Broken object-level authorisation
Whether changing an ID in a request returns or modifies another user’s data. The most common and most damaging API flaw.
A single broken authorisation check in an API can expose an entire customer dataset. We test every endpoint, documented or not, against the OWASP API Security Top 10.
APIs are now the product surface for most applications: your mobile app, your web front end and your partners all talk to the same endpoints. That makes them the highest-value target, and the one automated scanners understand least, because the interesting flaws depend on who is asking for what.
Our API assessments are manual. We tamper with requests, map object references, replay tokens across accounts and probe every endpoint we can discover, including the ones missing from your documentation. Authentication flows (JWT, OAuth, API keys) are analysed end to end rather than just checked for expiry.
The deliverable is an endpoint-by-endpoint risk register and an authorisation matrix showing which role can reach which resource, so your team can see the shape of the problem and not just a list of bugs.
Whether changing an ID in a request returns or modifies another user’s data. The most common and most damaging API flaw.
Weak token handling, missing expiry, credential stuffing exposure and flaws in JWT and OAuth flows.
Responses that return more fields than the client needs, and writes that accept fields the client should never set.
Whether ordinary users can call administrative endpoints by guessing the path or changing the HTTP method.
Missing rate limits, oversized payloads and expensive queries that allow abuse or denial of service.
Old API versions, undocumented endpoints, permissive CORS, verbose errors and unsafe handling of third-party API data.
Deep testing of REST, GraphQL and internal APIs against the OWASP API Security Top 10.
Purpose
Surface broken object-level authorisation, excessive data exposure and rate-limiting gaps that automated scanners routinely miss.
Scope
Every documented and undocumented endpoint, authentication and authorisation flow, and third-party integration point.
Methodology
Manual request tampering, IDOR mapping, and JWT/OAuth flow analysis mapped against the OWASP API Security Top 10.
Deliverables
Endpoint-by-endpoint risk register, authorisation matrix, exploit chains and a prioritised fix list.
Business Value
“APIs are the backbone of modern products — a single broken authorisation check can expose your entire customer dataset.”
We collect your specification, Postman collections and traffic, then find endpoints that are not documented.
Test accounts at different privilege levels are used to build a matrix of who can reach what.
Request tampering, IDOR checks, token replay and abuse testing across each endpoint and method.
Findings are combined to show realistic impact, such as moving from a low-privilege token to bulk data access.
Risk register, authorisation matrix and a prioritised fix list, with retesting once the fixes are in.
Yes. GraphQL adds its own risks, such as introspection exposure, query depth and batching abuse, alongside the same authorisation problems found in REST. Both are in scope.
An OpenAPI or Postman specification if one exists, a staging environment or agreed production window, and test credentials for at least two users per role.
Yes. Internal APIs, service-to-service endpoints and partner integrations are all assessed when they are in scope.
An API Health Check is ₹4,999, an API Security Assessment is ₹14,999 and API VAPT starts at ₹29,999+. Large API and SaaS platforms are quoted on a custom basis, and the final figure depends on endpoint count and authentication complexity.
Security checks, audits, VAPT, cloud, mobile, API and Security Care. Open the 7-page PDF online, no download needed.
Start with the full division overview, or go straight to the service closest to what you need.
Tell us what you need assessed, built or shipped. We reply within 24 hours with an honest view of scope, timeline and cost.