ZAP
PackageDynamic web application security testing with APIs and local MCP tools
- Price
- Free, open source
- Access
- Local use; configurable API/MCP key
About
Open-source web security proxy and dynamic application scanner, automated through its API, daemon mode or Automation Framework. A first-party add-on exposes local MCP tools. Configure sessions for authenticated testing and restrict scans to your authorized target environments.
What you can do with it
- Run dynamic security checks against a staging web application
- Inspect proxied requests and alerts through the ZAP API
- Automate scans from CI or connect an agent to the localhost MCP add-on
Get started
- Install ZAP and configure the target application and authentication
- Use its Automation Framework, API or daemon for repeatable scans
- Install the MCP Integration add-on for trusted localhost agent access
Details
- Hosting
- Runs locally, Self-hosted
- Available in
- Worldwide
- MCP server
- Local