OWASP ZAP Break API
The break API from OWASP ZAP — 11 operation(s) for break.
The break API from OWASP ZAP — 11 operation(s) for break.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/owasp-zap-break-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
title: ZAP Break API
description: The HTTP API for controlling and accessing ZAP.
contact:
name: ZAP User Group
url: https://groups.google.com/group/zaproxy-users
email: zaproxy-users@googlegroups.com
license:
name: Apache 2.0
url: https://www.apache.org/licenses/LICENSE-2.0.html
version: 2.16.1
servers:
- url: http://zap
description: The URL while proxying through ZAP.
- url: http://{address}:{port}
description: The URL of a Local Proxy of ZAP.
variables:
address:
description: The address ZAP is listening on.
default: 127.0.0.1
port:
description: The port ZAP is bound to.
default: '8080'
security:
- {}
- apiKeyHeader: []
- apiKeyQuery: []
tags:
- name: break
paths:
/JSON/break/action/addHttpBreakpoint/:
parameters:
- name: string
in: query
required: true
description: ''
schema:
type: string
- name: location
in: query
required: true
description: ''
schema:
type: string
- name: match
in: query
required: true
description: ''
schema:
type: string
- name: inverse
in: query
required: true
description: ''
schema:
type: string
- name: ignorecase
in: query
required: true
description: ''
schema:
type: string
get:
description: 'Adds a custom HTTP breakpoint. The string is the string to match. Location may be one of: url, request_header, request_body, response_header or response_body. Match may be: contains or regex. Inverse (match) may be true or false. Lastly, ignorecase (when matching the string) may be true or false.'
operationId: breakActionAddHttpBreakpoint
tags:
- break
responses:
default:
$ref: '#/components/responses/ErrorJson'
summary: Break action add http breakpoint
x-summary-source: derived
/JSON/break/action/break/:
parameters:
- name: type
in: query
required: true
description: ''
schema:
type: string
- name: state
in: query
required: true
description: ''
schema:
type: string
- name: scope
in: query
description: ''
schema:
type: string
get:
description: 'Controls the global break functionality. The type may be one of: http-all, http-request or http-response. The state may be true (for turning break on for the specified type) or false (for turning break off). Scope is not currently used.'
operationId: breakActionBreak
tags:
- break
responses:
default:
$ref: '#/components/responses/ErrorJson'
summary: Break action break
x-summary-source: derived
/JSON/break/action/continue/:
get:
description: Submits the currently intercepted message and unsets the global request/response breakpoints
operationId: breakActionContinue
tags:
- break
responses:
default:
$ref: '#/components/responses/ErrorJson'
summary: Break action continue
x-summary-source: derived
/JSON/break/action/drop/:
get:
description: Drops the currently intercepted message
operationId: breakActionDrop
tags:
- break
responses:
default:
$ref: '#/components/responses/ErrorJson'
summary: Break action drop
x-summary-source: derived
/JSON/break/action/removeHttpBreakpoint/:
parameters:
- name: string
in: query
required: true
description: ''
schema:
type: string
- name: location
in: query
required: true
description: ''
schema:
type: string
- name: match
in: query
required: true
description: ''
schema:
type: string
- name: inverse
in: query
required: true
description: ''
schema:
type: string
- name: ignorecase
in: query
required: true
description: ''
schema:
type: string
get:
description: Removes the specified breakpoint
operationId: breakActionRemoveHttpBreakpoint
tags:
- break
responses:
default:
$ref: '#/components/responses/ErrorJson'
summary: Break action remove http breakpoint
x-summary-source: derived
/JSON/break/action/setHttpMessage/:
parameters:
- name: httpHeader
in: query
required: true
description: ''
schema:
type: string
- name: httpBody
in: query
description: ''
schema:
type: string
get:
description: Overwrites the currently intercepted message with the data provided
operationId: breakActionSetHttpMessage
tags:
- break
responses:
default:
$ref: '#/components/responses/ErrorJson'
summary: Break action set http message
x-summary-source: derived
/JSON/break/action/step/:
get:
description: Submits the currently intercepted message, the next request or response will automatically be intercepted
operationId: breakActionStep
tags:
- break
responses:
default:
$ref: '#/components/responses/ErrorJson'
summary: Break action step
x-summary-source: derived
/JSON/break/view/httpMessage/:
get:
description: Returns the HTTP message currently intercepted (if any)
operationId: breakViewHttpMessage
tags:
- break
responses:
default:
$ref: '#/components/responses/ErrorJson'
summary: Break view http message
x-summary-source: derived
/JSON/break/view/isBreakAll/:
get:
description: Returns True if ZAP will break on both requests and responses
operationId: breakViewIsBreakAll
tags:
- break
responses:
default:
$ref: '#/components/responses/ErrorJson'
summary: Break view is break all
x-summary-source: derived
/JSON/break/view/isBreakRequest/:
get:
description: Returns True if ZAP will break on requests
operationId: breakViewIsBreakRequest
tags:
- break
responses:
default:
$ref: '#/components/responses/ErrorJson'
summary: Break view is break request
x-summary-source: derived
/JSON/break/view/isBreakResponse/:
get:
description: Returns True if ZAP will break on responses
operationId: breakViewIsBreakResponse
tags:
- break
responses:
default:
$ref: '#/components/responses/ErrorJson'
summary: Break view is break response
x-summary-source: derived
components:
schemas:
ErrorJson:
type: object
required:
- code
- message
properties:
code:
type: string
message:
type: string
detail:
type: string
responses:
ErrorJson:
description: Error of JSON endpoints.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorJson'
securitySchemes:
apiKeyHeader:
type: apiKey
name: X-ZAP-API-Key
in: header
apiKeyQuery:
type: apiKey
name: apikey
in: query