API Security Testing Checklist

1. Reconnaissance


πŸ” 2. Authentication & Authorization


πŸ”‘ 3. API Key / Token Handling


πŸ”„ 4. HTTP Method Manipulation


πŸ’‰ 5. Parameter Handling & Injection


πŸ“¦ 6. Data Handling & Security


⚑ 7. Rate Limiting & DoS


🎯 8. Business Logic Flaws


πŸ“Š 9. Logging & Monitoring


πŸ“ 10. Reporting & Automation


🎨 11. GraphQL API Testing


🚫 12. API Rate-Limiting & DDoS Testing


πŸ”Œ 13. WebSocket Security Testing

Last updated