# API Security Assessment

> From $12K · Offensive Security · https://cisomarketplace.services/services/api-security-assessment

Comprehensive testing of API endpoints and integrations

## In scope

- API inventory and documentation review (OpenAPI / GraphQL schemas)
- Authentication and token handling (OAuth 2.0, JWT, API keys)
- Object- and function-level authorization testing (OWASP API Security Top 10)
- Input validation, mass assignment and injection testing
- Rate limiting, quotas and abuse resistance
- Gateway, logging and monitoring configuration review

## Deliverables

- API security report mapped to the OWASP API Security Top 10
- Reproducible findings with requests and responses
- Remediation guidance for developers and platform teams
- Executive summary
- Retest of fixed findings

## Tiers

### Core API Assessment: $12K

Manual and automated security testing of 1 API with up to 25 endpoints and up to 2 user roles, against common API vulnerability classes (broken authorisation and authentication, injection, data exposure). Report plus 1 retest of fixed findings.

Limits: apis 1

Includes:
- 1 API, up to 25 endpoints
- Up to 2 user roles
- Common API vulnerability classes
- Findings report with fix guidance
- 1 retest round

Excludes:
- Third-party and internal integration testing
- Detailed authentication and token flow review
- Business logic abuse testing
- Custom exploit development

### Advanced API Assessment: $20K

Testing of up to 3 APIs with up to 75 endpoints in total and up to 4 user roles. Adds detailed review of authentication and token flows, business logic abuse, rate limiting, and testing of integration points such as webhooks and third-party connections.

Limits: apis 3

Includes:
- Up to 3 APIs, 75 endpoints total
- Up to 4 user roles
- Authentication and token flow review
- Business logic and rate-limit testing
- Integration point testing
- 1 retest round

Excludes:
- Custom exploit development and chained attacks
- API gateway and design architecture review
- More than 1 retest round

### Enterprise API Assessment: $35K

Testing of up to 10 APIs with up to 250 endpoints in total, all roles and all integrations. Adds custom exploit development, chained attack paths across services, API gateway configuration review and 2 retest rounds.

Limits: apis 10

Includes:
- Up to 10 APIs, 250 endpoints total
- All user roles and integrations
- Custom exploit development
- Chained attack paths across services
- API gateway configuration review
- 2 retest rounds

Excludes:
- Web or mobile front-end testing
- Source code review
- Denial-of-service load testing
- Continuous API monitoring

## Terms

Starting price shown is the lowest published tier. A written proposal fixes scope, tier and price before anything is signed. Timeline is set in the SOW.

Scope this engagement: https://cisomarketplace.services/scope?service=api-security-assessment
