PEN / PEN-04
API penetration testing
Testing the interfaces applications use to exchange data, with particular attention to object-level permissions and abusive usage.

WHEN IT HELPS
A focused response
to a defined need.
Product owner or CTO; mobile applications, partner integrations or architectures exposing multiple APIs.
SCOPE & OUTCOMES
What the engagement covers.
Scope
- Inventory routes and versions
- authentication and authorisation
- checks on usage limits, returned data and business logic
Deliverables
- Role-route-object matrix
- vulnerability report
- remediation requirements and regression-test cases
Acceptance evidence
User and organisation boundaries are tested; scenarios that could incur significant costs are capped.
DELIVERY
How the work is structured.
Approach
Obtain authorisation and rules of engagement; prepare accounts and backups; perform controlled tests; debrief, clean up and arrange retesting.
Prerequisites & responsibilities
Customer: written authorisation, asset ownership, third-party permission, stop contacts and scope. Provider: bounded testing, minimal evidence and critical-finding notification.
Scope factors
Applications, roles, APIs, networks, business complexity, supplied access, depth and authorised windows. Black/grey/white box and retesting affect effort; price after scoping.
Questions to clarify
Is OpenAPI documentation available? Who consumes the API? What usage limits and test environments exist?
IMPORTANT BOUNDARIES
Define excluded third-party APIs and limits; testing must not become a denial-of-service exercise.
No denial of service, destruction, real exfiltration or social engineering without explicit authorisation. Third parties are not tested merely at a customer’s request. Untested scope remains unassessed.
IN PRACTICE
Illustrative situations.
These examples describe possible engagements and target outcomes. They are not customer references or achieved results.
Scenario 01
A multi-tenant SaaS product exposes case records through an API. Project: test tenant separation. Target outcome: enforce authorisation for sensitive objects and deliver regression tests without extracting real records.
Scenario 02
An SMS platform bills per message. Project: assess limits and authorisation in a simulated environment. Target outcome: quotas and consumption controls without mass messaging or uncontrolled spending.
Technology and reference context
OWASP API Security; OpenAPI documentation and separate test identities.
The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.
CONNECTED SERVICES
Build the next step.
These services can complement the engagement. They are not automatically included.
START A CONVERSATION
Make the scope clear.
We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.
