Mollie Integration Penetration Testing
Mollie’s webhook sends only a payment ID, never a status, so your server’s own logic decides what happens next. We test how that logic verifies each update and handles a repeat call. CREST-certified testers, fixed price from £3,120 for a 2-day single-integration scope, quoted within 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
Mollie’s advanced access tokens are scoped to specific permissions across payments, refunds and webhooks, and only an account Admin can create one. We test which tokens exist, what permissions each one actually holds, and whether that still matches what the integration does.
Why Mollie findings sit in your tokens and your webhook handler, not the API
Mollie offers four ways to authenticate: a standard API key tied to a single payment profile, an advanced access token that can be scoped to specific permissions and, optionally, a specific profile or mode, an OAuth app access token for acting on behalf of a connected merchant, and Basic Auth using the OAuth client ID and secret to generate or revoke tokens. Only a user with the Admin role can create an advanced access token, so we test whether that restriction is enforced consistently and whether any token in use holds more permission than the integration needs.
Mollie’s webhook design deliberately sends only the ID of the updated object, for example a payment ID, never its new status, precisely so a forged call to your webhook URL cannot mark an order as paid on its own. That means the security of the flow depends entirely on your endpoint actually calling back into the Mollie API to fetch the real status before it acts. We test whether it does that every time, and how it behaves when Mollie retries the same call, which it does up to ten times over 26 hours if your endpoint does not return a 200.
Where a business is itself a platform using Mollie Connect, an OAuth app access token lets it act on behalf of connected merchant accounts once they have granted consent. We test what scope was actually granted against what the integration uses, how a connected account’s tokens are stored, and whether a revoked or expired authorisation is still honoured anywhere in the code.
SCOPE
What we pen test on a Mollie integration
API Key and Advanced Access Token Scope
Every credential type carries a different access level, from a full-profile API key to a permission-scoped advanced access token. We test which credentials exist in the integration and whether each one holds more access than the calls it actually makes.
Admin-Only Token Creation
Advanced access tokens are meant to be creatable only by an account Admin. We test whether that restriction holds in practice, including through any internal tooling built around the Mollie dashboard or API.
OAuth App Access Tokens and Mollie Connect
Platforms using Mollie Connect hold OAuth tokens that act on behalf of connected merchants. We test the scope granted during consent against what the integration actually calls, and how connected-account tokens are stored and refreshed.
Webhook Payload and Callback Verification
A Mollie webhook call carries only an object ID, never a status, by design. We test whether the receiving endpoint always calls back into the API for the current status before acting, rather than trusting anything in the request itself.
Webhook Retry and Duplicate Processing
Mollie retries an unacknowledged webhook call up to ten times over 26 hours. We test whether a repeated call for the same object can trigger the order, fulfilment or notification logic more than once.
Payment Status Trust on Redirect
A customer can be redirected back to your site before a webhook has arrived. We test whether that redirect alone is ever treated as proof of payment instead of the status your server fetched from the API.
Refund and Chargeback Handling
Refunds and chargebacks reach your system through the same webhook pattern as payments. We test whether your order and ledger logic reconciles these events correctly, including partial refunds.
Subscription and Recurring Payment Webhooks
A subscription’s webhook URL is called for every payment it generates. We test whether a failed or cancelled recurring payment is handled the same way as a first payment, rather than assumed to always succeed.
Test Mode and Live Mode Separation
Mollie keeps test and live API keys and a testmode request parameter separate by design. We test for a code path where a test-mode result, key or webhook could be accepted into live order processing.
Basic Auth Credentials for OAuth Token Management
The OAuth client ID and secret used to generate and revoke tokens are sent as Basic Auth credentials. We test how and where your integration stores them and who or what can reach that store.
OUR PROCESS
Mollie Integration Penetration Testing: From Scope to Attestation
Scope and Access
We agree the exact integration boundary and get test-mode API keys or a sandboxed environment, never live payment data unless you ask for it.
Integration Testing
CREST-certified testers work through token scope, webhook handling and payment-status logic against the rows above.
Findings and Retest
Findings are written against the specific credential, endpoint or code path involved, with a free retest once you have fixed them.
Report and Sign-off
You get a report ready to hand to an auditor or payment partner, plus a fixed retest window until every finding is closed.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST Mollie pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Mapped to Every Framework
Findings are written so your team can reference the report against each framework without translation work.
ISO 27001:2022
Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.
SOC 2 Type I & II
CC6 logical access, CC7 system operations, CC8 change management evidence.
PCI DSS
Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.
FCA SYSC
SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.
UK GDPR
Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.
Cyber Essentials Plus
Direct certification through our IASME body status, single-vendor delivery.
PRICING
Transparent Mollie Integration Penetration Testing Pricing
Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.
2 to 3 testing days
Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.
Get a fixed quote3 to 5 testing days
Multi-role SaaS, business application with payment integration. Around 8 to 12 working days from kickoff to report.
Get a fixed quote5 to 7 testing days
Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.
Get a fixed quoteSECTORS
Sectors We Test Mollie For
Sector-specific scoping for regulated UK organisations.
Fintech & FCA-Regulated
FCA SYSC, Open Banking FAPI 1.0, PSD2 SCA, payment-flow scrutiny, KYC/AML testing.
Fintech sector pageSaaS Companies
SOC 2 Type I & II evidence, multi-tenant boundaries, role escalation, customer-tenant isolation.
SaaS sector pageLaw Firms
SRA Cyber Standard, privileged data, conveyancing fraud defence, partner-tier procurement.
Law firm sector pageHealthcare
NHS DTAC, DSP Toolkit v6, UK GDPR Article 32, EHR systems, telehealth platforms.
Healthcare sector pageInsurance
FCA / PRA Operational Resilience, cyber underwriting, claims data, broker portals.
Insurance sector pagePublic Sector
CCS / G-Cloud framework, NCSC-aligned, citizen-facing services, PSN-compliance scrutiny.
Public sector pageWHY EJN LABS
What You Get From Mollie Integration Penetration Testing
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
What access do you need to test our Mollie integration?
Test-mode API keys or advanced access tokens scoped the same way as your live ones, plus access to the code or environment handling webhooks. We do not need your live API key or production payment data to complete most of the scope.
Does testing touch live payment data?
Not by default. We work in Mollie’s test mode wherever the integration allows it, and only test against live mode if you specifically ask for that and agree the safeguards during scoping.
Do you test Mollie’s own platform or our integration?
Your integration: the tokens you issue, the webhook handler you built, and the logic that decides what a payment update means. Mollie’s core payment processing infrastructure is not something we test.
Is card data handling in scope?
If you use Mollie’s hosted checkout or Components, Mollie holds the PCI Level 1 certification for the card data itself, so that storage is out of scope. Your own checkout logic, order handling and webhook processing around it are in scope.
How long does a Mollie integration test take?
A single integration is typically a 2-day scope. A platform using Mollie Connect with OAuth and multiple connected merchant accounts usually needs more time, which we confirm during scoping.
Does Mollie have a security testing or disclosure policy?
Mollie publishes a Responsible Disclosure Policy for reporting vulnerabilities in the Mollie platform itself, with reports sent to its security team by email. For testing your own integration, we confirm current terms with you and, where relevant, with Mollie during scoping.
Can you test our Mollie Connect OAuth flow?
Yes, if your business is a platform holding OAuth app access tokens for connected merchants, the consent flow, token storage and scope enforcement are all in scope.
Do you need our production Mollie account?
No. A test-mode account with the same profile and permission structure as production is enough for us to test the logic that matters.
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a fixed price for your Mollie integration
Mollie’s webhook sends only a payment ID, never a status, so your server’s own logic decides what happens next. We test how that logic verifies each update and handles a repeat call. CREST-certified testers, fixed price from £3,120 for a 2-day single-integration scope, quoted within 24 hours.



