets a custom quote once the scope is defined. The hourly rate ranges from US$ 150 to US$ 250 depending on stack, testing mode and timeline — larger packages have a lower hourly rate. Invoiced in USD via Wise or international wire transfer: 50% at kickoff, 50% on delivery.

FAQ

Frequently asked questions

  • Why do APIs need a dedicated penetration test?

    Because attacking an API is different from attacking a web app. There's no HTML rendering and no browser session. The attack is direct: enumerate endpoints, test authorization object by object, confuse types, abuse batching. These bugs live in endpoints that look simple but return another tenant's data. Scanners don't find them — researchers do.

  • Do you pentest GraphQL APIs?

    Yes. Coverage includes introspection abuse, alias overload, query depth bombs, array-based batch attacks, field suggestion mining, BOPLA in nested fields and rate limit bypass via aliases. GraphQL has a larger attack surface than REST because a single endpoint exposes the entire schema.

  • How much does API penetration testing cost?

    API with up to 50 endpoints: Sprint (25h), US$ 3,750 to US$ 6,250. API with 50 to 200 endpoints (typical B2B SaaS): Deep Dive (50h), US$ 7,500 to US$ 12,500. Enterprise API with GraphQL + REST + webhooks: Full Scope (100h+), from US$ 15,000. PTaaS (recurring): on request. The hourly rate ranges from US$ 150 to US$ 250 per hour.

  • What are BOLA, BFLA and BOPLA?

    BOLA (Broken Object Level Authorization) — a user accesses an object that isn't theirs (e.g., /api/orders/123 returns someone else's order). BFLA (Broken Function Level Authorization) — a user accesses a function that isn't theirs (e.g., an admin route reachable by a regular user). BOPLA (Broken Object Property Level Authorization) — a user reads or modifies a property they shouldn't (e.g., a PATCH on an isAdmin field).

Next step

Ready to test your API?

Send us your API scope. Mutual NDA within 24h, formal proposal within 3 business days after the technical call.

Talk to a researcher