Skip to content

Expert-led service

API security testing.

APIs quietly hand out data to whoever asks correctly. We test that every endpoint checks who is asking — for every object, every function and every field.

What we test

Scope, agreed in writing.

  • Object-level authorization

    Can user A read or change user B's records by changing an id? (BOLA)

  • Function-level authorization

    Can a regular user call admin-only operations?

  • Data exposure

    Fields returned that the client never shows — and never should have received.

  • Authentication

    Token issuance, validation, expiry and revocation.

  • Rate limiting

    Login, OTP and expensive endpoints that can be hammered.

  • GraphQL

    Introspection, query depth and batching abuse, resolver authorization.

How we work

Methodical, and never destructive without agreement.

  1. 01Build an endpoint inventory from docs, traffic and the client code.
  2. 02Create an authorization matrix: every role against every endpoint.
  3. 03Test each cell of the matrix, by hand, with real accounts.
  4. 04Map findings to the OWASP API Security Top 10.

What you receive

  • Endpoint coverage map
  • Authorization matrix with results
  • Reproduction scripts for each finding
  • Retest and written confirmation

Manual testing or MyPentest?

MyPentest discovers API endpoints referenced in your JavaScript, OpenAPI documents and GraphQL, and tests object-level access with your test accounts.

Choose a manual API test for complex permission models, multi-tenant data, or partner and payment APIs.

Automated vs manual penetration testing

FAQ

Questions, answered straight.

How long does an engagement take?

Most engagements run 5–12 testing days depending on scope, with the report delivered within 5 business days of testing finishing. Exact dates are agreed in the scoping document before you commit.

Will testing affect production?

Rules of engagement are agreed in writing before anything starts. We recommend a staging environment; when production testing is required we use non-destructive techniques, throttle traffic and agree testing windows. Denial-of-service testing is never performed without explicit written agreement.

Is retesting included?

Yes. When you've fixed the issues, we retest them and confirm in writing which are closed.

Talk to a tester, not a sales team.

A free 30-minute scoping call, then a fixed quote in writing. Or start with a free automated pentest today.