Services

I find the access-control bugs that ship to prod

alg=none, HS/RS key confusion, weak secrets, broken RBAC — and the bug pattern-matching scanners miss: IDOR/BOLA, where an authenticated user reaches another user’s data. I review your authentication and authorization surface, hand you a report with proof-of-concept and remediation, and re-test it after you patch. Fixed price, fixed timeline.

Spot Check

$150 fixed

One flow, fast read

A single auth flow or endpoint checked against the five JWT classes, claim hygiene, and the most likely IDOR on that route. Proof of value, fast.

  • 1-page findings report with severities
  • Concrete remediation for each issue
  • 48–72h turnaround
Book & pay → questions first?
Most popular

Auth & Access Review

$600 fixed

Authentication + authorization

The full surface: JWT, sessions, RBAC and OAuth/OIDC config — plus an IDOR/BOLA pass over your Next.js route handlers and Server Actions, where one user reaches another user’s data.

  • Report: severities, PoCs, remediation, SARIF
  • One free re-test after you patch
  • 3–5 day turnaround
Book & pay → questions first?

Review + Fix

$1200 fixed

I find it and I patch it

Everything in the Auth & Access Review, then I implement the hardening myself and hand you a reviewed pull request ready to merge.

  • Everything in the Review
  • Merged hardening PR against your repo
  • Re-test included
Book & pay → questions first?

Prices in USD, paid via PayPal. Remote, worldwide. Engagements run under a written scope and authorization — I only test systems you own or are authorized to test.

How it works

Three steps, no surprises

01

Scope in one call

A 15-minute call (or async) to confirm the surface. Fixed price, fixed timeline — no hourly meter, no scope creep.

02

I break it

My own tooling plus manual review: jwt-scan over your tokens, authzscan over your route handlers, and a human read of the auth and access-control logic.

03

You get the fix

A clear report with severities, proof-of-concept and remediation (Markdown + SARIF for code scanning). One free re-test after you patch so you know it is closed.

Why me

I build the tools I review with

I don't just run a scanner — I wrote two. authzscan reasons about IDOR/BOLA in Next.js code the way pattern-matching SAST can't, and is measured against a seeded benchmark with recall and precision gates. The detection logic comes from reproducing the bugs from scratch. The same rigor goes into your review.

Book a review — or ask first

Tell me about your app and I'll reply within a day. Want a free read? Pick Free health check below and send me a token or a public repo. Ready to go? Use the PayPal buttons above to book instantly.