Skip to content
8bytes

Find what
your API tests missed.

Schema review, authentication abuse, business-logic attacks. Coverage for REST, GraphQL, and gRPC — including the endpoints your test suite forgot.

Coverage

What we test.

API testing across the four protocols and patterns we most commonly see in modern stacks. Mixed-protocol environments are the norm; we cover them in a single engagement.

REST APIs

OWASP API Security Top 10. BOLA, BOPLA, broken function-level authorisation, mass assignment, unrestricted resource consumption.

GraphQL

Introspection abuse, query depth and complexity attacks, field-level authorisation, batching abuse, schema-vs-implementation drift.

gRPC services

Protobuf schema review, authentication on streaming RPCs, server reflection abuse, service-to-service trust assumptions.

Webhooks & event APIs

Signature verification, replay protection, secret rotation, server-side request forgery on outbound callbacks.

Methodology

How we work.

01

Schema & spec review

Read your OpenAPI / GraphQL SDL / .proto files. Identify shape-of-data risks before any test traffic flies.

02

Authentication & authorisation analysis

Map every authentication flow and trust boundary. Token issuance, refresh, revocation, multi-tenancy isolation.

03

Business-logic mapping

Document what your API does, not just what it exposes. The most expensive bugs live in business logic, not in OWASP Top 10.

04

Attack execution

Targeted testing using the threat model from the previous phases. Manual, schema-aware, business-logic-aware.

05

Reporting & retest

Per-endpoint findings with reproducible curl/HTTP requests. Retest after fixes ship.

Deliverables

What you receive.

Everything you need to fix what we found — and prove it to your auditors.

  • OWASP API Security Top 10 coverage matrix
  • Annotated schema highlighting risky endpoints and fields
  • Per-endpoint findings with reproducible PoC requests
  • Authentication and authorisation flow risk map
  • Recommended detection signatures for abnormal API usage
  • Retest after fixes (typically within 30 days)

FAQs

Common questions.

01

Do you need our OpenAPI spec to start?

It helps but is not required. If you have an OpenAPI / GraphQL SDL / .proto file we read it first; if you do not, we reverse-engineer the schema from traffic and code. We can also work from a Postman collection or HAR file.

02

Can you test GraphQL safely against production?

Yes, with safeguards. We start in a staging environment when one is available; if production is the only option, we agree query complexity limits, rate caps, and a kill-switch with your team beforehand.

03

What if our API uses non-standard authentication?

Most do. We work with mTLS, mutual JWT, signed requests, HMAC-based custom schemes, OAuth variants, and stack-specific patterns (Cognito, Auth0, Clerk, Firebase, etc). Send us a description and we will tell you what we need.

04

How long does an API audit take?

A focused engagement on a single API (10–30 endpoints) typically takes 1.5–2 weeks. Multi-API estates or microservice meshes can take 3–5 weeks. Scoping call usually narrows this.

05

Do you cover internal / microservice APIs?

Yes. Internal APIs often have weaker authentication assumptions than external ones — exactly because teams assume the network perimeter is doing the work. We test that assumption.

Get in touch

Ready to scope an API audit?

Book a call

Free 30-min scoping call. No commitment.