I will perform API penetration testing and security assessment


Level 2
About this gig
Your API is your biggest attack surface and the place most testers go shallow. I go deep.
Senior pentester (OSCP, OSWE, CBBH) specialized in REST and GraphQL security. I test the way real attackers and bug bounty hunters do, by hand, chaining small flaws into real impact.
What I test:
- Broken object-level auth (IDOR/BOLA) and broken function-level auth across every endpoint
- Mass assignment, excessive data exposure, and auth/JWT/OAuth flaws
- GraphQL introspection, batching, and rate-limit bypass
- Business logic, injection, and SSRF reachable through the API
What you get:
- A professional report mapping each issue to the OWASP API Top 10, with CVSS severity, raw proof,
and step-by-step fixes
- An executive summary plus a developer-focused technical section
- One free retest after remediation
Send me your API docs (Swagger/Postman) or base URL and roles, and I will scope it and quote a fixed price before you order.
Respect third-party rights
Please be aware that it is against Fiverr's policies for sellers to include themes, templates, or any other elements that infringe third-party rights or applicable laws in the delivered work. Read more about in our Guide to Responsible Digital Creation.
Get to know Cyber Services
Senior Red Team Operator and Penetration Tester OSCP, OSEP, CRTO
Level 2
- FromPakistan
- Member sinceFeb 2024
- Avg. response time1 hour
- Last delivery2 weeks
Languages
English, Urdu, Punjabi, Hindi
FAQ
REST and GraphQL both?
Yes, plus SOAP and gRPC on request.
Do you need credentials?
Test accounts for each role give the best results, but I can also test the unauthenticated surface only.

