Skip to main content
Home/Services/API Penetration Testing
REST, GraphQL & gRPC API Security

API Penetration Testing

Targeted security assessments of REST, GraphQL, and gRPC APIs - hunting for BOLA, broken function authorization, mass assignment, and data exfiltration vectors.

OWASP API Security Top 10 SOC 2 Type II ISO 27001 PCI-DSS v4.0 OSFI B-13 PIPEDA
engagement log API Penetration Testing testing
day 01 spec OpenAPI spec ingested & endpoint inventory mapped mapped
day 01 auth token validation & OAuth 2.0 grant flows tested complete
day 02 finding BOLA vulnerability on GET /api/v2/org/{id}/financials critical
day 02 finding mass assignment on PUT /users allows is_admin=true update critical
day 03 finding GraphQL introspection enabled exposing internal admin schema medium
day 04 triage API findings validated with exact curl reproduction proofs published
day 04 deliver remediation guidance and Postman collection delivered 201
after retest API endpoint fixes verified and retested at no cost retested
retest included human countersigned report your auditor accepts
1-2 weekstypical duration $5,500fixed scope, from 7deliverables 8methodology stages
Scope

What This Engagement Covers

The Service

APIs serve as the foundational plumbing of modern software architectures - yet they are frequently the most poorly secured layer. Traditional network firewalls and web scanners fail to understand API data models, leaving broken object-level authorization (BOLA), excessive data exposure, unauthenticated admin routes, and rate-limiting flaws completely unnoticed. Our API penetration testing thoroughly exercises every endpoint in scope against the OWASP API Security Top 10.

What We Test

We test all modern API architectures: RESTful JSON APIs, GraphQL services (including schema introspection, batching, and query complexity), gRPC interfaces, WebSocket streams, and webhook delivery endpoints. We evaluate authentication mechanisms (OAuth 2.0, JWT, API keys, mTLS), authorization policies across multi-tenant architectures, parameter pollution, mass assignment, and backend injection vectors.

Targets

Components Evaluated in Scope

Our testers systematically inspect the following architectural layers and attack vectors during the assessment.

RESTful APIs, endpoints, and JSON/XML payloads
GraphQL schemas, introspection, queries, mutations, and subscriptions
gRPC services, Protocol Buffers, and streaming RPCs
OWASP API Security Top 10 (2023 & 2025) vulnerabilities
Broken Object Level Authorization (BOLA / IDOR)
Broken Function Level Authorization (BFLA)
Broken Object Property Level Authorization & Mass Assignment
JWT and OAuth 2.0 token security, signing, and expiration
Server-Side Request Forgery (SSRF) and injection via API parameters
Rate limiting, resource exhaustion, and query complexity limits
Method

How We Run It

We combine automated endpoint fuzzing with deep manual authorization testing. We systematically swap object identifiers across user accounts to identify BOLA flaws, alter HTTP methods to bypass function-level controls, analyze GraphQL schemas for undocumented queries and mutations, and test data parsing libraries for deserialization and injection vulnerabilities.

01

API Surface Discovery & Documentation

Ingesting OpenAPI/Swagger specs, Postman collections, and probing for undocumented shadow endpoints.

02

Authentication & Token Security Review

Analyzing JWT validation, signature verification, token expiration, and OAuth 2.0 scope enforcement.

03

Object-Level Authorization (BOLA) Testing

Systematically manipulating resource identifiers across tenant boundaries to verify strict isolation.

04

Function-Level Authorization (BFLA) Testing

Attempting administrative API actions using standard user tokens and unauthorized HTTP verbs.

05

Property-Level Authorization & Mass Assignment

Injecting undocumented parameters to elevate privileges or overwrite read-only record attributes.

06

GraphQL / gRPC Specific Security Checks

Testing query depth limits, batching attacks, field suggestions, and circular reference vulnerabilities.

07

Rate Limiting & Resource Exhaustion Testing

Evaluating denial-of-service resilience, pagination limits, and large payload handling.

08

Reporting & Developer Postman Collections

Delivering detailed findings with reproduction curl commands, CVSS scores, and remediation examples.

Deliverables

What You Receive

Findings land in your tracker as you go, not only in a PDF at the end. Free retesting is included in scope, not billed as a change order.

  • OWASP API Top 10 mapped technical findings report with CVSS v3.1 scores
  • Actionable curl reproduction commands and Postman verification collection
  • Schema-level remediation guidance and input validation patterns
  • Authentication and authorization architecture analysis
  • Executive risk summary tailored for technology executives
  • Free retesting of all critical and high findings within 48 hours
  • Letter of Attestation for partner integrations, auditors, and investors
Typical Results

What We Usually Find

The issues this engagement surfaces most often. Your environment will differ, but this reflects typical exposure patterns.

Broken Object Level Authorization (BOLA / IDOR) on Resource IDs Mass Assignment Permitting Unauthorized Privilege Escalation Missing or Ineffective Rate Limiting on Sensitive API Endpoints Unrestricted GraphQL Schema Introspection and Query Depth Abuse JWT Algorithm Confusion (None Algorithm / Weak HMAC Secret) Excessive Data Exposure Returning Full Database Records to Client Broken Function Level Authorization on Admin Management Routes Server-Side Request Forgery (SSRF) via Webhook and URL Parameters
Fit

Who This Is For

B2B SaaS Companies Exposing Public or Partner APIs
FinTech and Open Banking Platforms Complying with Canadian Standards
Modern Cloud Applications Utilizing GraphQL or Microservices
Enterprises Modernizing Monoliths into Distributed API Architectures
Organizations Preparing for SOC 2 Type II or PCI-DSS 4.0 Audits
Firms Undergoing Technical Due Diligence for Investment or M&A
Standards this assessment supports

Findings are mapped directly to OWASP API Security Top 10, SOC 2 Type II, ISO 27001, PCI-DSS v4.0, OSFI B-13, PIPEDA, allowing your team to drop the report into an audit package without manual translation.

Canadian Operations

Calgary & Toronto Security Specialists

Canadian enterprises integrating with federal open banking initiatives or exposing customer data via APIs must comply with PIPEDA and provincial privacy standards. Lorikeet Security Canada validates that API endpoints strictly enforce multi-tenant isolation and object authorization.

Calgary OfficeAlberta Operations
Toronto OfficeOntario Operations
FAQ

Common Questions

What documentation do you need to begin an API penetration test? +

An OpenAPI (Swagger) specification, Postman collection, or GraphQL endpoint URL is ideal. If documentation is unavailable, we can reverse engineer the API surface from web and mobile clients, though providing a specification maximizes testing efficiency.

Can you test GraphQL and gRPC APIs as well as REST? +

Yes. We have specialized expertise in GraphQL security (query depth, introspection, batching abuse) and gRPC Protocol Buffer services, evaluating them with tools specifically built for modern API protocols.

Do you provide ready-to-run reproduction commands for our developers? +

Yes. Every finding in our report includes exact, copy-pasteable curl commands or Postman requests showing the precise headers, authentication tokens, and parameters required to reproduce the issue.

How do you test for multi-tenant data leaks? +

We require at least two distinct user accounts from different organizations or tenants in your test environment. We systematically use the credentials of Tenant A to access, modify, or delete the data belonging to Tenant B.

Client Stories

Trusted by Fast-Growing Companies

JBWeb

Digital Agency

“From Pentest to malware analysis these guys know what they're doing.”

We came to Lorikeet Security with not so small task of tracking down the source of a cyber incident. Lorikeet Security looked at attack vectors and they set up a full test environment and really showed they knew what they were doing. With amazing analytics reports on down to the minute of login attempts. The level of detail that Cyber Insurance Companies wish they had in house - Those reports are an invaluable tool and give confidence and value add to the executive level for pre or post ransomware attacks.

SOCaaS Incident Response
Flowtriq

SaaS Platform

“Streamlined Security Testing with White Glove Service”

We used Lorikeet Security for a PTaaS pentest and briefly tried their ASM tool - both were amazing. Fast tests, accurate findings, and everything handled through a modern interface. The report summary, live chat, asset management, and live quoting features of the portal really stand out. Their 'white glove' touch contributed to a 10/10 experience. They're truly changing the pentest game with the new portal clients can use.

Penetration Testing Continuous Assessments
Next

Scope It in One Call

Tell us what is in scope and we come back with a fixed flat-rate price and a verified start date. No discovery-call maze, no hourly estimates that move.