Skip to content
SVC-02 · Service

API Penetration Testing

REST and GraphQL testing focused on authorization and data exposure.

APIs carry the data. In most modern applications the front end is a thin client and every meaningful control lives behind an endpoint. That makes object-level authorization, token handling and data exposure the most common and most impactful API vulnerability classes.

CyberZ tests REST and GraphQL APIs manually, using the OWASP API Security Top 10 and the OWASP WSTG as references. Test cases are adapted to the agreed scope, your API documentation and the roles you provide.

Ideal for

  • SaaS products with public or partner APIs
  • Mobile back ends and single-page application APIs
  • AI products exposing inference or data endpoints
  • Platforms with customer-facing API keys or OAuth apps
Coverage

Testing may include, depending on the agreed scope:

Depending on the agreed scope, testing may include the areas below. We work from your OpenAPI / GraphQL schema when available and from observed traffic when it is not.

Authorization

  • Broken object level authorization (BOLA / IDOR)
  • Broken function level authorization
  • Privilege escalation across roles and tenants
  • Object property level authorization
  • Multi-tenancy isolation

Authentication & tokens

  • Authentication flows and API key handling
  • JWT validation, algorithms, expiry and revocation
  • OAuth / OIDC flows and scopes
  • Token leakage in logs, URLs and responses

Data & input

  • Excessive data exposure
  • Mass assignment
  • Injection (SQL, NoSQL, command, GraphQL-specific)
  • Input validation and schema enforcement
  • Error handling and verbose responses

Abuse & business logic

  • Rate limiting and resource consumption
  • Business-logic abuse of workflows
  • GraphQL introspection, batching and depth/complexity limits
  • Unsafe consumption of third-party APIs
Why manual

Automated API scanning vs. manual API security testing

Automated scanning

  • Finds known patterns: missing headers, outdated components, obvious injection
  • Does not understand which user should see which object
  • Cannot judge whether a workflow can be abused
  • Useful for continuous coverage between manual tests

Manual API testing

  • Tests authorization per object, per role, per tenant
  • Exercises business logic, sequencing and state
  • Chains low-severity issues into real impact
  • Produces evidence and remediation your team can act on
Approach

How we work on this engagement.

Role and tenant matrices

We map every endpoint against the roles and tenants in scope and attempt cross-role and cross-tenant access systematically — the manual work that catches BOLA and privilege escalation.

Schema-driven coverage

OpenAPI or GraphQL schemas are used to enumerate endpoints, parameters and object properties so that mass assignment and excessive exposure are tested per object, not per guess.

Findings you can reproduce

Every finding ships with exact requests and responses, so your engineers can reproduce and fix it without a call.

Deliverables

What you receive.

Security assessments represent a point-in-time evaluation and do not constitute a guarantee that the assessed systems remain secure or free from vulnerabilities after the assessment.

  1. 01Executive summary
  2. 02Technical report with endpoint-level findings
  3. 03Severity ratings with CVSS scores
  4. 04Request/response evidence and reproduction steps
  5. 05Remediation guidance
  6. 06Retest results
  7. 07CyberZ Penetration Testing Certificate on request
Questions
Do you need our API documentation?

It helps. An OpenAPI or GraphQL schema, a Postman collection, or a walkthrough of key flows significantly improves coverage. We can also test from observed traffic if documentation is incomplete.

Can you test APIs used by a mobile app?

Yes. Mobile back-end APIs are tested the same way. Client-side mobile testing is agreed separately if required.

Next step

Request a security assessment.

Tell us what you need tested, when, and which evidence you need at the end. We reply with scoping questions, not a sales deck.