Skip to content
Halberd Security
Authorised testing only. We test only with the owner's written authorisation, so scope is agreed before testing begins. Unauthorised testing is also illegal under the Computer Fraud and Abuse Act.

Service

API penetration testing for the endpoints your product really runs on

API penetration testing checks whether each endpoint enforces who may see and change what. Increasingly, the API is the whole product, so a single broken check can expose every customer's data.

  • Named tester before day one
  • One retest within 30 days
  • OWASP WSTG and NIST SP 800-115
Api penetration testing: collect the spec, test every object and prove and fix

Why API penetration testing is its own test

Web front ends hide a lot. However, the API behind them accepts anything a client sends, including requests the interface never makes. That is why the most serious findings in modern apps sit in the API layer.

What API penetration testing checks

We work from your specification, such as an OpenAPI file or a Postman collection, and then go beyond it.

  • Object references you can walk, such as changing an ID in the URL
  • Function-level checks, such as a user calling an admin endpoint
  • Excessive data returned to the client
  • Rate limits that are missing or easy to bypass
  • Mass assignment of fields the user should not set

The checklist follows the OWASP API Security Top 10, which auditors recognise.

API penetration testing readiness check

Tick what you can hand over. Missing items just become scoping questions.

Your result appears here as you tick, so you can see what is still open.

How API penetration testing is scoped

The fee depends on the number of endpoints and roles. Therefore we ask for the specification and a test account for each role. Undocumented endpoints we discover are reported too, because they are often the forgotten ones.

Scope inputWhy it matters
Number of endpointsEvery endpoint needs its own authorisation checks.
User rolesEach role multiplies the permission tests.
Authentication methodTokens, keys and OAuth flows each need testing.
Versions in useOld versions often lack newer checks.

What you receive from API penetration testing

Every finding includes the exact request and response that prove it, plus a fix. In addition, you get an executive summary for leadership and an attestation letter for customers. One retest inside 30 days is included.

Price range

Our published range for API work is $10,000 to $25,000. A small internal API with one role sits near the bottom. On the other hand, a public API with partner keys and many roles sits near the top.

API penetration testing questions

Do you test GraphQL as part of API penetration testing?

Yes. GraphQL needs extra checks for introspection, query depth and field-level authorisation.

What if we have no specification?

We can work from traffic captured while using the app, although a specification makes the scope more precise.

Is API penetration testing included in a web app test?

Partly. A web test covers the calls the front end makes. A dedicated API test covers every endpoint, including the ones the interface never uses.

Can you test partner or public APIs?

Yes, if you own them or hold written authorisation from the owner.

Related guides

Get an API penetration testing quote in writing

Send the specification and the list of roles. We reply with a fixed fee and a written scope.

Get my estimate