Prompt
API security testing
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
API security testing is the process of finding vulnerabilities in an API before attackers do. It focuses on whether the API properly authenticates users, enforces authorization, validates input, protects data, and resists abuse.
What to test
1) Authentication
Check whether the API correctly verifies identity.
- Missing or weak auth on sensitive endpoints
- Broken JWT validation
- Token leakage or reuse
- Session fixation or improper token expiration
2) Authorization
Check whether users can access only what they should.
- IDOR / BOLA: changing object IDs to access others’ data
- BFLA: calling functions or endpoints without permission
- Role/tenant boundary bypasses
- Privilege escalation
3) Input validation
Look for unsafe handling of user input.
- SQL/NoSQL injection
- Command injection
- SSRF
- Path traversal
- Deserialization issues
- Mass assignment / over-posting
4) Rate limiting and abuse controls
- Brute force protection
- Credential stuffing defenses
- Enumeration prevention
- Throttling and quotas
- CAPTCHA or step-up controls where appropriate
5) Data exposure
- Excessive data in responses
- Sensitive fields exposed in errors
- Verbose stack traces
- PII or secrets returned unnecessarily
- Insecure object references in URLs or JSON
6) Transport and config
- TLS enforced
- Weak ciphers disabled
- CORS configured properly
- Security headers where relevant
- Debug endpoints disabled
- Swagger/OpenAPI not exposing sensitive functionality publicly
7) Business logic
- Bypassing workflow steps
- Reusing coupons, tokens, or one-time actions
- Manipulating quantities, prices, or state transitions
- Race conditions
Common testing methods
Manual testing
- Send requests with Burp Suite, Postman, curl, or similar
- Modify headers, IDs, roles, and payloads
- Compare responses across user accounts
Automated testing
- API security scanners
- Fuzzing inputs
- Schema-based tests against OpenAPI specs
- Unit/integration security tests in CI/CD
Threat modeling
- Map endpoints, trust boundaries, and data flows
- Identify high-value assets and abuse cases
- Prioritize tests based on risk
Useful standards and references
- OWASP API Security Top 10
- OWASP ASVS
- NIST guidance for application security
- OpenAPI/Swagger for schema-driven testing
Example test cases
- Can user A access user B’s resource by changing
id=123toid=124? - Can an unprivileged user call admin-only endpoints?
- Does the API accept extra fields like
role=adminin requests? - Can a token still work after logout or expiration?
- Does the endpoint return too much user information?
Safe process
- Inventory endpoints and authentication methods
- Test one role at a time
- Validate authorization on every request
- Record findings with evidence
- Fix and retest
If you want, I can also give you:
- an API security testing checklist
- a Burp Suite workflow
- an OWASP API Top 10 mapping
- or sample test cases for REST/GraphQL APIs