Skip to content
mcp/skillhub

Zap MCP Server

by dtkmnio.github.dtkmn/mcp-zap-serverv0.15.0

Self-hosted OWASP ZAP integration with guided security scans, findings summaries and report generation.

67Dockerremoteofficial registry

context tax

queued

security

queued

cold start

queued

freshness

Active2d ago

Install Zap MCP server

No published package or hosted endpoint yet — see the repository README for build-from-source instructions.

Configuration

VariableRequiredSecretDescription
ZAP_API_URL——Hostname or URL of a separately running ZAP daemon reachable from this container.
ZAP_API_PORT——ZAP API port.
ZAP_API_KEYyesyesAPI key configured on the ZAP daemon.
MCP_API_KEYyesyesAPI key clients must send as X-API-Key.
MCP_SERVER_TOOLS_SURFACE——Tool surface to expose. Use guided for the safer default workflow, including report readback. Use expert only when clients need raw ZAP tools outside the guided surface.
MCP_SECURITY_MODE——
MCP_SECURITY_ENABLED——
MCP_SECURITY_ALLOW_PLACEHOLDER_API_KEY——

Freshness

Active — last maintenance signal 2d ago. The newest of the signals below sets the band.

  1. Last commit (default branch)

    2026-10-08 · 2d ago · GitHub

  2. Latest release

    2026-10-08 · 2d ago · GitHub · v0.15.0

  3. Package published

    no data · npm/PyPI

  4. Registry entry updated

    2026-10-08 · 2d ago · official registry · v0.15.0

FAQ

›Does Zap require an API key?

Yes. It expects ZAP_API_KEY, MCP_API_KEY, of which 2 are secrets.

›Can I use Zap as a remote (hosted) MCP server?

Yes. It is a hosted MCP server; connect to its URL with any client that supports remote MCP.

›Is Zap in the official MCP registry?

Yes, as io.github.dtkmn/mcp-zap-server.

Alternatives to Zap

Other security MCP servers.

View all