TECHNOLOGIES: MOLLIE

Mollie Integration Penetration Testing

Mollie’s webhook sends only a payment ID, never a status, so your server’s own logic decides what happens next. We test how that logic verifies each update and handles a repeat call. CREST-certified testers, fixed price from £3,120 for a 2-day single-integration scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
Mollie Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
Tokens

Mollie’s advanced access tokens are scoped to specific permissions across payments, refunds and webhooks, and only an account Admin can create one. We test which tokens exist, what permissions each one actually holds, and whether that still matches what the integration does.

Why Mollie findings sit in your tokens and your webhook handler, not the API

Mollie offers four ways to authenticate: a standard API key tied to a single payment profile, an advanced access token that can be scoped to specific permissions and, optionally, a specific profile or mode, an OAuth app access token for acting on behalf of a connected merchant, and Basic Auth using the OAuth client ID and secret to generate or revoke tokens. Only a user with the Admin role can create an advanced access token, so we test whether that restriction is enforced consistently and whether any token in use holds more permission than the integration needs.

Mollie’s webhook design deliberately sends only the ID of the updated object, for example a payment ID, never its new status, precisely so a forged call to your webhook URL cannot mark an order as paid on its own. That means the security of the flow depends entirely on your endpoint actually calling back into the Mollie API to fetch the real status before it acts. We test whether it does that every time, and how it behaves when Mollie retries the same call, which it does up to ten times over 26 hours if your endpoint does not return a 200.

Where a business is itself a platform using Mollie Connect, an OAuth app access token lets it act on behalf of connected merchant accounts once they have granted consent. We test what scope was actually granted against what the integration uses, how a connected account’s tokens are stored, and whether a revoked or expired authorisation is still honoured anywhere in the code.

SCOPE

What we pen test on a Mollie integration

ML-01

API Key and Advanced Access Token Scope

Every credential type carries a different access level, from a full-profile API key to a permission-scoped advanced access token. We test which credentials exist in the integration and whether each one holds more access than the calls it actually makes.

ML-02

Admin-Only Token Creation

Advanced access tokens are meant to be creatable only by an account Admin. We test whether that restriction holds in practice, including through any internal tooling built around the Mollie dashboard or API.

ML-03

OAuth App Access Tokens and Mollie Connect

Platforms using Mollie Connect hold OAuth tokens that act on behalf of connected merchants. We test the scope granted during consent against what the integration actually calls, and how connected-account tokens are stored and refreshed.

ML-04

Webhook Payload and Callback Verification

A Mollie webhook call carries only an object ID, never a status, by design. We test whether the receiving endpoint always calls back into the API for the current status before acting, rather than trusting anything in the request itself.

ML-05

Webhook Retry and Duplicate Processing

Mollie retries an unacknowledged webhook call up to ten times over 26 hours. We test whether a repeated call for the same object can trigger the order, fulfilment or notification logic more than once.

ML-06

Payment Status Trust on Redirect

A customer can be redirected back to your site before a webhook has arrived. We test whether that redirect alone is ever treated as proof of payment instead of the status your server fetched from the API.

ML-07

Refund and Chargeback Handling

Refunds and chargebacks reach your system through the same webhook pattern as payments. We test whether your order and ledger logic reconciles these events correctly, including partial refunds.

ML-08

Subscription and Recurring Payment Webhooks

A subscription’s webhook URL is called for every payment it generates. We test whether a failed or cancelled recurring payment is handled the same way as a first payment, rather than assumed to always succeed.

ML-09

Test Mode and Live Mode Separation

Mollie keeps test and live API keys and a testmode request parameter separate by design. We test for a code path where a test-mode result, key or webhook could be accepted into live order processing.

ML-10

Basic Auth Credentials for OAuth Token Management

The OAuth client ID and secret used to generate and revoke tokens are sent as Basic Auth credentials. We test how and where your integration stores them and who or what can reach that store.

OUR PROCESS

Mollie Integration Penetration Testing: From Scope to Attestation

01

Scope and Access

We agree the exact integration boundary and get test-mode API keys or a sandboxed environment, never live payment data unless you ask for it.

02

Integration Testing

CREST-certified testers work through token scope, webhook handling and payment-status logic against the rows above.

03

Findings and Retest

Findings are written against the specific credential, endpoint or code path involved, with a free retest once you have fixed them.

04

Report and Sign-off

You get a report ready to hand to an auditor or payment partner, plus a fixed retest window until every finding is closed.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST Mollie pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent Mollie Integration Penetration Testing Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£3,120–£4,590
2 to 3 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£7,330–£11,170
5 to 7 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From Mollie Integration Penetration Testing

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need to test our Mollie integration?

Test-mode API keys or advanced access tokens scoped the same way as your live ones, plus access to the code or environment handling webhooks. We do not need your live API key or production payment data to complete most of the scope.

Does testing touch live payment data?

Not by default. We work in Mollie’s test mode wherever the integration allows it, and only test against live mode if you specifically ask for that and agree the safeguards during scoping.

Do you test Mollie’s own platform or our integration?

Your integration: the tokens you issue, the webhook handler you built, and the logic that decides what a payment update means. Mollie’s core payment processing infrastructure is not something we test.

Is card data handling in scope?

If you use Mollie’s hosted checkout or Components, Mollie holds the PCI Level 1 certification for the card data itself, so that storage is out of scope. Your own checkout logic, order handling and webhook processing around it are in scope.

How long does a Mollie integration test take?

A single integration is typically a 2-day scope. A platform using Mollie Connect with OAuth and multiple connected merchant accounts usually needs more time, which we confirm during scoping.

Does Mollie have a security testing or disclosure policy?

Mollie publishes a Responsible Disclosure Policy for reporting vulnerabilities in the Mollie platform itself, with reports sent to its security team by email. For testing your own integration, we confirm current terms with you and, where relevant, with Mollie during scoping.

Can you test our Mollie Connect OAuth flow?

Yes, if your business is a platform holding OAuth app access tokens for connected merchants, the consent flow, token storage and scope enforcement are all in scope.

Do you need our production Mollie account?

No. A test-mode account with the same profile and permission structure as production is enough for us to test the logic that matters.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your Mollie integration

Mollie’s webhook sends only a payment ID, never a status, so your server’s own logic decides what happens next. We test how that logic verifies each update and handles a repeat call. CREST-certified testers, fixed price from £3,120 for a 2-day single-integration scope, quoted within 24 hours.