API Pentest
APIs form the backbone of modern applications — and are an increasingly targeted attack surface. An API pentest helps you discover vulnerabilities early, before they are exploited.
Why an API pentest?
APIs regularly contain vulnerabilities that traditional web application scans miss: broken object level authorization (BOLA), insecure authentication flows and overly verbose data responses. The OWASP API Security Top 10 describes the most critical risks — and those are exactly what we test.
What do we test?
- Broken Object Level Authorization (BOLA/IDOR) — can a user retrieve another user’s data by modifying an ID?
- Broken Authentication — insecure token validation, JWT misconfigurations, weak API keys
- Broken Object Property Level Authorization — excessive data returned or too many fields editable
- Unrestricted Resource Consumption — missing rate limiting, possible abuse scenarios
- Business logic flaws — skipping process steps, price manipulation, race conditions
- Security Misconfiguration — debug endpoints, overly permissive CORS settings, verbose error messages
- Injection — SQL, NoSQL, command injection via API parameters
Supported API types
- REST APIs (JSON/XML)
- GraphQL
- SOAP / WSDL
- gRPC (on request)
- Internal APIs and microservices
Approach
We use a grey box approach by default: you provide documentation (Swagger/OpenAPI spec, Postman collection) and a test account. This makes the test more efficient and realistic — we simulate an attacker who has obtained an account.
For an in-depth review including source code analysis, we also offer a white box API pentest. More on the pentest methodology page.
Who is this for
- SaaS companies with a public or private API
- Organisations offering an API to business clients or partners
- Development teams wanting a new API version tested
- Organisations that must comply with ISO 27001, NIS2 or PCI DSS
FAQ
Can you also test internal APIs?
Yes, provided secure access and a clear scope are available. We then work via VPN or a test environment.
Is this the same as a web application pentest?
No. A web application pentest focuses on the user interface and underlying logic. An API pentest focuses specifically on the API layer and the attack scenarios relevant to it. Both can be combined.
What do I need to get started?
API documentation (Swagger/OpenAPI or Postman collection), a test or staging environment, and a test account. No source code required for a grey box test.
How long does an API pentest take?
Usually 1 to 3 business days, depending on the number of endpoints and the complexity of the authorization logic.
Related: web application pentest · SaaS pentest · request a quote
Compliance & Sector-Specific Pentests
Does your organisation operate under specific regulations? We carry out pentests tailored to your industry’s requirements.
- DigiD Pentest & IT Security Assessment — mandatory for organisations with a DigiD connection
- ISO 27001 Pentest — support for certification
- NIS2 Pentest — technical assessment for NIS2-obligated organisations
- PCI DSS Pentest — mandatory test for payment environments
- Government Pentest — BIO-aligned for the public sector
- Healthcare Pentest — NEN 7510 and GDPR-focused
- SaaS Pentest — for software and platform companies
