REST API Penetration Testing Checklist Form
Use this form to document a REST API security assessment checklist, including scope, authentication context, test coverage, findings, and completion status.
API Scope and Authentication
API or Base URL / Environment
*
Authenticated Role or Test Account Context
*
Authentication Method
*
API Key
Bearer Token
OAuth
Session Cookie
None
Other
Checklist Coverage
Endpoint discovery and inventory
Checked
Not checked
Authentication bypass attempts
Checked
Not checked
Authorization and access control checks
Checked
Not checked
Input validation and injection testing
Checked
Not checked
Rate limiting and throttling checks
Checked
Not checked
Findings and Completion
Overall Test Result
*
Pass
Pass with Findings
Fail
Incomplete
Primary Severity / Risk Level
*
Please Select
Informational
Low
Medium
High
Critical
Notes / Evidence Summary
Completion / Verification Status
*
Complete
Needs Review
Verified
Not Verified
Submit
Should be Empty: