Home / Services / API security testing

API security testing

API security testing where UK SaaS actually breaks.

Two authenticated identities, every object ID, every GraphQL field. This is the engagement that finds the IDOR your last web scan called ‘informational’.

Source on a laptop. Two authenticated identities, every object ID.
Source on a laptop. Two authenticated identities, every object ID.

Coverage

Two accounts or it did not happen

Object-level auth

Change the ID, get the other tenant. Horizontal and vertical. UUID is not access control.

BOLAIDOR

Function-level auth

Admin mutations reachable as a user. Hidden verbs. Verb tampering.

BFLAAdmin

Tokens & sessions

JWT alg confusion, long-lived refresh, missing audience, leaked in logs.

JWTOAuth

GraphQL & mass assignment

Introspection in prod, batching, nested queries, binding extra fields into privileged updates.

GraphQLMass assignment

UK procurement teams have learned to ignore ‘possible IDOR’. The report they keep is the one with two sessions, two responses, and a screenshot of the other organisation’s invoice.

Ready to scope a UK engagement?

A thirty-minute call. Assets, timeline, a quote in pounds sterling.

Request a quote