✓ OSCP · OSWE · OSEP certified | Joost performs every test himself — no juniors | Response within 1 business day | Based in Haarlem

API Pentest

APIs form the backbone of modern applications — and are an increasingly targeted attack surface. An API pentest helps you discover vulnerabilities early, before they are exploited.

Why an API pentest?

APIs regularly contain vulnerabilities that traditional web application scans miss: broken object level authorization (BOLA), insecure authentication flows and overly verbose data responses. The OWASP API Security Top 10 describes the most critical risks — and those are exactly what we test.

What do we test?

  • Broken Object Level Authorization (BOLA/IDOR) — can a user retrieve another user’s data by modifying an ID?
  • Broken Authentication — insecure token validation, JWT misconfigurations, weak API keys
  • Broken Object Property Level Authorization — excessive data returned or too many fields editable
  • Unrestricted Resource Consumption — missing rate limiting, possible abuse scenarios
  • Business logic flaws — skipping process steps, price manipulation, race conditions
  • Security Misconfiguration — debug endpoints, overly permissive CORS settings, verbose error messages
  • Injection — SQL, NoSQL, command injection via API parameters

Supported API types

  • REST APIs (JSON/XML)
  • GraphQL
  • SOAP / WSDL
  • gRPC (on request)
  • Internal APIs and microservices

Approach

We use a grey box approach by default: you provide documentation (Swagger/OpenAPI spec, Postman collection) and a test account. This makes the test more efficient and realistic — we simulate an attacker who has obtained an account.

For an in-depth review including source code analysis, we also offer a white box API pentest. More on the pentest methodology page.

Who is this for

  • SaaS companies with a public or private API
  • Organisations offering an API to business clients or partners
  • Development teams wanting a new API version tested
  • Organisations that must comply with ISO 27001, NIS2 or PCI DSS

FAQ

Can you also test internal APIs?

Yes, provided secure access and a clear scope are available. We then work via VPN or a test environment.

Is this the same as a web application pentest?

No. A web application pentest focuses on the user interface and underlying logic. An API pentest focuses specifically on the API layer and the attack scenarios relevant to it. Both can be combined.

What do I need to get started?

API documentation (Swagger/OpenAPI or Postman collection), a test or staging environment, and a test account. No source code required for a grey box test.

How long does an API pentest take?

Usually 1 to 3 business days, depending on the number of endpoints and the complexity of the authorization logic.

Related: web application pentest  ·  SaaS pentest  ·  request a quote

Compliance & Sector-Specific Pentests

Does your organisation operate under specific regulations? We carry out pentests tailored to your industry’s requirements.

Scroll to Top