ZAP

Package

Dynamic web application security testing with APIs and local MCP tools

Price
Free, open source
Access
Local use; configurable API/MCP key

About

Open-source web security proxy and dynamic application scanner, automated through its API, daemon mode or Automation Framework. A first-party add-on exposes local MCP tools. Configure sessions for authenticated testing and restrict scans to your authorized target environments.

What you can do with it

  • Run dynamic security checks against a staging web application
  • Inspect proxied requests and alerts through the ZAP API
  • Automate scans from CI or connect an agent to the localhost MCP add-on

Get started

  1. Install ZAP and configure the target application and authentication
  2. Use its Automation Framework, API or daemon for repeatable scans
  3. Install the MCP Integration add-on for trusted localhost agent access

Details

Hosting
Runs locally, Self-hosted
Available in
Worldwide
MCP server
Local

Tasks

Last checked on .