Skip to content
Verified official

MCP ZAP Server MCP

v0.11.0

io.github.dtkmn/mcp-zap-server

Safe, self-hosted OWASP ZAP operator for guided AI security scans and reports.

transport:stdio runtime:oci

Target client

run in your project directory

Held in this page only — never stored, logged, or sent anywhere but back to your screen.

claude mcp add mcp-zap-server -e ZAP_API_URL=<ZAP_API_URL> -e ZAP_API_PORT=<ZAP_API_PORT> -e ZAP_API_KEY=<ZAP_API_KEY> -e MCP_API_KEY=<MCP_API_KEY> -e MCP_SERVER_TOOLS_SURFACE=<MCP_SERVER_TOOLS_SURFACE> -e MCP_SECURITY_MODE=<MCP_SECURITY_MODE> -e MCP_SECURITY_ENABLED=<MCP_SECURITY_ENABLED> -e MCP_SECURITY_ALLOW_PLACEHOLDER_API_KEY=<MCP_SECURITY_ALLOW_PLACEHOLDER_API_KEY> -- docker run -i --rm ghcr.io/dtkmn/mcp-zap-server:v0.11.0

Adds it for this project only. Append --scope user to make it available everywhere. Claude Code docs

This listing does not declare its tools. Connect the server and your client will discover them on the handshake.