mcp-zap-server

mcp-zap-server

MCP.Pizza Chef: dtkmn

This server lets your AI assistant perform safe, guided web security scans using OWASP ZAP technology. You can scan websites for vulnerabilities, get detailed findings and reports, and keep production guardrails in place. It works with apps like Cursor and a web UI, requires no coding, and installs easily with Docker. You host it yourself, keeping control and security tight while automating web security checks.

Other
Web/Research

Use This MCP server To

Run guided web security scans on my websites Generate detailed security scan reports Control scan settings with safe defaults Review scan history and findings Deploy security scanning on my own server Set up production guardrails for web security scans Integrate security scans into AI workflows

README

MCP ZAP Server logo

MCP ZAP Server

Give AI agents a safe, self-hosted OWASP ZAP operator for guided web security scans, findings, reports, and production guardrails.

GitHub stars GitHub forks GitHub tag GitHub license

Note This project is not affiliated with or endorsed by OWASP or the OWASP ZAP project. It is an independent implementation.

mcp-zap-server exposes OWASP ZAP through MCP over streamable HTTP so agentic tools can run operator-controlled security workflows without brittle glue scripts or unsafe scanner access.

Use it when you want:

  • safe agentic scanning with guided defaults for spider, active scan, passive scan, API imports, findings, and reports
  • operator control through API-key or JWT auth, tool scopes, runtime policy bundles, rate limits, and audit events
  • self-hosted deployment with Docker Compose for local adoption and Helm for Kubernetes
  • expert ZAP access when you intentionally need lower-level ZAP context, user, scan, and report controls

Full documentation: danieltse.org/mcp-zap-server

Watch the demo: browser demo or YouTube

MCP ZAP Server demo video thumbnail

Quick Start

Prerequisites:

  • Docker 20.10+
  • Docker Compose v2 (docker compose)
  • an MCP-capable client, or the bundled Open WebUI client
git clone https://github.com/dtkmn/mcp-zap-server.git
cd mcp-zap-server

./bin/bootstrap-local.sh
./dev.sh
./bin/self-serve-doctor.sh

Those scripts are the supported local happy path, not hidden magic:

  • bootstrap-local.sh creates .env, generates local API keys, and prepares the ZAP workspace.
  • dev.sh starts the Docker Compose stack with the faster JVM image.
  • self-serve-doctor.sh checks Docker, auth, MCP initialize, tools/list, guided tools, and a harmless tool call.

mcp-zap-server FAQ

Can I use this to perform guided web security scans?
Yes — it lets AI agents safely run guided scans like spider, active, and passive scans with controlled settings.
Can I use this to generate security scan reports?
Yes — it produces findings and detailed reports from scans for review.
Which apps can I use this with?
It works with MCP-capable clients such as Cursor and the bundled Open WebUI client.
Do I need an API key or account?
Yes — it uses API key or JWT authentication to securely control access.
How hard is it to set up?
Setup is one-click with Docker Compose or Helm charts; no coding needed.
Can I run this on my own machine?
Yes — it is self-hosted using Docker or Kubernetes for local or cloud deployment.