API Penetration Testing
Targeted security assessments of REST, GraphQL, and gRPC APIs - hunting for BOLA, broken function authorization, mass assignment, and data exfiltration vectors.
What This Engagement Covers
The Service
APIs serve as the foundational plumbing of modern software architectures - yet they are frequently the most poorly secured layer. Traditional network firewalls and web scanners fail to understand API data models, leaving broken object-level authorization (BOLA), excessive data exposure, unauthenticated admin routes, and rate-limiting flaws completely unnoticed. Our API penetration testing thoroughly exercises every endpoint in scope against the OWASP API Security Top 10.
What We Test
We test all modern API architectures: RESTful JSON APIs, GraphQL services (including schema introspection, batching, and query complexity), gRPC interfaces, WebSocket streams, and webhook delivery endpoints. We evaluate authentication mechanisms (OAuth 2.0, JWT, API keys, mTLS), authorization policies across multi-tenant architectures, parameter pollution, mass assignment, and backend injection vectors.
Components Evaluated in Scope
Our testers systematically inspect the following architectural layers and attack vectors during the assessment.
How We Run It
We combine automated endpoint fuzzing with deep manual authorization testing. We systematically swap object identifiers across user accounts to identify BOLA flaws, alter HTTP methods to bypass function-level controls, analyze GraphQL schemas for undocumented queries and mutations, and test data parsing libraries for deserialization and injection vulnerabilities.
API Surface Discovery & Documentation
Ingesting OpenAPI/Swagger specs, Postman collections, and probing for undocumented shadow endpoints.
Authentication & Token Security Review
Analyzing JWT validation, signature verification, token expiration, and OAuth 2.0 scope enforcement.
Object-Level Authorization (BOLA) Testing
Systematically manipulating resource identifiers across tenant boundaries to verify strict isolation.
Function-Level Authorization (BFLA) Testing
Attempting administrative API actions using standard user tokens and unauthorized HTTP verbs.
Property-Level Authorization & Mass Assignment
Injecting undocumented parameters to elevate privileges or overwrite read-only record attributes.
GraphQL / gRPC Specific Security Checks
Testing query depth limits, batching attacks, field suggestions, and circular reference vulnerabilities.
Rate Limiting & Resource Exhaustion Testing
Evaluating denial-of-service resilience, pagination limits, and large payload handling.
Reporting & Developer Postman Collections
Delivering detailed findings with reproduction curl commands, CVSS scores, and remediation examples.
What You Receive
Findings land in your tracker as you go, not only in a PDF at the end. Free retesting is included in scope, not billed as a change order.
- OWASP API Top 10 mapped technical findings report with CVSS v3.1 scores
- Actionable curl reproduction commands and Postman verification collection
- Schema-level remediation guidance and input validation patterns
- Authentication and authorization architecture analysis
- Executive risk summary tailored for technology executives
- Free retesting of all critical and high findings within 48 hours
- Letter of Attestation for partner integrations, auditors, and investors
What We Usually Find
The issues this engagement surfaces most often. Your environment will differ, but this reflects typical exposure patterns.
Who This Is For
Findings are mapped directly to OWASP API Security Top 10, SOC 2 Type II, ISO 27001, PCI-DSS v4.0, OSFI B-13, PIPEDA, allowing your team to drop the report into an audit package without manual translation.
Calgary & Toronto Security Specialists
Canadian enterprises integrating with federal open banking initiatives or exposing customer data via APIs must comply with PIPEDA and provincial privacy standards. Lorikeet Security Canada validates that API endpoints strictly enforce multi-tenant isolation and object authorization.
Common Questions
An OpenAPI (Swagger) specification, Postman collection, or GraphQL endpoint URL is ideal. If documentation is unavailable, we can reverse engineer the API surface from web and mobile clients, though providing a specification maximizes testing efficiency.
Yes. We have specialized expertise in GraphQL security (query depth, introspection, batching abuse) and gRPC Protocol Buffer services, evaluating them with tools specifically built for modern API protocols.
Yes. Every finding in our report includes exact, copy-pasteable curl commands or Postman requests showing the precise headers, authentication tokens, and parameters required to reproduce the issue.
We require at least two distinct user accounts from different organizations or tenants in your test environment. We systematically use the credentials of Tenant A to access, modify, or delete the data belonging to Tenant B.
Trusted by Fast-Growing Companies
We came to Lorikeet Security with not so small task of tracking down the source of a cyber incident. Lorikeet Security looked at attack vectors and they set up a full test environment and really showed they knew what they were doing. With amazing analytics reports on down to the minute of login attempts. The level of detail that Cyber Insurance Companies wish they had in house - Those reports are an invaluable tool and give confidence and value add to the executive level for pre or post ransomware attacks.
We used Lorikeet Security for a PTaaS pentest and briefly tried their ASM tool - both were amazing. Fast tests, accurate findings, and everything handled through a modern interface. The report summary, live chat, asset management, and live quoting features of the portal really stand out. Their 'white glove' touch contributed to a 10/10 experience. They're truly changing the pentest game with the new portal clients can use.
Scope It in One Call
Tell us what is in scope and we come back with a fixed flat-rate price and a verified start date. No discovery-call maze, no hourly estimates that move.