Offensive security

    API Penetration Testing

    The authorisation layer is where APIs break.

    REST, GraphQL and webhook testing focused on broken object-level authorisation, data exposure and rate-limit abuse.

    Test sequence

    Inventory: Documented and undocumented endpoints, versions and methods.

    API penetration testing checks whether your interfaces enforce authorisation on every object, for every role, on every method. Most serious API breaches are not exotic exploits — they are requests that should have been refused. We test against the OWASP API Security Top 10, with particular depth on broken object-level and function-level authorisation, which account for the majority of real-world API incidents.

    • Tested against the OWASP API Security Top 10 with documented request evidence.
    • Shadow and deprecated endpoints are actively looked for, not assumed away.
    • Findings are delivered per endpoint so they map directly onto service ownership.

    How this service connects

    For browser workflows and application business logic surrounding the interface, use Web Application Security Testing.

    For device-side controls and the mobile client that consumes the API, use Mobile Application Penetration Testing.

    For a wider attack path across applications, infrastructure and networks, use Penetration Testing.

    Who should consider this assessment

    • Startups and product teams exposing a small set of business-critical endpoints.
    • Businesses using APIs for authentication, data exchange or third-party integrations.
    • Enterprises operating multi-tenant, role-based REST, GraphQL or machine-to-machine services.

    What you receive

    1. 01A per-endpoint report with reproducible requests, affected roles and demonstrated impact.
    2. 02Prioritised remediation guidance for authorisation, data exposure, input handling and abuse controls.
    3. 03An executive summary connecting technical findings to business and tenant risk.

    Service packages

    Starter Package

    Who it is for
    Small APIs or single-purpose endpoints.
    Scope
    Up to 10 endpoints, basic authentication mechanisms and simple data flows.
    Ideal for
    Small businesses or MVP-level APIs with straightforward functionality.

    €1,500 excl. VAT

    Configure with our team

    Standard Package

    Who it is for
    Medium-sized APIs with moderate complexity.
    Scope
    Up to 50 endpoints, third-party integrations, role-based access and complex authentication.
    Ideal for
    Mid-size applications with user authentication and multiple data-exchange functions.

    €3,600 excl. VAT

    Configure with our team

    Enterprise Package

    Who it is for
    Large-scale or enterprise-level API systems.
    Scope
    Unlimited endpoints, extensive backend integrations, OAuth/JWT and multi-role access testing.
    Ideal for
    SaaS platforms, multi-tenant APIs and large enterprise systems.

    Custom scope

    Configure with our team

    Expertise and delivery standards

    Certified offensive-security expertise

    Our experts hold certifications including OSEE, OSCP, OSWE, OSEP, OSED, OSWP, eWPTx, eMAPT, eCPPT, CRTO and CEH.

    ISO 9001 & ISO 27001

    Evolvice operates certified quality-management and information-security systems under ISO 9001:2015 and ISO 27001:2022.

    13+ years in IT delivery

    More than thirteen years of technology delivery inform scoping, communication, reporting and remediation support.

    Their penetration testing report was not only detailed but actionable. Our developers could immediately start fixing the issues.
    They helped us identify critical vulnerabilities we didn’t know existed. A truly professional and responsive team.
    From the initial scoping call to the final report, everything was handled with precision and professionalism.

    What the engagement covers

    01

    Broken object-level authorisation

    Cross-tenant and cross-user object access — the single most common API weakness.

    02

    Function-level authorisation

    Administrative and privileged operations reachable by lower-privileged tokens.

    03

    GraphQL-specific testing

    Introspection exposure, nested query depth, batching abuse and resolver-level authorisation.

    04

    Excessive data exposure

    Responses returning more than the client needs, including internal fields.

    05

    Mass assignment & injection

    Unvalidated input binding to internal properties; injection across query and parser layers.

    06

    Rate limiting & resource abuse

    Enumeration, credential stuffing surfaces and denial-of-wallet conditions.

    Q&A

    Do you need an OpenAPI or GraphQL schema?

    It helps and speeds things up, but it is not required. We enumerate endpoints independently and frequently find undocumented ones.

    Do you test GraphQL as well as REST?

    Yes. GraphQL adds introspection, query-depth and batching concerns on top of the same authorisation testing.

    Is API testing included in a web application test?

    The APIs a web application calls are covered there. A standalone API test goes deeper: every role, every method, every object boundary, including machine-to-machine clients.

    How do you handle production data?

    Test accounts and non-production data wherever possible. Where production access is required, it is agreed in writing and limited by scope and window.

    Let us look at your current security position first.