Solutions / What we cover

Test the API as more than a list of endpoints.

Casco uses API documentation when available and observes network calls made by the workflows in scope. Its reasoning engine can learn how to call REST, GraphQL, WebSocket, and other reachable protocols, then check whether a user can access another object, call a restricted function, expose more data than intended, or bypass a business rule.

Testing workflowApproved scope only
  1. 01Approved API scopeHosts, roles, tokens, and documentation
  2. 02Map calls and identitiesREST, GraphQL, WebSocket, and other traffic
  3. 03Authorization testsObjects, functions, roles, tenants, and state
  4. 04Report and retestAffected endpoint, impact, fix, and retest
Routes, identities, objects, and requestsApproved scope only

What is API pentesting?

API pentesting checks whether an API enforces authentication, authorization, data-handling, and business rules as intended. Casco is not limited to a particular API specification: it can test REST, GraphQL, WebSocket, and other network calls that are in scope and reachable with the access provided. Confirmed findings include fix guidance and, when available, the request sequence used to reproduce the issue.

How Casco tests

How Casco tests an API.

Scroll through the four parts of the test. The diagram shows what Casco has at each point, what it checks next, and what it records.

Test contextStep 01 / 04
Hosts
Rules
Test roles
API docs
StageScope
API scope recorded
01

Set the scope

List the approved hosts, endpoints, accounts, roles, and actions Casco must avoid. Provide API documentation and sample workflows when available.

02

Map requests and identities

Casco records protocols, routes, methods, parameters, objects, accounts, and request sequences from the documentation and network traffic available in the test.

03

Test authorization and business rules

Casco changes object references, roles, tenants, parameters, and request order to check access control, data handling, state changes, and application rules.

04

Write and retest findings

Each confirmed issue can include the affected endpoint or object, impact, fix guidance, reproduction steps, and captured requests when request tracking is available.

Pentest deliverables

What the API report contains.

The report ties each confirmed issue to the affected operation, identity or role, impact, and fix.

  • Approved API scope, identities, roles, and test limits
  • Prioritized findings with severity, affected endpoints, and impact
  • Reproduction steps and captured requests when tracking is available
  • Remediation guidance plus finding status for retesting

Checks included when applicable

What Casco checks for.

The checks depend on the protocol, accounts, roles, documentation, and traffic in the test. Casco reports behavior it can confirm, not an endpoint inventory.

Broken object level authorization
Broken function level authorization
Excessive data exposure
Mass assignment
GraphQL abuse and introspection risk
Rate limit and workflow bypasses

Frequently asked questions

API pentesting questions, answered.

What is AI API pentesting?+

AI API pentesting uses software agents to send requests, inspect responses, and choose the next security test. Casco tests the approved endpoints and accounts and reports vulnerabilities it can reproduce.

Can Casco test authenticated APIs?+

Yes. Provide credentials or tokens for each role or tenant boundary you want tested. Documentation and sample application traffic help Casco reach the intended workflows.

Does Casco test REST, GraphQL, and WebSocket APIs?+

Yes. Casco is not limited to one API specification. Its reasoning engine can observe network calls and learn how to call REST, GraphQL, WebSocket, and other reachable protocols. The relevant traffic, endpoints, test identities, and rules of engagement must be included in the scope.

How is API pentesting different from API scanning?+

An API scanner usually applies predefined checks to individual requests. Casco can change a request based on the previous response and test a sequence that crosses objects, roles, or application states.

What access does Casco need for API pentesting?+

Casco needs the approved hosts or endpoints, rules of engagement, and credentials or tokens for logged-in coverage. API documentation, role definitions, and sample workflows help define what should be tested.

Can Casco test object authorization and tenant isolation?+

Yes. Provide test identities and objects for each role or tenant boundary. Casco compares what each identity can read, change, or call.

What comes with a confirmed API finding?+

A finding can include severity, the affected endpoint or object, impact, fix guidance, reproduction steps, execution output, and captured requests when request tracking is available.

Does Casco retest API findings?+

Yes. Casco records the original result, the retest, and the current finding status.

Scope a pentest for this system.

Book a demo