Skip to content
Safestorm
Menu

Core service

API Security Testing

Manual testing of REST, GraphQL and other APIs for authorisation, data exposure and business-logic weaknesses.

API security testing examines how identities, objects, functions and business workflows are protected at the service boundary. Safestorm tests the documented interface and the behaviours discovered during assessment, with particular attention to authorisation failures that automated scanners cannot reliably determine.

Founder-led technical delivery

Why Safestorm for this assessment

Felix combines application-security testing with an attacker’s focus on identity and trust. For APIs, that means comparing intended permissions with effective behaviour across users, roles and tenants, varying structured input to expose SQL or NoSQL injection behaviours, and examining whether individual authorisation or workflow weaknesses can be chained into material data or account impact.

  • More than six years’ offensive-security experience
  • OSCP and OSEP certified
  • Red teaming, adversary simulation and control validation
  • Published IPv6 research presented at BSides London

Felix’s prior experience includes identifying high-impact weaknesses in healthcare environments. Client identities and engagement details remain confidential.

What the assessment covers

Final coverage is agreed during scoping and reflects your technologies, user roles, threat model and operational constraints.

  • Endpoint, operation, parameter and data-object discovery
  • API keys, OAuth 2.0, OpenID Connect, JWTs and service-to-service authentication
  • Broken object-level and function-level authorisation, including BOLA and BFLA
  • Object-property authorisation, mass assignment and excessive data exposure
  • Resource consumption, rate controls and unrestricted sensitive business flows
  • Injection, server-side request forgery and unsafe consumption of upstream APIs
  • GraphQL query, mutation, introspection, batching and depth controls where applicable
  • Versioning, inventory management, error handling and security misconfiguration

Common risks identified

Testing is not limited to this list. These examples illustrate the types of material risk the assessment is designed to uncover.

  • Users reading or modifying objects that belong to another account or tenant
  • Lower-privileged identities invoking administrative operations
  • Sensitive fields exposed or accepted because property-level controls are incomplete
  • Automation of high-value workflows such as registration, booking or redemption
  • Weak token validation enabling impersonation or cross-service token reuse

A controlled process

How the engagement works

  1. Step 1

    Define API hosts, versions, roles, workflows and dependencies

  2. Step 2

    Agree test identities, rate constraints and prohibited operations

  3. Step 3

    Import documentation and discover the effective API surface

  4. Step 4

    Test identity, object, function and property-level controls

  5. Step 5

    Investigate business logic, automation and chained attack paths

  6. Step 6

    Report reproducible requests, debrief engineers and retest fixes

Who this service is suitable for

  • Customer, partner, mobile-backend and internal service APIs
  • REST, GraphQL and mixed API estates
  • Microservices handling sensitive data or privileged business operations
  • APIs approaching launch, integration or a significant version change

Not sure whether this is the right assessment? Safestorm can help define the assurance question before recommending a scope.

Methodology and industry references

Testing is risk-led and tailored rather than reduced to a checklist. Relevant, recognised guidance helps structure coverage and communicate results.

Referencing a framework does not represent certification against it or guarantee compliance with every control.

Frequently asked questions

Do you require an OpenAPI or GraphQL schema?

Documentation improves coverage and efficiency but is not always essential. OpenAPI collections, GraphQL schemas, example requests and role definitions help establish intended behaviour and identify undocumented endpoints.

Does API testing include the web or mobile client?

The client may be used to understand workflows and obtain legitimate API traffic, but full testing of the client application should be scoped separately when required.

Can you test multi-tenant authorisation?

Yes. Representative identities for different tenants and privilege levels allow Safestorm to assess object, function and property-level isolation more effectively.

Define the right scope

Tell us what you need to assess, your timescale and the assurance outcome you need. We will propose a proportionate scope and clear rules of engagement.

Discuss your requirements