TECHNOLOGIES: SQUARE

Square Integration Penetration Testing

A Square personal access token reaches everything in the account; an OAuth token reaches only what the merchant granted. We test which token your integration holds and what a leaked one exposes. CREST-certified testers, fixed price from £3,120 for a 2-day single-integration scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
Square Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
Scopes

Square scopes decide what a connected merchant’s OAuth token can do. A personal access token skips that check entirely and reaches everything in the account.

Why the access token matters as much as the code that calls it

Square gives an application two very different credentials. A personal access token grants unrestricted access to every resource in a Square account, useful for a single-account integration but never intended for an app that serves other people’s merchants. An OAuth access token is scoped to whatever permissions the merchant granted when they connected the app and expires after 30 days, refreshed rather than replaced with something broader. An integration that reaches for a personal access token because it is already sitting in the dashboard has quietly removed the entire permission boundary.

The payment and order logic carries its own risk. A Square order’s line items can reference a catalogue object, whose price Square holds, or be built ad hoc with a base_price_money value your own code supplies, and an integration that fills that field from whatever the checkout page sent has not fixed anything by routing the charge through the Orders API first. The same scepticism applies to webhooks: every notification carries an x-square-hmacsha256-signature header, an HMAC-SHA-256 signature built from the signature key, the notification URL and the raw body, and a listener that never checks it will act on whatever is posted to it.

The rest sits in configuration: whether sandbox credentials can reach production, whether one connected merchant’s token can be used to read another merchant’s data in a multi-merchant app, and who inside your application can authorise a refund. None of this touches Square’s own infrastructure. It is entirely about the access, the amounts and the signatures your team’s integration decided to trust.

SCOPE

What we pen test on a Square integration

SQ-01

OAuth scope enforcement

Whether your backend checks that a call is covered by a scope the merchant actually granted, such as PAYMENTS_WRITE, ORDERS_WRITE or MERCHANT_PROFILE_READ, rather than assuming a connected merchant carries every scope the app originally requested.

SQ-02

Personal access token vs OAuth token usage

Whether any part of the integration authenticates with your own personal access token, which reaches every resource in your Square account, in a path that should instead use a merchant-scoped OAuth token, and what a single leaked personal token would expose across every merchant the app serves.

SQ-03

Token storage, rotation and refresh

How OAuth access tokens and refresh tokens are stored, whether an access token is refreshed before its 30-day expiry rather than forcing a merchant back through authorisation, and, if your app uses the PKCE flow, whether its single-use refresh token is replaced correctly rather than reused a second time.

SQ-04

Order and payment amount integrity

Whether ad hoc line items in an order are priced from your own catalogue or product data rather than a value the checkout page sent, and whether the amount passed to CreatePayment always comes from an order your backend built rather than a total computed in the browser.

SQ-05

Payment and order idempotency

Whether idempotency keys on CreatePayment, CreateOrder and RefundPayment are generated fresh per user action rather than reused across retries, and what your integration does with the conflict Square returns if a retried request reuses a key with a different amount.

SQ-06

Web Payments SDK token handling

Whether card details are ever captured outside the SDK’s own Card element, whether the token from card.tokenize() reaches your server over a path that could be substituted, and whether the verificationDetails intent your integration sends, CHARGE, STORE or CHARGE_AND_STORE, matches what the resulting CreatePayment call actually does.

SQ-07

Webhook signature verification

Whether your listener recomputes the HMAC-SHA-256 signature from your subscription’s signature key, notification URL and the raw request body and compares it to the x-square-hmacsha256-signature header, rather than trusting the event_type or payment ID in whatever gets posted to the endpoint.

SQ-08

Merchant account separation

In an app that connects multiple Square merchants, whether a request authenticated as one merchant’s session can be made to act using a different merchant’s stored OAuth token, and whether merchant_id is checked on every call rather than assumed from the session alone.

SQ-09

Refund authorisation and limits

Who in your application can trigger a RefundPayment call and against which payment_id, whether that check happens before the request reaches Square, and how your integration handles a refund that is only partially possible because earlier refunds already reduced what remains.

SQ-10

Sandbox and production credential separation

Whether sandbox access tokens, applications or test values can reach a production endpoint or vice versa, and what your integration does if it receives a request or webhook event carrying the wrong environment’s identifiers.

OUR PROCESS

Square Integration Penetration Testing: From Scope to Attestation

01

Scope the integration

We list every Square touchpoint in your application: OAuth connection, orders, payments, webhooks and refunds, and confirm which credentials are Sandbox, which are production, and how many merchants the app serves.

02

Test against the Sandbox first

OAuth, order, payment, webhook and refund logic is tested against your Square Sandbox test accounts and test values wherever the check allows; anything that genuinely needs live Square is agreed with you first and run read-only.

03

Exploit the business logic

CREST-certified testers chain findings across scopes, tokens, order amounts and webhook handling, covering forged signatures, amount tampering and token misuse rather than relying on scanner output alone.

04

Report and retest

Executive summary, technical report with CVSS scores and reproduction steps, a walkthrough call, free retest after remediation, and an attestation letter.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST Square pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent Square Integration Penetration Testing Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£3,120–£4,590
2 to 3 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£7,330–£11,170
5 to 7 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From Square Integration Penetration Testing

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need?

A Sandbox application (client ID and secret) and a Sandbox test account acting as the connected merchant. We do not need your live Square password or dashboard login, and only need scoped, read-only production access where a specific check requires it.

Does this touch live Square accounts or real transactions?

No, wherever the check allows. Square’s Sandbox mirrors the production API and lets us run orders, payments, refunds and webhook events against test values that are never charged. Anything that must run against a live Square account is agreed with you in advance and scoped tightly.

How long does a Square integration test take?

A single integration is a 2-day scope. Multiple connected merchants, custom Web Payments SDK flows, or a second payment provider running alongside Square add testing days, which we agree before the engagement starts.

We use Square’s hosted checkout, not a custom Web Payments SDK form. Is there still anything to test?

Yes. A hosted checkout reduces client-side risk, but order creation, the payment call, your webhook listener and your refund logic are still your code, and that is where testing time goes regardless of which component collects the card.

What is out of scope?

Square’s own infrastructure, authentication systems and payments platform. We test the integration your team built: your OAuth handling, order and payment logic, webhook endpoint and refund authorisation, never Square’s platform itself.

Does Square have a policy on this kind of testing?

Square provides a dedicated Sandbox that mirrors the production API specifically so integrations can be tested with values that are never charged, and account credentials from one environment cannot be used in the other. We test against your Sandbox credentials for exactly that reason, and confirm Square’s current developer terms during scoping for anything that has to run against a live account.

Do you test multi-merchant or marketplace apps that connect to many Square accounts?

Yes, and it is scoped as its own area. We test whether one merchant’s OAuth token, session or data can be reached from another connected merchant’s context, alongside the standard order, payment and webhook checks.

Our integration currently uses a personal access token instead of OAuth. Can you still test it?

Yes. We test whichever credential model is live today, and where a personal access token is being used for something OAuth was designed for, such as serving more than one merchant, that is exactly the kind of finding this test is built to catch.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your Square integration

A Square personal access token reaches everything in the account; an OAuth token reaches only what the merchant granted. We test which token your integration holds and what a leaked one exposes. CREST-certified testers, fixed price from £3,120 for a 2-day single-integration scope, quoted within 24 hours.