---
name: api-abuse-and-misuse
description: Review APIs for broken object authorization, excessive data, unsafe methods, rate-limit gaps, and abuse paths.
---

# API Abuse and Misuse

Trace every sensitive endpoint from request to authorization, query, mutation, and response. Check BOLA/IDOR, mass assignment, over-broad selects, enumeration, pagination abuse, replay, missing idempotency, rate limits, quota bypass, unsafe webhooks, CORS, error leakage, and privilege escalation. Ensure controls are enforced server-side and test negative cases for another user, tenant, role, and unauthenticated caller.
