Scoping from the specification
We ask for the OpenAPI, Swagger, GraphQL schema, or Postman collection up front and scope on the number of endpoints, authentication schemes, and consumer types (first-party web or mobile client, partner integration, public developer API). Undocumented endpoints discovered during testing are in scope by default because they are exactly where the risk lives.
- Typical effort: 4 to 7 testing days for an API of 30 to 80 endpoints with two or three roles.
- Access we need: credentials or tokens for every role, a non-production base URL or a production window, and the specification file.
- Coverage guarantee: every documented endpoint is exercised with every role, and the report lists the ones that produced no finding.