Authorisation tested role by role
We create accounts across your roles and check, object by object and function by function, who can reach what. That finds the flaw that exposes every customer; a scanner cannot.
Every web and mobile app, every partner integration, every microservice runs on APIs, and a single missing authorisation check can hand one user another user’s data at scale. We attack your APIs the way a real adversary would, and provide exactly what an attacker could read, change or abuse.
How an API pentest worksProtected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.
Request received.
We’ll be in touch within one business day with next steps.
No se ha podido enviar. Inténtalo otra vez o escríbenos.















An API does not have a screen to hide behind. It answers requests directly, so the only thing standing between a curious user and your data is whether the server checks that the request is theirs to make. Very often, it does not. We test each by hand, chain them where a chain exists, and hand your engineers the exact request and the fix.
A new public API, a partner integration, a mobile backend going live, a customer’s security questionnaire, or a compliance audit forces the question.
With PCI DSS, ISO 27001, ENS or GDPR on the line, the report has to survive scrutiny: traceable scope, a methodology mapped to the recognised API standard, signed retest evidence and an execution certificate.
When the ask is for assurance, you need an external, expert-led API pentest and a deliverable that maps to business impact in language a non-technical stakeholder can read.
Every API surface ships with its own threat model, and the flaw that hurts is almost never the one a scanner reads off a schema. We test object-level and function-level authorisation, tenant checks, token scopes and the business flows.
The question is not whether one issue exists but which adjacent paths are still open. We focus the engagement on the suspected exposure, confirm it is closed, and map the routes an attacker would reach for next.
We test the APIs the way the other side of the table would, including the old and undocumented endpoints nobody listed, so what you are taking on is evidence rather than an assurance.
The same shape your auditor expects, adapted to APIs. The short version is below; the full step-by-step lives on its own page.
Most API tests run a scanner over your documentation and call it done. Here is where we go further.
We create accounts across your roles and check, object by object and function by function, who can reach what. That finds the flaw that exposes every customer; a scanner cannot.
REST, GraphQL, gRPC and SOAP each break differently. We test GraphQL introspection and query abuse, and gRPC and SOAP message handling, not a REST checklist stretched to fit.
Old versions, debug routes and undocumented endpoints are where breaches hide. We map the full surface, not only what your documentation admits exists.
Findings arrive live in our platform, mapped to the OWASP API Security Top 10, and a free retest confirms each fix against the original proof.
We at Etnia highly value our collaboration with Asperis Security.
Names, roles and companies on the record.
We at Etnia highly value our collaboration with Asperis Security. Their professionalism, approachability, quick response and ability to adapt to our needs have been key in every project. The quality of service and continuous support always give us peace of mind. Without a doubt, it is a pleasure to have them as technology partners.
ASPERIS has worked alongside us to define and implement our cybersecurity roadmap in Microsoft 365 with a structured approach aligned to business objectives. Thanks to their advice, we took the strategic step of completing our Microsoft ecosystem and reinforcing it with CrowdStrike for advanced mobile device protection, significantly raising our security level.
At NPAW we have collaborated with Asperis on various security initiatives and the experience has been very positive. We especially value their ability to adapt to our needs and the depth with which they approach each project. Results are clear, structured and useful for decision-making and continuous security improvement. We like working with Asperis for the judgment and value they bring to every collaboration. Their work has helped us strengthen our security level.
With Asperis you don’t hire a service. You hire a partner. They don’t look to bill a project. They look to establish a relationship of trust, caring about the key points that affect your organisation’s security. Professionalism, know-how and diligence.
Tell us your API style, roughly how many endpoints, and whether you can share documentation. An experienced consultant replies with a tailored scope, a fixed quote and a timeline.
API penetration testing is a manual security assessment of the interfaces your applications use to exchange data, such as REST, GraphQL, gRPC and SOAP. It focuses on the flaws that matter most in APIs: whether one user can reach another’s data, call functions they should not, or abuse a business flow. The deliverable is a short list of proven, exploitable findings, mapped to the OWASP API Security Top 10 and ranked by business impact, each with a reproducible proof of concept.
BOLA (Broken Object Level Authorisation, also called IDOR) is the most common serious API flaw: the server returns a record without checking that it belongs to the user asking. In practice it means changing an ID in a request, say from your account number to the next one, and receiving someone else’s data. Because IDs are often sequential, a single flawed endpoint can expose your entire customer base, which is why it sits at number one in the OWASP API Security Top 10 and why we test it exhaustively.
A scanner cannot judge whether a request should be allowed, because the request itself is valid. When an ordinary user reads an admin record, the API returns a normal 200 OK response; nothing looks broken to a tool. Deciding that the response should never have reached that user requires understanding your roles and your business, which is human work. Scanners help with coverage and known issues; they do not find the authorisation flaws that cause the biggest API breaches.
No, though they overlap. A web pentest looks at the application a user sees in the browser; an API pentest looks at the machine-to-machine interface behind it, the same interface your mobile app, partners and microservices call directly. APIs concentrate authorisation and business-logic risk, and they often expose functions the web front end never shows. If your product is API-first or has a mobile app, the API is frequently the more important target. Many engagements cover both; we will tell you in the introductory meeting which your situation needs. See also our web application pentesting service.
We test all four. REST is the most common, but GraphQL, gRPC and SOAP each have their own risks, GraphQL schema introspection and query abuse, gRPC and SOAP message handling, and we test them on their own terms rather than forcing a REST checklist onto them. Tell us what you run and we scope accordingly.
A focused API with a clear role model typically takes one to two weeks of active testing; a large surface with many roles, multiple API styles or complex business flows runs two to three weeks. Good documentation and test accounts shorten it. We confirm the timeline in the proposal, delivered within 48 hours of the first call.
Price follows scope: the number of endpoints, the number of roles, the API styles involved and the complexity of your business logic. We quote a fixed price with no hidden fees and no obligation to renew. A focused single-API assessment sits at the bottom of the range; large multi-role, multi-style surfaces scale from there. The retest that confirms your fixes is always included.
Ideally API documentation (OpenAPI/Swagger, a GraphQL schema or a Postman collection), two test accounts per role so we can test authorisation across boundaries, and a staging environment or a production URL in scope. If documentation is incomplete we still proceed; discovering undocumented endpoints is part of the value. One technical contact for questions keeps the engagement moving.
The senior specialist you meet on the first call runs it end to end. Our team holds OSCP, OSWE and OSEP credentials, works by hand against the OWASP API Security Top 10, and we are NASA Bug Bounty verified contributors with published API findings. The same person scopes, executes and retests. They are your point of contact throughout.
Start with a no-obligation introductory meeting. We will review your API surface, your roles and your sensitive flows, and define the right API pentest before the project begins.
Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.
Got it.
The API pentester who’d run your project will email you within one business day.
No se ha podido enviar. Inténtalo otra vez o escríbenos.
Or email [email protected] directly.
OUR CLIENTS HAVE ALREADY DONE IT
We at Etnia highly value our collaboration with Asperis Security.
ASPERIS has worked alongside us to define and implement our cybersecurity roadmap in Microsoft 365 with a structured approach aligned to business objectives.
At NPAW we have collaborated with Asperis on various security initiatives and the experience has been very positive.
With Asperis you don’t hire a service. You hire a partner.
Pick a time that suits you. You tell us what you need and where you are, and we explain how we work and how we can help.