Find what
your API tests missed.
Schema review, authentication abuse, business-logic attacks. Coverage for REST, GraphQL, and gRPC — including the endpoints your test suite forgot.
Coverage
What we test.
API testing across the four protocols and patterns we most commonly see in modern stacks. Mixed-protocol environments are the norm; we cover them in a single engagement.
REST APIs
OWASP API Security Top 10. BOLA, BOPLA, broken function-level authorisation, mass assignment, unrestricted resource consumption.
GraphQL
Introspection abuse, query depth and complexity attacks, field-level authorisation, batching abuse, schema-vs-implementation drift.
gRPC services
Protobuf schema review, authentication on streaming RPCs, server reflection abuse, service-to-service trust assumptions.
Webhooks & event APIs
Signature verification, replay protection, secret rotation, server-side request forgery on outbound callbacks.
Methodology
How we work.
Schema & spec review
Read your OpenAPI / GraphQL SDL / .proto files. Identify shape-of-data risks before any test traffic flies.
Authentication & authorisation analysis
Map every authentication flow and trust boundary. Token issuance, refresh, revocation, multi-tenancy isolation.
Business-logic mapping
Document what your API does, not just what it exposes. The most expensive bugs live in business logic, not in OWASP Top 10.
Attack execution
Targeted testing using the threat model from the previous phases. Manual, schema-aware, business-logic-aware.
Reporting & retest
Per-endpoint findings with reproducible curl/HTTP requests. Retest after fixes ship.
Deliverables
What you receive.
Everything you need to fix what we found — and prove it to your auditors.
- OWASP API Security Top 10 coverage matrix
- Annotated schema highlighting risky endpoints and fields
- Per-endpoint findings with reproducible PoC requests
- Authentication and authorisation flow risk map
- Recommended detection signatures for abnormal API usage
- Retest after fixes (typically within 30 days)
FAQs
Common questions.
01 Do you need our OpenAPI spec to start?
It helps but is not required. If you have an OpenAPI / GraphQL SDL / .proto file we read it first; if you do not, we reverse-engineer the schema from traffic and code. We can also work from a Postman collection or HAR file.
02 Can you test GraphQL safely against production?
Yes, with safeguards. We start in a staging environment when one is available; if production is the only option, we agree query complexity limits, rate caps, and a kill-switch with your team beforehand.
03 What if our API uses non-standard authentication?
Most do. We work with mTLS, mutual JWT, signed requests, HMAC-based custom schemes, OAuth variants, and stack-specific patterns (Cognito, Auth0, Clerk, Firebase, etc). Send us a description and we will tell you what we need.
04 How long does an API audit take?
A focused engagement on a single API (10–30 endpoints) typically takes 1.5–2 weeks. Multi-API estates or microservice meshes can take 3–5 weeks. Scoping call usually narrows this.
05 Do you cover internal / microservice APIs?
Yes. Internal APIs often have weaker authentication assumptions than external ones — exactly because teams assume the network perimeter is doing the work. We test that assumption.