API Penetration Testing Quote, Priced per Endpoint
Operator prices agentic API penetration testing per protected API, based on how many endpoints it exposes. Fill in your APIs, endpoint counts, and scan cadence below to build a live, indicative estimate before you talk to a specialist. Development, staging, and production environments all cost the same, so you can test everywhere your API runs.
How the price is built
The calculator below runs the same inputs through the pricing engine used to scope real quotes. Here is what each input does to the number:
| Input | How it affects your price |
|---|---|
| Number of APIs (1 to 20) | Each protected API is priced on its own, and the totals are added together. |
| Endpoints per API | Priced on a decreasing per-endpoint curve, so the marginal cost per endpoint falls as a single API grows larger. |
| Scans per month | Four scans per month are included in the base price. Choosing 8, 12, 20, or 30 scans raises the price for deeper, more continuous coverage. |
| Environment (dev, staging, production) | Recorded for scoping only. It does not change the price. |
This is an indicative estimate, not a list price. Final scope and price are confirmed when a specialist reviews your submission. See how tiers are structured.
Frequently asked questions
Is the price shown here binding?
No. The number the calculator shows is an indicative estimate, not a list price or a binding quote. Final scope and price are confirmed after a specialist reviews what you submit.
What counts as an endpoint?
An endpoint is a distinct operation your API exposes, generally a unique path and HTTP method combination. Count the operations you want tested, not the number of hosts, services, or client apps that call them.
Do development, staging, and production environments cost differently?
No. Operator is priced by endpoint volume, not environment. Development, staging, and production APIs cost the same, so you can test everywhere your API runs.
What is included in a quoted engagement?
A quoted engagement runs autonomous exploitation of your API with a runnable proof of concept for every finding, plus request and response evidence and a CVSS v3.1 vector. See the pricing page for the full feature breakdown by tier.
How long does a scan take?
Scan time depends on how many APIs and endpoints you include and how many scans per month you choose. Scans run autonomously in the background and do not require you to block off time; exact timing is confirmed when your engagement is scoped.