API PENETRATION TESTING

Your APIs carry your data. We prove who can actually reach it.

Every web and mobile app, every partner integration, every microservice runs on APIs, and a single missing authorisation check can hand one user another user’s data at scale. We attack your APIs the way a real adversary would, and provide exactly what an attacker could read, change or abuse.

How an API pentest works
87%
of our clients renew annually
150+
organisations across multiple European countries
7/10
confirm findings their previous provider did not find
Want to know what your APIs hand over?

Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.

Trusted by engineering and platform teams in highly regulated environments

Identify exactly how one endpoint exposes everyone.

demo de pentest de API
OBJETIVO · DATOS DE OTROS CLIENTES
/v1/users/{id}/orders · falta la comprobación de propietarioautenticado como el usuario 9421 · leyendo el 9422EN VIVO
GET/v1/users/9422/orders
Authorization:Bearer eyJ… [sub=9421 · tenant=northwind]
order_idaccountemailcard
ord_281149422[email protected]7421
BOLAel sub del token nunca se compara con {id}
PANEL DE ACME · VISTA DEL CLIENTE
El historial solo muestra mis pedidos.
La interfaz oculta ord_28114. La API lo devuelve.
Devueltos pedidos de otra cuenta.
LO QUE VE EL CLIENTE
API → PIVOTE ENTRE TENANTS 5 SALTOS · ~18 MIN
discoveropenapi.json sin autenticar · 142 rutas, 38 no documentadas
authsecreto HS256 en el bundle público · admin:impersonate emitido
bola/v1/users/{id}/orders · otra cuenta, sus pedidos y datos de tarjeta
·massassignPATCH fusionó role=admin · escalada de privilegios en una llamada
·tenanttenant_id cambiado · 18.421 usuarios de acme, de punta a punta

An API does not have a screen to hide behind. It answers requests directly, so the only thing standing between a curious user and your data is whether the server checks that the request is theirs to make. Very often, it does not. We test each by hand, chain them where a chain exists, and hand your engineers the exact request and the fix.

WHAT WE TEST
  • Object-level authorisation
  • Function-level authorisation
  • Mass assignment
  • Authentication and tokens
  • Business logic abuse
  • Server-side request forgery
  • Undocumented endpoints
  • GraphQL and gRPC

Why a CTO, CISO or platform lead books an API pentest.

A new public API, a partner integration, a mobile backend going live, a customer’s security questionnaire, or a compliance audit forces the question.

TAP A SITUATION
Compliance & audit PCI DSS payment API

An auditor does not accept a marketing PDF, and an API handling card or personal data raises the bar.

With PCI DSS, ISO 27001, ENS or GDPR on the line, the report has to survive scrutiny: traceable scope, a methodology mapped to the recognised API standard, signed retest evidence and an execution certificate.

  • Methodology mapped to the OWASP API Security Top 10, plus PTES and NIST SP 800‑115
  • Authorisation and data-exposure tested endpoint by endpoint
  • Execution certificate ready for the auditor folder
  • Retest evidence with timestamps and signoff
Board & customer Enterprise customer security questionnaire

Someone with authority asked, and ‘we’re fine’ isn’t an answer.

When the ask is for assurance, you need an external, expert-led API pentest and a deliverable that maps to business impact in language a non-technical stakeholder can read.

  • Executive summary that lands without translation
  • Findings ranked by business impact and audit exposure
  • Attestation language that satisfies enterprise procurement and partner review
  • Independence: external and expert-led throughout
Release & change New public REST or GraphQL API

A new API surface is going live. Audit it before your customers find it.

Every API surface ships with its own threat model, and the flaw that hurts is almost never the one a scanner reads off a schema. We test object-level and function-level authorisation, tenant checks, token scopes and the business flows.

  • Threat model written for the surface shipping, not a generic checklist
  • Object-level and function-level authorisation tested endpoint by endpoint
  • Tenant boundaries and token scopes pressure-tested with real requests
  • Findings tied to backend and platform owners, not just a ticket queue
Incident-driven API abuse or scraping detected

Something looked off. You need to know what is still exposed.

The question is not whether one issue exists but which adjacent paths are still open. We focus the engagement on the suspected exposure, confirm it is closed, and map the routes an attacker would reach for next.

  • Targeted scope around the suspected exposure
  • Adjacent paths mapped: object access, function access, tokens, business logic
  • Rate limits, quotas and enumeration tested against real usage patterns
  • Live findings to your responders, not the final report
Business event Newly acquired platform

A transaction put the platform under someone else’s eyes.

We test the APIs the way the other side of the table would, including the old and undocumented endpoints nobody listed, so what you are taking on is evidence rather than an assurance.

  • Scope agreed against the API estate as it is, undocumented endpoints included
  • Shadow and zombie endpoints hunted, not assumed retired
  • Findings ranked by business impact, in language a non-technical reader follows
  • Retest to closure, so the handover ends with the gaps closed

Ready to see what your API actually exposes?

A seven-phase method, for your API security pentesting.

The same shape your auditor expects, adapted to APIs. The short version is below; the full step-by-step lives on its own page.

What you actually get, and why it is different.

Most API tests run a scanner over your documentation and call it done. Here is where we go further.

Authorisation tested role by role

We create accounts across your roles and check, object by object and function by function, who can reach what. That finds the flaw that exposes every customer; a scanner cannot.

Every API style, not just REST

REST, GraphQL, gRPC and SOAP each break differently. We test GraphQL introspection and query abuse, and gRPC and SOAP message handling, not a REST checklist stretched to fit.

The shadow endpoints you forgot

Old versions, debug routes and undocumented endpoints are where breaches hide. We map the full surface, not only what your documentation admits exists.

Closed, not just reported

Findings arrive live in our platform, mapped to the OWASP API Security Top 10, and a free retest confirms each fix against the original proof.

Want to see what your next API pentest with us would look like?

We at Etnia highly value our collaboration with Asperis Security.
Sergi Leno, Systems Manager · ETNIA Barcelona

Loved by engineering and security teams.

Names, roles and companies on the record.

We at Etnia highly value our collaboration with Asperis Security. Their professionalism, approachability, quick response and ability to adapt to our needs have been key in every project. The quality of service and continuous support always give us peace of mind. Without a doubt, it is a pleasure to have them as technology partners.
Sergi Leno, Systems Manager
ETNIA Barcelona
ASPERIS has worked alongside us to define and implement our cybersecurity roadmap in Microsoft 365 with a structured approach aligned to business objectives. Thanks to their advice, we took the strategic step of completing our Microsoft ecosystem and reinforcing it with CrowdStrike for advanced mobile device protection, significantly raising our security level.
Jordi Bondia, IT Director
SALVI
At NPAW we have collaborated with Asperis on various security initiatives and the experience has been very positive. We especially value their ability to adapt to our needs and the depth with which they approach each project. Results are clear, structured and useful for decision-making and continuous security improvement. We like working with Asperis for the judgment and value they bring to every collaboration. Their work has helped us strengthen our security level.
Sergi Laencina Verdaguer, CISO
NPAW
With Asperis you don’t hire a service. You hire a partner. They don’t look to bill a project. They look to establish a relationship of trust, caring about the key points that affect your organisation’s security. Professionalism, know-how and diligence.
Juan Valer Tecedor, Software Engineer
GNOSS
READY WHEN YOU ARE

Want a real scope for your APIs?

Tell us your API style, roughly how many endpoints, and whether you can share documentation. An experienced consultant replies with a tailored scope, a fixed quote and a timeline.

Questions that come up before signing.

Straight answers on how an API pentest differs from a web pentest, scope, price, staging vs production, and who runs it.

API penetration testing is a manual security assessment of the interfaces your applications use to exchange data, such as REST, GraphQL, gRPC and SOAP. It focuses on the flaws that matter most in APIs: whether one user can reach another’s data, call functions they should not, or abuse a business flow. The deliverable is a short list of proven, exploitable findings, mapped to the OWASP API Security Top 10 and ranked by business impact, each with a reproducible proof of concept.

BOLA (Broken Object Level Authorisation, also called IDOR) is the most common serious API flaw: the server returns a record without checking that it belongs to the user asking. In practice it means changing an ID in a request, say from your account number to the next one, and receiving someone else’s data. Because IDs are often sequential, a single flawed endpoint can expose your entire customer base, which is why it sits at number one in the OWASP API Security Top 10 and why we test it exhaustively.

A scanner cannot judge whether a request should be allowed, because the request itself is valid. When an ordinary user reads an admin record, the API returns a normal 200 OK response; nothing looks broken to a tool. Deciding that the response should never have reached that user requires understanding your roles and your business, which is human work. Scanners help with coverage and known issues; they do not find the authorisation flaws that cause the biggest API breaches.

No, though they overlap. A web pentest looks at the application a user sees in the browser; an API pentest looks at the machine-to-machine interface behind it, the same interface your mobile app, partners and microservices call directly. APIs concentrate authorisation and business-logic risk, and they often expose functions the web front end never shows. If your product is API-first or has a mobile app, the API is frequently the more important target. Many engagements cover both; we will tell you in the introductory meeting which your situation needs. See also our web application pentesting service.

We test all four. REST is the most common, but GraphQL, gRPC and SOAP each have their own risks, GraphQL schema introspection and query abuse, gRPC and SOAP message handling, and we test them on their own terms rather than forcing a REST checklist onto them. Tell us what you run and we scope accordingly.

A focused API with a clear role model typically takes one to two weeks of active testing; a large surface with many roles, multiple API styles or complex business flows runs two to three weeks. Good documentation and test accounts shorten it. We confirm the timeline in the proposal, delivered within 48 hours of the first call.

Price follows scope: the number of endpoints, the number of roles, the API styles involved and the complexity of your business logic. We quote a fixed price with no hidden fees and no obligation to renew. A focused single-API assessment sits at the bottom of the range; large multi-role, multi-style surfaces scale from there. The retest that confirms your fixes is always included.

Ideally API documentation (OpenAPI/Swagger, a GraphQL schema or a Postman collection), two test accounts per role so we can test authorisation across boundaries, and a staging environment or a production URL in scope. If documentation is incomplete we still proceed; discovering undocumented endpoints is part of the value. One technical contact for questions keeps the engagement moving.

The senior specialist you meet on the first call runs it end to end. Our team holds OSCP, OSWE and OSEP credentials, works by hand against the OWASP API Security Top 10, and we are NASA Bug Bounty verified contributors with published API findings. The same person scopes, executes and retests. They are your point of contact throughout.

Ready to prove your APIs only answer to the right people?

Start with a no-obligation introductory meeting. We will review your API surface, your roles and your sensitive flows, and define the right API pentest before the project begins.

Request an API pentest proposal.
An experienced API pentester replies within one business day. You talk to the person who runs the test.

Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.

Or email [email protected] directly.

OUR CLIENTS HAVE ALREADY DONE IT

We at Etnia highly value our collaboration with Asperis Security.

Sergi Leno, Systems Manager
ETNIA Barcelona

ASPERIS has worked alongside us to define and implement our cybersecurity roadmap in Microsoft 365 with a structured approach aligned to business objectives.

Jordi Bondia, IT Director
SALVI

At NPAW we have collaborated with Asperis on various security initiatives and the experience has been very positive.

Sergi Laencina Verdaguer, CISO
NPAW

With Asperis you don’t hire a service. You hire a partner.