HomeSecurity › MCP ZAP Server

MCP ZAP Server

Safe, self-hosted OWASP ZAP operator for guided AI security scans and reports.

Java Local
★ 66 stars Last pushed 2026-09-22 License: Apache-2.0

Topics: Security

Connect

Review any command before running it. Package names and URLs come from the server's own registry entry.

Package (oci)

Package: oci ghcr.io/dtkmn/mcp-zap-server:v0.11.0

  • ZAP_API_URL — Hostname or URL of a separately running OWASP ZAP daemon reachable from this container.
  • ZAP_API_PORT — OWASP ZAP API port.
  • ZAP_API_KEY required secret — API key configured on the OWASP ZAP daemon.
  • MCP_API_KEY required secret — API key clients must send as X-API-Key.
  • MCP_SERVER_TOOLS_SURFACE — Tool surface to expose. Use guided for the safer default workflow, including report readback. Use expert only when clients need raw ZAP tools outside the guided surface.
  • MCP_SECURITY_MODE
  • MCP_SECURITY_ENABLED
  • MCP_SECURITY_ALLOW_PLACEHOLDER_API_KEY

This server takes extra arguments — see its repository.

Package (oci)

Package: oci docker.io/dtkmn/mcp-zap-server:v0.11.0

  • ZAP_API_URL — Hostname or URL of a separately running OWASP ZAP daemon reachable from this container.
  • ZAP_API_PORT — OWASP ZAP API port.
  • ZAP_API_KEY required secret — API key configured on the OWASP ZAP daemon.
  • MCP_API_KEY required secret — API key clients must send as X-API-Key.
  • MCP_SERVER_TOOLS_SURFACE — Tool surface to expose. Use guided for the safer default workflow, including report readback. Use expert only when clients need raw ZAP tools outside the guided surface.
  • MCP_SECURITY_MODE
  • MCP_SECURITY_ENABLED
  • MCP_SECURITY_ALLOW_PLACEHOLDER_API_KEY

This server takes extra arguments — see its repository.

Related servers

Listed in punkpeye/awesome-mcp-servers (MIT)

Data from the Official MCP Registry