Set the scope
List the approved hosts, endpoints, accounts, roles, and actions Casco must avoid. Provide API documentation and sample workflows when available.
Casco uses API documentation when available and observes network calls made by the workflows in scope. Its reasoning engine can learn how to call REST, GraphQL, WebSocket, and other reachable protocols, then check whether a user can access another object, call a restricted function, expose more data than intended, or bypass a business rule.
API pentesting checks whether an API enforces authentication, authorization, data-handling, and business rules as intended. Casco is not limited to a particular API specification: it can test REST, GraphQL, WebSocket, and other network calls that are in scope and reachable with the access provided. Confirmed findings include fix guidance and, when available, the request sequence used to reproduce the issue.
How Casco tests
Scroll through the four parts of the test. The diagram shows what Casco has at each point, what it checks next, and what it records.
List the approved hosts, endpoints, accounts, roles, and actions Casco must avoid. Provide API documentation and sample workflows when available.
Casco records protocols, routes, methods, parameters, objects, accounts, and request sequences from the documentation and network traffic available in the test.
Casco changes object references, roles, tenants, parameters, and request order to check access control, data handling, state changes, and application rules.
Each confirmed issue can include the affected endpoint or object, impact, fix guidance, reproduction steps, and captured requests when request tracking is available.
Pentest deliverables
The report ties each confirmed issue to the affected operation, identity or role, impact, and fix.
Learn more
Read how Casco confirmed and disclosed an API vulnerability during an approved test.
Read the sourceCompare fixed checks, scanner output, manual testing, and Casco agent testing.
Read the sourceReview Casco's penetration testing accreditation and supervised testing option.
Read the sourceChecks included when applicable
The checks depend on the protocol, accounts, roles, documentation, and traffic in the test. Casco reports behavior it can confirm, not an endpoint inventory.
Related testing
Frequently asked questions
AI API pentesting uses software agents to send requests, inspect responses, and choose the next security test. Casco tests the approved endpoints and accounts and reports vulnerabilities it can reproduce.
Yes. Provide credentials or tokens for each role or tenant boundary you want tested. Documentation and sample application traffic help Casco reach the intended workflows.
Yes. Casco is not limited to one API specification. Its reasoning engine can observe network calls and learn how to call REST, GraphQL, WebSocket, and other reachable protocols. The relevant traffic, endpoints, test identities, and rules of engagement must be included in the scope.
An API scanner usually applies predefined checks to individual requests. Casco can change a request based on the previous response and test a sequence that crosses objects, roles, or application states.
Casco needs the approved hosts or endpoints, rules of engagement, and credentials or tokens for logged-in coverage. API documentation, role definitions, and sample workflows help define what should be tested.
Yes. Provide test identities and objects for each role or tenant boundary. Casco compares what each identity can read, change, or call.
A finding can include severity, the affected endpoint or object, impact, fix guidance, reproduction steps, execution output, and captured requests when request tracking is available.
Yes. Casco records the original result, the retest, and the current finding status.