API penetration testing services: published prices, scope and retest terms compared
By The PenTest Index · Offers checked October 9, 2026 · How we check offers
API penetration testing services are security tests of your API's endpoints, logins and permissions, sold alone or inside a web or mobile app test. Published prices for a small standalone API start at $4,000 (Atlant Security, up to 50 endpoints; Invadel, about a dozen). Your endpoint count, roles and retest deadline decide the real number.
Here is the short version. The table that backs it up is right below.
- A web or mobile app sits in front of your API, and that app is being tested. You may not need a separate purchase. Get the API written into that scope by name.
- Your API stands alone and is small to mid-sized. Start with these three offers that publish an API price: Astra, Atlant Security and Invadel.
- Your API serves many customers from one system. Look at Invadel's $6,000 tier and ask Adversim for a quote. Both spell out role and tenant testing.
- Your fixes will take more than 30 days. Astra's included re-scans won't fit unless Astra extends them in writing.
Jump to the comparison · Copy the API brief
API penetration testing services compared
Four of the eight offers we checked publish a price that names APIs. Five still need a quote, including Synack for its required platform line item, but most publish how they count an API or how many retests you get. We read each provider's own pages on October 9, 2026. We did not buy or run any of these tests.
Offers are listed A to Z within each group. Nobody paid to be here. Prices appear as each provider shows them, with a dollar sign and no currency code, so ask for the billing currency in your quote. "Not stated" means we did not find it in the pages we read.
Offers with a published API price
| Offer | How it counts your API | Published price | Retest terms | Stated timing |
|---|---|---|---|---|
| Astra · Pentest Expert | A standalone API is one target. A web app plus every API it uses is also one target. | $5,999 per year, per target. An annual package with a manual pentest and ongoing scanning, not a one-test price. | Two re-scans by Astra's testers. You must ask within 30 days of the findings being reported. Extensions are case by case. | Manual pentest: 10–15 working days |
| Atlant Security · API pentest | Up to 50 endpoints. REST, GraphQL or gRPC. All roles. | From $4,000. The fixed price is set in writing after a scoping call. | One free retest. Deadline not stated. | 5–7 days of testing. Report within 14 days of the start. |
| Invadel · API pentest | Three size tiers. Small: about a dozen endpoints, one or two roles. Medium: several dozen endpoints, multiple roles or tenants. Large: many endpoints, versions and tenants. | From $4,000 / $6,000 / $9,500+ by tier. Not a per-endpoint rate. | Free retest of the findings you fix. Count and deadline not stated. | About a week of testing for a small API, then the report |
Sources: Astra pricing and Astra rescan rules; Atlant Security API pentest; Invadel API pricing. All provider-published, checked October 9, 2026.
Two things to know before you lean on these numbers. "From" is a floor. Atlant Security and Invadel both say the fixed price is the one they send you in writing. And these are small firms we read about, not firms we've used. We haven't bought from them, checked their credentials or confirmed where their testers work.
Offers that need a quote
| Offer | What it says about API scope | Price | Retest terms | Stated timing |
|---|---|---|---|---|
| Adversim · API penetration testing | REST and GraphQL. Asks for test accounts for each role and, where relevant, two separate tenants. The report includes a summary of which endpoints were tested with which roles. | Quoted as a fixed fee. No public price. | Critical and high findings are retested after you fix them. Count and deadline not stated. | Active testing: one to three weeks |
| BreachLock · Extended package | The Extended package is described as fitting "APIs needing advanced testing." BreachLock states its testers are in-house. | Quote required | Two free manual retests. Deadline not stated. | Not stated |
| Cobalt · API pentest on annual credits | You enter your number of user roles and your number of REST endpoints, or GraphQL queries and mutations. A calculator turns that into credits. REST, GraphQL and SOAP are named. | Quote required. Sold as annual credit packages. | Free retests for 6 months (Standard) or 12 months (Premium, Enterprise) for Agile and Comprehensive pentests while your contract is active. The request window closes 10 days before your contract ends, if that comes first. | "Launch your API pentest in 24 hours," per its API page |
| NetSPI · API penetration testing | Signed-in and anonymous testing, access checks across user roles, manual and automated work. REST, SOAP and GraphQL are named. NetSPI states its testers are employees. | Quote required | Not mentioned on the API page | Not stated |
| Synack · Synack14 | The lowest-priced package whose asset list includes "api." Endpoint limits for an API are not stated. | From $27,120 per test, plus a required platform charge that is a separate line item. The total is incomplete until Synack itemizes it. | Patch verification is listed. Count and deadline not stated. | 14-day testing window |
Sources: Adversim API testing; BreachLock packages; Cobalt API pentest, Cobalt scoping rules and Cobalt retest rules; NetSPI API testing; Synack pricing. All provider-published, checked October 9, 2026.
Web app offers that don't say whether your API is covered
Some lower-priced offers are sold for web apps. Don't assume they include a standalone API.
Pentest-Tools.com's managed web app test lists $3,400 for a black-box test and prices starting at $3,400 plus $900 per user role for a gray-box test. Its service description does not mention API coverage (source, checked October 9, 2026). Cobalt's Autonomous Pentest and Intruder's AI web app pentest are both listed for web applications in our main comparison, checked October 7, 2026.
If one of these is on your list, ask one question first: "Is our API in scope, and what does that cost?"
Which API pentest offer should you look at first?
Pick by the thing that would rule an offer out for you. For most buyers that is the retest deadline, the endpoint limit, or whether tenants are covered.
| Your situation | Look first | Confirm before you book |
|---|---|---|
| Your API sits behind an app you're already having tested | Your current provider | That the API is in scope by name, with the roles listed |
| Small standalone API, and you want a price today | Atlant Security, Invadel, Astra Pentest Expert | The fixed price in writing, and the deadline to ask for the retest |
| One system serving many customers (multi-tenant) | Invadel's medium tier; Adversim by quote | That both directions between two test tenants get tested |
| Fixes will take more than 30 days | Anyone except Astra's standard terms | A written retest deadline that lands after your fix date |
| Several tests a year | Cobalt's credit packages | Credits needed, and which pentest type your report needs |
| You want a provider-employed team or have a large API estate | BreachLock, NetSPI | Who will test, and the full price |
| You already have a provider you trust | Them | Their answers to the brief below. Keeping them may be the right call. |
Atlant Security deserves one extra question if you're multi-tenant. Its $4,000 row covers an API with "all roles." Tenant isolation appears on a separate row, "SaaS multi-tenant platform," from $6,000. Ask which row your API falls under.
Already know which one fits? Go straight to the provider and send them the brief below, so their answer lines up with everyone else's.
See Adversim's API penetration testing
See Astra's Pentest Expert plan
See Atlant Security's API pentest pricing
See Invadel's API pentest pricing
See NetSPI's API penetration testing
See Synack's API penetration testing
Is API testing included in a web app pentest?
Sometimes. It depends on the offer, so get it in writing.
Providers handle this differently. Astra counts a web app and every API it uses as one target. Adversim says its web app test covers the app's APIs, and that a separate API test makes sense when the API is public, used by partners or mobile apps, or does things the website doesn't show. Cobalt sells "Web + API" as a combined scope. Pentest-Tools.com's web app service description doesn't mention API coverage.
Think of a web app test as checking the doors a person can see in a browser. Your API may have more doors than that. A partner-only endpoint or a mobile-only endpoint has no button on the website. A tester who works from the browser can miss it unless it's on the list.
So before you buy a second test, send your current provider your endpoint list and ask what's already covered. Invadel's own pricing page says pairing the API with the app that uses it costs less than two separate bookings.
Testing both together? Our checklist for a web app and its API covers the boundary questions.
How much does an API penetration test cost?
In the prices we could find published, a small API starts at $4,000, a mid-sized one at $6,000, and a large one at $9,500 or more. Most providers still quote case by case.
Here are the published API prices from the first group, in one place:
| What you get | Published price | Who publishes it |
|---|---|---|
| One API, up to 50 endpoints, all roles, one free retest | From $4,000 | Atlant Security |
| One small API, about a dozen endpoints, one or two roles, free retest | From $4,000 | Invadel |
| One medium API, several dozen endpoints, multiple roles or tenants, free retest | From $6,000 | Invadel |
| One large API, many endpoints, versions and tenants, free retest | From $9,500 | Invadel |
| One standalone API as an annual package with scanning and two re-scans | $5,999 per year | Astra |
Checked October 9, 2026. These are advertised starting prices, not quotes for your API.
You'll also see price ranges in vendor blog posts. Those are sellers' estimates, they don't agree with each other, and none we saw shows where its numbers come from. We left them out.
How providers count an API
The price follows the count, and each provider counts differently.
- Endpoints. Atlant Security and Invadel size by endpoints. Cobalt does too, and tells you how: count each endpoint URL once, ignoring specific parameters. A GET and a POST to the same URL are one endpoint.
- GraphQL. A GraphQL API has one URL, so counting URLs tells you nothing. Cobalt asks for the number of queries and mutations instead.
- Targets. Astra counts a standalone API as one target, whatever its size. Its pricing FAQ adds that several APIs "can be clubbed into one target," so ask how yours would be counted.
- Roles and tenants. Every provider here asks about them. More roles means more permission checks on every endpoint.
Count yours before you ask for a price. Your OpenAPI file or Postman collection has the number.
A worked example
This buyer is made up. No provider has quoted for it.
Say you run a 30-person software company with one partner-facing REST API. It has 40 endpoints, counting each endpoint URL once and ignoring specific parameters and HTTP methods. It has three roles: Viewer, Editor and Admin. It serves many customers, so you set up two test tenants. Your SOC 2 auditor wants a report. Your developers need about 45 days to ship fixes.
Three roles across two tenants gives 3 × 2 = 6 role-and-tenant combinations, requiring 12 test accounts at Invadel's two accounts per role and tenant. That is not 240 tests and it is not a price formula. It just tells the provider how much permission checking there is.
Here is what the published terms say about that buyer:
| What you need | Offer | What we found | Ask this |
|---|---|---|---|
| 40 endpoints, 3 roles, 2 tenants | Invadel | Supported, as a starting price. "Several dozen endpoints" with "multiple roles or tenants" is the medium tier: from $6,000. | "Is 40 endpoints, three roles and two tenants your medium tier, and what is the fixed price?" |
| 40 endpoints, 3 roles, 2 tenants | Atlant Security | Unresolved. 40 is under the 50-endpoint limit on the $4,000 row. Tenant isolation is on a separate row from $6,000. | "Which price row covers a 40-endpoint API with two tenants?" |
| Roles and tenants tested | Adversim | Supported for that one point. It asks for accounts for each role and two tenants. Price is by quote. | "What is your fixed fee for this scope?" |
| A retest requested on day 45 | Astra Pentest Expert | Mismatch. Re-scans must be requested within 30 days of the findings. Day 45 is too late. | "Can you extend the re-scan window to 45 days in writing, and what does that cost?" |
| A retest requested on day 45 | Atlant Security, Invadel | Unresolved. Both say the retest is free. Neither gives a deadline. | "Is there a deadline to ask for the free retest?" |
| A retest requested on day 45 | Adversim | Unresolved. Critical and high findings are retested. No deadline is given, and lower-severity findings aren't mentioned. | "Will you retest medium findings, and until when?" |
| A retest requested on day 45 | Cobalt | Supported, with a condition. Six or twelve months is plenty for a day-45 request on an Agile or Comprehensive pentest, as long as your contract is still active and more than 10 days from ending. | "What is the calendar date our retest window closes?" |
| A full price | Synack14 | Unresolved. $27,120 plus a platform charge with no listed amount. An unknown charge is not zero. | "Please itemize the test and the platform charge for one API." |
Where that leaves this buyer. Astra is out unless it extends the window in writing. Invadel is the clearest fit on paper at a $6,000 start. Atlant Security and Adversim are worth a quote, each with one question to settle. Cobalt can fit one annual pentest or several tests this year.
"Supported" means the published terms back that one point. It doesn't mean the provider is good, or that your auditor will accept the report.
API penetration testing vs API vulnerability scanning
A scan is software checking your API for known problems. A penetration test is someone trying to reach data or actions they shouldn't be able to.
The difference shows up in one question: can customer A read customer B's invoice? To answer it, a tester needs two accounts and has to know what each one is supposed to see. That's what you're paying a pentest for.
Scans are a separate, cheaper purchase. Astra, for example, sells an API scanner at $199 a month or $1,999 a year, next to its $5,999 pentest plan (source, checked October 9, 2026). Both are useful. They aren't the same thing, so check which one a quote is for.
AI-led pentests sit in between and are their own category. The ones in our main comparison are sold for web apps. If you're offered one for an API, ask what a person checks and what your report recipient thinks of it.
What should an API pentest cover?
At a minimum, who can reach what. Most serious API flaws are permission flaws.
One buyer on Reddit put the worry plainly. They had 25 endpoints and wanted to be sure "users can only fetch / edit their own data." A reply asked the right follow-up: "25 endpoints but how many user roles?" That exchange is the whole scoping problem in two lines.
The common reference list is the OWASP API Security Top 10 (2023). Its ten risks are:
- Broken object level authorization. Change the ID in a request and get someone else's record.
- Broken authentication
- Broken object property level authorization. Read or change a field you shouldn't, such as your own role.
- Unrestricted resource consumption
- Broken function level authorization. A normal user calls an admin action.
- Unrestricted access to sensitive business flows
- Server side request forgery
- Security misconfiguration
- Improper inventory management. An old version still answers.
- Unsafe consumption of APIs
OWASP's list names risks. It is not a test plan, and it is not a rule from any auditor. A provider saying "we cover the OWASP API Top 10" tells you less than a provider saying which roles and tenants it will test.
Three things to settle in the scope:
- API type. REST, GraphQL, gRPC and SOAP are tested differently. Atlant Security names REST, GraphQL and gRPC. Invadel names REST, GraphQL and SOAP. Cobalt and NetSPI name REST, GraphQL and SOAP. Adversim names REST and GraphQL. If yours isn't named, ask.
- Same-role checks. Two Editors in the same tenant shouldn't be able to edit each other's private drafts. That takes two accounts with the same role. Atlant Security and Invadel both ask for two accounts per role.
- What's left out. Cobalt's API method page says third-party logins such as "Login with Google" are out of scope. Every provider has a list like that. Ask for it.
What do you need to give the testers?
Five things: your API docs, test accounts, an environment, limits, and a contact.
- Docs. An OpenAPI or Swagger file, a Postman collection or a GraphQL schema. Adversim and Atlant Security both say they can work without one, by building the list from your app's traffic. That takes longer.
- Accounts. Two per role, in each of two test tenants if you have tenants.
- Environment. Staging or production. Either can work. Staging is safer if it runs the same permission code.
- Limits. How many requests per minute, what hours, and which payment or messaging services must not be touched.
- A contact. One person on each side who can stop the test.
Never put passwords, keys or tokens in a scope document. Agree how to share access with the provider you hire.
How long does an API pentest take?
For a small API, the published testing times run from about one week to three. The report and your fixes come after that.
| Provider | What it states |
|---|---|
| Atlant Security | 5–7 days of testing, report within 14 days of the start |
| Invadel | About a week of testing for a small API, then reporting |
| Adversim | One to three weeks of active testing |
| Astra | 10–15 working days for the manual pentest |
| KirkpatrickPrice | Says the average test takes two to three weeks and a whole engagement two to three months, from kickoff through retest (source) |
These are stated periods, not booked dates. Ask for the final report date in writing.
Then add your own time. For the buyer in our example: testing, the report, 45 days of fixes, then the retest. If the retest window closes on day 30, the last step never happens. Check that deadline before anything else.
Will your auditor or customer accept an API pentest report?
They decide. The provider doesn't, and we don't. Ask them before you book.
Three questions cover most of it:
- Do you need a report on the API alone, or is API coverage inside a wider test fine?
- Is AI-led or automated testing acceptable, or must a person do it?
- Do you need proof the fixes were retested?
Here's a real example of why to ask. Cobalt's documentation describes two pentest types. An Agile pentest comes with an automated report "intended for internal use." A Comprehensive pentest is the one meant for an audit or a customer. Buy the wrong type and you have a report designed for internal use.
When you review a sample report, look for four things: what was tested and what wasn't, the exact request and response behind each finding, a fix your developers can act on, and the retest result for each finding.
Providers list the standards they say their reports map to. Those are their claims. Our questions for your report recipient will get you the real answer.
The API brief to send every provider
Send every provider the same brief. A scope brief asks each supplier the same question, so their answers line up and you can compare them.
Copy this, fill in the brackets, and send it to two or three providers. Or send it to the provider you already have.
API pentest brief
Why we need this. [Customer request / audit / launch / other]. The report goes to [who]. They need [what they asked for].
What to test. [Number] APIs. Type: [REST / GraphQL / gRPC / SOAP]. Size: [number] endpoints, counting each endpoint URL once and ignoring specific parameters and HTTP methods, or [number] GraphQL queries and mutations. Versions in scope: [list]. Docs attached: [OpenAPI / Postman / schema / none].
App overlap. [We have / don't have] a web or mobile app test that includes this API. Please tell us what would be tested twice.
Roles and tenants. Roles: [list]. Tenants: [yes / no]. We'll provide two test accounts per role [in each of two test tenants].
What matters most. [Payments / exports / invites / approvals / other]. What each role should and shouldn't be able to do: [attach rules].
Limits. Environment: [staging / production]. Hours: [window]. Request limit: [number]. Off limits: [list].
Dates. We need the report by [date]. Our fixes will be ready by [date]. We need the retest done by [date].
Please reply with:
- Is our API in scope by name, and how did you count it?
- Which roles and tenants will you test?
- Who does the testing, and how much is automated?
- The fixed price in writing, the billing currency, and what would raise it.
- How many retests, which findings they cover, and the deadline to ask.
- The date we get the final report.
- What is out of scope.
This brief is for pricing only. It is not permission to test. We will sign a separate written authorization that names the exact targets and activities.
That last line matters. A brief helps you buy. It does not authorize anyone to touch your systems.
If your fixes will take a while, add this one question:
"Can you retest [number] days after the findings are reported? Please confirm the deadline and any cost in writing."
Not sure what to put in the brackets? Find My PenTest Match has a section just for APIs. It walks you through what to settle first and gives you a free scope checklist to copy or print. It doesn't ask for your contact details.
Short answers
Is API pentesting priced per endpoint?
Not in the prices we found. Endpoint count sets the size tier. Invadel's pricing page says so directly, and Atlant Security prices one API "up to 50 endpoints" at one starting price.
Do providers test GraphQL and gRPC?
Many do, but check by name. Atlant Security lists both. Adversim, Cobalt, Invadel and NetSPI list GraphQL. For GraphQL, give the number of queries and mutations, not the number of URLs.
Is the retest free?
Often, with limits. Atlant Security and Invadel include a free retest. BreachLock's Extended package includes two. Astra includes two re-scans but only if you ask within 30 days. Always ask for the deadline.
Do I need a provider near me?
Usually not. API testing is done remotely. Ask where the testers work if your contracts restrict that. Adversim states its testing is done by a U.S.-based practitioner.
I'm looking for an API pentesting course, not a service. Where should I go?
This page is for buying a test. To learn the craft, start with OWASP's API Security project and PortSwigger's free Web Security Academy.
Sources and how we checked
We read each provider's own published pages on October 9, 2026, and applied their terms to the made-up buyer above. We did not buy these services, test their quality or confirm any provider's credentials. The PenTest Index does not perform or authorize penetration testing. Read more in our methodology and how we make money.
| Provider | Pages read | Checked |
|---|---|---|
| Adversim | API penetration testing | October 9, 2026 |
| Astra | Pricing; rescan rules | October 9, 2026 |
| Atlant Security | API pentest | October 9, 2026 |
| BreachLock | Packages | October 9, 2026 |
| Cobalt | API pentest; scoping rules; retest rules; glossary; API method | October 9, 2026 |
| Invadel | API pricing | October 9, 2026 |
| KirkpatrickPrice | API penetration testing | October 9, 2026 |
| NetSPI | API penetration testing | October 9, 2026 |
| Pentest-Tools.com | Managed web app testing | October 9, 2026 |
| Synack | Pricing | October 9, 2026 |
| OWASP | API Security Top 10, 2023 | October 9, 2026 |
Provider terms change. If you spot something out of date, the offer's own page is the final word.