Skip to content
Use our free scanner to check your security!

API pentesting

Your API is the part of your product with no interface to hide behind. We test it the way an attacker does, call by call and role by role, with experienced European pentesters and autonomous agents working the same target.

Request pentest

What API pentesting is

API pentesting is a security assessment of the interface itself, rather than of anything drawn on top of it. Every endpoint, parameter, token and role is attacked under controlled conditions, including the calls your own front end never makes. That is exactly where an attacker starts.

We combine experienced European pentesters with AI-supported tooling. The agents work through the surface at scale, every endpoint against every role, while our specialists chase the flaws that need a person to understand what the calls are for.

What we test

REST, GraphQL, gRPC and the SOAP services still quietly holding a business together. Every endpoint, against every role.

  • Authentication and tokens

    JWT handling and signature validation, OAuth flows, API keys, refresh logic and how long a stolen token stays useful.

  • Authorization per object

    Broken object-level authorization, function-level gaps, role escalation and whether one tenant's identifier reaches another tenant's data.

  • What comes back

    Responses returning more than the screen shows, mass assignment on the way in, and errors that describe your internals with GDPR impact attached.

  • Rate limits and abuse

    Throttling, quotas and lockout, plus the endpoints an attacker can turn into an expense: enumeration, brute force and costly queries.

  • Business logic

    Order, payment and approval calls made out of sequence, replayed, or carrying values no client of yours would ever send.

  • Configuration and transport

    CORS, TLS, HTTP methods, verbose errors, debug routes and old API versions still answering after the new one shipped.

Types of pentest

How much you hand over at the start decides how far a test can go. All three are run by our own pentesters, working with an AI agent set up for that level of access.

  • Black box

    We start with nothing but your address, exactly as a real attacker would. The most realistic test, and usually the shortest list of findings.

    What you give us

    • Included: Your address or application
    • Not included: Test logins and documentation
    • Not included: Your source code

    Usually done in 3-5 working days

  • Grey box

    You give us a login, so we can test everything your own users can reach. That usually finds considerably more.

    What you give us

    • Included: Your address or application
    • Included: Test logins and documentation
    • Not included: Your source code

    Usually done in 5-7 working days

  • White box

    You give us the source code as well. Nothing stays hidden, and the report points at the exact lines to fix.

    What you give us

    • Included: Your address or application
    • Included: Test logins and documentation
    • Included: Your source code

    Usually done in about 2 weeks

How an API test runs

Six stages, from the first call to the retest. At every point you know what is happening and what comes next.

Where it starts
  1. Scoping

    We agree the environments, the roles, the test window, the rules of engagement and which endpoints are in scope.

  2. Mapping

    We build the full picture of the surface: every endpoint, parameter and version, from your specification and from what the API actually answers.

  3. AI-assisted testing

    Our agents run the matrix, every endpoint against every role, while our pentesters work the logic no matrix can describe.

  4. Human validation

    Every finding is reproduced and rated by a senior pentester, so what reaches your report is real and nothing else.

  5. Reporting

    You receive the findings with the exact request that triggers them, a risk analysis and concrete fixes, alongside a management summary.

  6. Retest

    Once your fixes are deployed we replay the same calls, so you know a finding you closed is actually closed.

What you get

A report your developers can work from directly, with a summary the people funding the work can read.

  • Every finding with the exact request and response that proves it
  • A risk analysis per finding, weighed against real business impact
  • Concrete, prioritized fixes written for the people who own the endpoint
  • An executive summary that explains the risk in a way anyone can understand
  • Findings mapped to the relevant ISO 27001 controls through ARGUS
A sample AssistSec pentest report, open at the executive summary, with the technical appendix half-visible behind it

AssistSec v.s. others

APIs change with every release, which is the problem with testing them once a year and filing the PDF.

AssistSec compared with a traditional API penetration test
AspectTraditional pentest
ApproachAgents covering every endpoint against every role, with senior pentesters on the logicA junior pentester on the test
FrequencyContinuous testing that carries on between releasesOne snapshot, already out of date by the next deploy
FindingsLive in the ARGUS portal, visible the moment something is foundA PDF, weeks after the test ended
RetestingOn demand, straight from the portal, at no extra costQuoted separately, scheduled again
ComplianceEvery finding mapped to the relevant ISO 27001 controlsEvidence you assemble yourself

Frequently asked questions

Which kinds of API do you test?

REST and GraphQL most often, and gRPC, WebSocket and SOAP services just as readily. What matters is not the protocol but whether we can reach it and know which roles are supposed to reach what.

Do you need our OpenAPI specification?

It helps and we will ask for it, along with a Postman collection if you have one. Both let us start on the logic instead of on discovery. Neither is required: we can map the surface from traffic and from the API's own answers, and finding endpoints your specification forgot is often a result in itself.

What do you need from us?

Accounts for each role, ideally two per role so we can test whether one account reaches the other's data, plus a reachable environment and a contact who can answer a question during the test.

Can you test our production API?

Yes, and we regularly do. We agree a test window in advance and treat destructive actions as out of scope unless you explicitly ask for them. If rate limits or noisy monitoring are a concern we work around them, or you point us at an acceptance environment instead.

Does a pentest help with ISO 27001 or NIS2?

A pentest gives you demonstrable evidence for a certification or audit track. Through ARGUS every finding is mapped to the relevant ISO 27001 controls, which makes reporting on your security posture considerably simpler.

Interested in a pentest?

Discover how AI-backed pentesting gives your organization faster and more thorough insight into vulnerabilities.

Contact us