API Security Testing Checklist
1. Reconnaissance
π 2. Authentication & Authorization
π 3. API Key / Token Handling
π 4. HTTP Method Manipulation
π 5. Parameter Handling & Injection
π¦ 6. Data Handling & Security
β‘ 7. Rate Limiting & DoS
π― 8. Business Logic Flaws
π 9. Logging & Monitoring
π 10. Reporting & Automation
π¨ 11. GraphQL API Testing
π« 12. API Rate-Limiting & DDoS Testing
π 13. WebSocket Security Testing
PreviousWeb Security Testing ChecklistNextCloud Security Testing Checklist (AWS, Azure, GCP + Reporting)
Last updated