Authentication — Test API authentication mechanisms, token handling, session controls, and common implementation weaknesses.
Authorization — Assess object-level and function-level access controls and whether users can access data or actions beyond their permissions.
Data exposure — Identify excessive data returned by endpoints, sensitive information exposure, and insecure API responses.
Input validation — Assess how endpoints handle unexpected, malformed, or attacker-controlled input.
Rate limiting & abuse controls — Review protections against excessive requests and relevant API abuse scenarios.
Business logic — Test important workflows for authorization gaps, parameter manipulation, and unintended functionality.