Prompt
security testing for REST APIs
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
Security testing for REST APIs means checking that an API resists common attacks and enforces the right access controls, validation, and data protection.
Key areas to test
1. Authentication
Verify only valid users can access the API.
- Test missing/expired/invalid tokens
- Check token signature, expiry, and audience/issuer validation
- Ensure login endpoints resist brute force and credential stuffing
- Verify MFA if required
2. Authorization
Make sure authenticated users can only access allowed resources.
- Test horizontal access control issues: user A accessing user B’s data
- Test vertical privilege escalation: regular user accessing admin endpoints
- Verify object-level authorization on every request
- Check IDOR issues by changing resource IDs
3. Input validation
API inputs should be strictly validated.
- Send unexpected data types, oversized payloads, nulls, and special characters
- Test SQL injection, NoSQL injection, command injection
- Check JSON/XML parsing edge cases
- Verify schema validation and reject unknown fields if appropriate
4. Rate limiting and abuse prevention
Prevent misuse and denial of service.
- Test whether repeated requests are throttled
- Check login, OTP, password reset, and search endpoints
- Verify limits per user, IP, token, and device as appropriate
5. Sensitive data exposure
Ensure secrets and personal data are protected.
- Check responses for unnecessary PII
- Verify passwords, tokens, keys, and internal IDs are not leaked
- Confirm HTTPS/TLS is enforced
- Review logging for sensitive data exposure
6. Session and token security
If the API uses cookies or tokens:
- Ensure tokens are stored and transmitted securely
- Check token expiration and revocation
- Verify refresh token handling
- Confirm no token leakage through URLs, logs, or responses
7. Error handling
Errors should not reveal internal details.
- Check for stack traces, SQL errors, framework versions, or debug info
- Ensure consistent error messages
- Avoid information leakage about valid users or resources
8. CORS and browser-related issues
If the API is called from browsers:
- Test CORS headers and allowed origins
- Avoid wildcard origins with credentials
- Verify preflight behavior
9. Mass assignment
Ensure attackers cannot set hidden fields.
- Try adding unexpected fields like
role,isAdmin,price,ownerId - Confirm the API only accepts intended attributes
10. Business logic abuse
Look for flaws in workflow enforcement.
- Test replay attacks, parameter tampering, race conditions
- Try skipping steps in multi-step flows
- Check coupon, payment, balance, and approval logic
11. File upload security
If the API accepts files:
- Validate file type, size, and content
- Scan uploads for malware
- Prevent path traversal and executable uploads
- Store uploads safely
12. Security headers and transport
- Enforce HTTPS
- Use HSTS where applicable
- Check cache control for sensitive responses
- Ensure strict content types
Common tools
- Postman / Insomnia: manual testing
- OWASP ZAP / Burp Suite: interception, fuzzing, authorization checks
- curl / httpie: quick request manipulation
- OpenAPI/Swagger validators: schema-based testing
- k6 / JMeter: load and abuse testing
Good testing process
- Review API docs and schemas
- Map endpoints, auth methods, roles, and data flows
- Test positive and negative cases
- Fuzz parameters and payloads
- Validate access controls
- Check logs, monitoring, and alerting
- Repeat after changes and before release
Reference checklist
If you want a standardized baseline, use:
- OWASP API Security Top 10
- OWASP ASVS
- NIST guidance for authentication and access control
If you want, I can also provide:
- a REST API security test checklist
- sample test cases
- a Burp Suite workflow
- or a Postman-based security testing plan.