Trava

Solutions

+

−

Advisory Solutions

Compliance Readiness

Data Privacy Compliance

Internal Audit

vCISO

AI Risk Management Services

Cybersecurity Risk Assessment Service

Cyber Due Diligence

Documentation Support

Policy & Controls Implementation

Tabletop Exercises

Cybersecurity Solutions

Penetration Testing

Vulnerability Assessment Service

Social Engineering

Red Teaming

Managed Programs

Managed Compliance Program

Managed Pen Test Program

Managed Security Training Program

Managed VM Program

Managed SOC Program

Blog

Building with AI: What It Means for Your APIs and Your Pen Test

AI-assisted development grows your API surface faster than anyone designed it. Here's how that changes your pen test scope and how to be ready for testing.

Published October 5, 2026

AI-assisted development grows your API surface. Here's what that means for your next pen test, and how to be ready for testing. This post is a companion to our Web Application Penetration Testing service.

What AI-assisted development changes

AI coding tools let small teams ship in weeks what used to take months. The catch is that more code gets written, and less of it gets a careful human review. Knowing what you shipped matters as much as how fast you shipped it.

What you gain: faster releases, smaller teams shipping more, low-cost prototyping.

What to plan for: more endpoints than anyone designed, security choices made by the tool, routes that outlive their features, and more third-party dependencies.

45% of AI coding tasks introduced a security vulnerability in Veracode's 2025 GenAI Code Security Report, even when the code worked. When developers don't state security requirements, the model decides for them. AI builds fast. People still decide what ships.

Source: Veracode, 2025 GenAI Code Security Report

Why your API surface grew

  • Features sit on many endpoints. Checkout alone can run on a dozen.
  • AI tools build full sets by default. A feature request often produces create, read, update, and delete endpoints, used or not.
  • Code is added faster than it's removed. Old routes stay live after features change.
  • Direct-to-backend calls count. Backend-as-a-service tables and browser-called APIs are part of your surface.

Why that changes your pen test scope

Your app may look the same to users as last year while running several times the endpoints. A pen test is scoped to what's reachable, not what's visible.

  • Each endpoint is tested per role. 15 endpoints across 3 roles is 45 access checks.
  • Authorization needs a human tester. Checking whether one user can reach another's data means acting as each user.
  • Live means in scope. Unused endpoints can still be reached.

Your count may be bigger than your surface. Many teams count each method and path separately, and many routes perform the same read. A first count in the hundreds often drops substantially once reviewed.

While you build

  • Establish design patterns around API endpoints. Teach AI how you decide whether something is worth one endpoint or being split into multiple.
  • Keep a spec. Have your AI tool maintain an OpenAPI spec as it builds.
  • Remove what you replace. Delete routes when features change.
  • Check authorization on the server. Hiding a button isn't protection.
  • Return only what's needed, and keep API keys out of the browser.
  • Review before you ship, especially code touching login, payments, or data changes.

Before you test

Prioritize by what endpoints do:

  • First: endpoints that create, update, delete data, handle uploads, or manage identity and access, or return sensitive data
  • Next: payments and core business logic
  • Later: read-only routes and data pulled from other sources

Refine your scope. Every endpoint you retire is one you don't pay to test. Count paths, not method plus path; retire unused and duplicate routes; share your OpenAPI spec or Postman collection; provide two (2) test accounts per role; and decide whether internal and admin APIs belong in this round.

First test for your app? A vulnerability assessment can clear common issues first, so a later pen test goes deeper.

Questions to ask any provider

Each question below is paired with the answer that should give you pause.

  • Ask: How did you arrive at the endpoint count in this quote?
    Listen for: They used your number without asking what it includes.
  • Ask: How will you test that one user can't access another user's data?
    Listen for: They only need one test account.
  • Ask: How will you find endpoints that aren't in our documentation?
    Listen for: They'll test only what's listed.
  • Ask: What do your automated tools do, and what do testers do by hand?
    Listen for: They can't say where the tools stop.
  • Ask: How will you test our app's workflows, like checkout or account changes?
    Listen for: A generic answer; workflow flaws can't be scanned.
  • Ask: What would change the price once testing starts?
    Listen for: No clear answer on how new endpoints are handled.
  • Ask: Can we see a redacted sample report?
    Listen for: Findings with no steps to reproduce or business context.

How Trava can help

AI helps you build fast. Our practitioners help you see what you actually shipped, and test it the way an attacker would. Whether this is your app's first test or its fiftieth release, we'll meet you where you are:

Book a scoping call. We'll review your endpoint count with you and define scope, timeline, and investment together.