{"repo":"dtkmn/mcp-zap-server","free":true,"listed":false,"github":"https://github.com/dtkmn/mcp-zap-server","clone":"git clone https://github.com/dtkmn/mcp-zap-server.git","description":"Give AI agents a safe, self-hosted OWASP ZAP operator for guided web security scans, findings, reports, and production guardrails.","language":"Java","stars":63,"topics":["mcp","mcp-server","java","llm","owasp","spring-ai","spring-boot","zap","ai"],"license":"Apache-2.0","category":"mcp-servers","readme_excerpt":"MCP ZAP Server Give AI agents a safe, self-hosted OWASP ZAP operator for guided web security scans, findings, reports, and production guardrails. Note This project is not affiliated with or endorsed by OWASP or the OWASP ZAP project. It is an independent implementation. mcp-zap-server exposes OWASP ZAP through MCP over streamable HTTP so agentic tools can run operator-controlled security workflows without brittle glue scripts or unsafe scanner access. Use it when you want: - safe agentic scanning with guided defaults for spider, active scan, passive scan, API imports, findings, and reports - operator control through API-key or JWT auth, tool scopes, runtime policy bundles, rate limits, and audit events - self-hosted deployment with Docker Compose for local adoption and Helm for Kubernetes - expert ZAP access when you intentionally need lower-level ZAP context, user, scan, and report controls Full documentation: danieltse.org/mcp-zap-server Watch the demo: browser demo or YouTube Quick Start Prerequisites: - Docker 20.10+ - Docker Compose v2 ( docker compose ) - an MCP-capable client, or the bundled Open WebUI client Those scripts are the supported local happy path, not hidden magic: - bootstrap-local.sh creates .env , generates local API keys, and prepares the ZAP workspace. - dev.sh starts the Docker Compose stack with the faster JVM image. - self-serve-doctor.sh checks Docker, auth, MCP initialize, tools/list , guided tools, and a harmless tool call. The JVM image remains J","default_branch":null,"files":null,"tree":[],"storefront":"/r/dtkmn","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/dtkmn/mcp-zap-server/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}