Skip to content

Cost guide

API Penetration Testing Cost

API penetration testing starts at $4,000 for a small API, agreed as a fixed price before testing begins. It covers manual testing of every endpoint across the OWASP API Security Top 10, from broken object-level authorization to data exposure, with a written report and a free retest included.

APIFixed price

Small

A single API with roughly a dozen endpoints, one authentication model, and one or two roles, such as a REST service behind a mobile or web client.

$4,000

Medium

Several dozen endpoints across REST or GraphQL, multiple roles or tenants, and more complex authorization to exercise on each endpoint.

$6,000

Large

A large API surface of many endpoints across multiple versions, several tenants, and partner integrations tested end to end.

$9,500+
Free retest includedFrom $4,000

What moves the number

What drives the cost of API penetration testing

01

Number of endpoints

The endpoint count is the main lever. Each one needs authorization testing across every role, so a dozen endpoints and two hundred endpoints are very different engagements. An OpenAPI spec makes the count exact.

02

Authentication and token models

One simple API key is quick to test. OAuth flows, JWT handling, multiple token types, and session models each add work, because every mechanism carries its own set of abuse cases to exercise.

03

Roles and tenants

Broken object-level authorization is the top API risk, and finding it needs at least two accounts per role and tenant. More roles and tenants means more cross-account tests to run against every endpoint.

04

REST, GraphQL, or SOAP

Each API style is tested differently. GraphQL adds introspection, nested queries, and batching abuse; SOAP adds XML and WS-Security handling. A mixed estate needs more than one test plan.

05

Business flows and rate limits

Checkout, signup, and one-time-code flows can be abused even when each endpoint is sound. Testing for automation abuse and missing limits adds effort proportional to how many sensitive flows the API exposes.

In the price

What every API penetration testing price includes

  • Coverage of all ten OWASP API Security Top 10 categories across REST, GraphQL, and SOAP
  • Manual, role-by-role authorization testing of every endpoint, including BOLA and BFLA
  • A full inventory of the endpoints tested, with example requests and responses
  • A fixed price agreed in writing before work begins, with no hourly billing
  • An executive summary for leadership and a full technical report with reproduction steps
  • A free retest of remediated findings, with the report updated to show them closed
  • An attestation letter and findings platform access at no extra cost
  • Senior in-house testers, OSCP and OSCE3 certified

Keep it tight

How to keep the price down

  1. 01Send an OpenAPI or Swagger spec, or a Postman collection, during scoping. An exact endpoint count means an exact price, with no padding for the unknowns a vague description forces.
  2. 02Provide at least two accounts for each role and tenant. Cross-account authorization testing is the highest-value work on an API, and it is far quicker with the accounts already in hand.
  3. 03Retire or exclude deprecated and duplicate API versions before testing. Paying to test three live versions of the same endpoints when one is current is effort you do not need to spend.
  4. 04Pair the API test with the web or mobile app that consumes it in one engagement. Scoping and onboarding happen once, which costs less than two separate bookings.

Timeline

Onboarding starts within 24 hours of a signed proposal, with testing typically beginning within a week of scoping. A small API of a dozen or so endpoints takes about a week to test, then reporting. Larger APIs with many endpoints, versions, and tenants take longer, and the complimentary retest runs once your developers have shipped the fixes.

Priced the same forSOC 2PCI DSSISO 27001GDPR

FAQ

Questions about API penetration testing cost

01How much does an API penetration test cost?

API testing starts at $4,000 for a small API, fixed before work begins, with a free retest included. Medium APIs start at $6,000 and large ones with many endpoints or complex role models at $9,500 and up. Sharing an OpenAPI spec during scoping lets us confirm a fixed price quickly. Every starting price is on the pricing page.

02What drives the price of an API test?

The endpoint count is the biggest lever, followed by the authentication model and the number of roles and tenants. Broken object-level authorization is the top API risk and needs testing across every role, so more endpoints and more accounts to check mean a larger engagement.

03Does the price cover REST, GraphQL, and SOAP?

Yes, whichever your API uses. Each style is tested differently, so a mixed estate that runs more than one adds scope, but there is no separate product or surcharge. We confirm which styles are in play and price the whole thing as one fixed engagement.

04How do we keep an API test affordable?

Send an OpenAPI or Swagger spec so the endpoint count is exact, provide two accounts per role for cross-account testing, and exclude deprecated versions you no longer run. Bundling the API with the app that consumes it also saves a second scoping pass.

05Is retesting included?

Yes. Once your developers ship fixes we retest the affected endpoints at no extra cost and update the report to show them closed. It is part of the fixed price, so a cheaper initial quote elsewhere can cost more once a separate retest is added.

Get the exact number for your scope

Tell us what needs testing. You get a written fixed price within one business day, and the number does not move once testing starts.

Prefer the full scoping questionnaire? 

Get a Fixed-Scope Quote

Tell us what you need tested. We reply within one business day.