OWASP ZAP Core API

The core API from OWASP ZAP — 97 operation(s) for core.

Business capability
Vulnerability Management BC-620.40

Operations 97

GET /JSON/core/action/accessUrl/ Core action access url #
GET /JSON/core/action/addProxyChainExcludedDomain/ Core action add proxy chain excluded domain #
GET /JSON/core/action/clearExcludedFromProxy/ Core action clear excluded from proxy #
GET /JSON/core/action/createSbomZip/ Core action create sbom zip #
GET /JSON/core/action/deleteAlert/ Core action delete alert #
GET /JSON/core/action/deleteAllAlerts/ Core action delete all alerts #
GET /JSON/core/action/deleteSiteNode/ Core action delete site node #
GET /JSON/core/action/disableAllProxyChainExcludedDomains/ Core action disable all proxy chain excluded domains #
GET /JSON/core/action/disableClientCertificate/ Core action disable client certificate #
GET /JSON/core/action/enableAllProxyChainExcludedDomains/ Core action enable all proxy chain excluded domains #
GET /JSON/core/action/enablePKCS12ClientCertificate/ Core action enable PKCS12 client certificate #
GET /JSON/core/action/excludeFromProxy/ Core action exclude from proxy #
GET /JSON/core/action/generateRootCA/ Core action generate root CA #
GET /JSON/core/action/loadSession/ Core action load session #
GET /JSON/core/action/modifyProxyChainExcludedDomain/ Core action modify proxy chain excluded domain #
GET /JSON/core/action/newSession/ Core action new session #
GET /JSON/core/action/removeProxyChainExcludedDomain/ Core action remove proxy chain excluded domain #
GET /JSON/core/action/runGarbageCollection/ Core action run garbage collection #
GET /JSON/core/action/saveSession/ Core action save session #
GET /JSON/core/action/sendRequest/ Core action send request #
GET /JSON/core/action/setHomeDirectory/ Core action set home directory #
GET /JSON/core/action/setLogLevel/ Core action set log level #
GET /JSON/core/action/setMode/ Core action set mode #
GET /JSON/core/action/setOptionAlertOverridesFilePath/ Core action set option alert overrides file path #
GET /JSON/core/action/setOptionDefaultUserAgent/ Core action set option default user agent #
GET /JSON/core/action/setOptionDnsTtlSuccessfulQueries/ Core action set option dns ttl successful queries #
GET /JSON/core/action/setOptionHttpStateEnabled/ Core action set option http state enabled #
GET /JSON/core/action/setOptionMaximumAlertInstances/ Core action set option maximum alert instances #
GET /JSON/core/action/setOptionMergeRelatedAlerts/ Core action set option merge related alerts #
GET /JSON/core/action/setOptionProxyChainName/ Core action set option proxy chain name #
GET /JSON/core/action/setOptionProxyChainPassword/ Core action set option proxy chain password #
GET /JSON/core/action/setOptionProxyChainPort/ Core action set option proxy chain port #
GET /JSON/core/action/setOptionProxyChainPrompt/ Core action set option proxy chain prompt #
GET /JSON/core/action/setOptionProxyChainRealm/ Core action set option proxy chain realm #
GET /JSON/core/action/setOptionProxyChainSkipName/ Core action set option proxy chain skip name #
GET /JSON/core/action/setOptionProxyChainUserName/ Core action set option proxy chain user name #
GET /JSON/core/action/setOptionSingleCookieRequestHeader/ Core action set option single cookie request header #
GET /JSON/core/action/setOptionTimeoutInSecs/ Core action set option timeout in secs #
GET /JSON/core/action/setOptionUseProxyChain/ Core action set option use proxy chain #
GET /JSON/core/action/setOptionUseProxyChainAuth/ Core action set option use proxy chain auth #
GET /JSON/core/action/setOptionUseSocksProxy/ Core action set option use socks proxy #
GET /JSON/core/action/shutdown/ Core action shutdown #
GET /JSON/core/action/snapshotSession/ Core action snapshot session #
GET /OTHER/core/other/fileDownload/ Core other file download #
GET /OTHER/core/other/fileUpload/ Core other file upload #
GET /OTHER/core/other/htmlreport/ Core other htmlreport #
GET /OTHER/core/other/jsonreport/ Core other jsonreport #
GET /OTHER/core/other/mdreport/ Core other mdreport #
GET /OTHER/core/other/messageHar/ Core other message har #
GET /OTHER/core/other/messagesHar/ Core other messages har #
GET /OTHER/core/other/messagesHarById/ Core other messages har by id #
GET /OTHER/core/other/proxy.pac/ Core other proxy pac #
GET /OTHER/core/other/rootcert/ Core other rootcert #
GET /OTHER/core/other/sendHarRequest/ Core other send har request #
GET /OTHER/core/other/setproxy/ Core other setproxy #
GET /OTHER/core/other/xmlreport/ Core other xmlreport #
GET /JSON/core/view/alert/ Core view alert #
GET /JSON/core/view/alerts/ Core view alerts #
GET /JSON/core/view/alertsSummary/ Core view alerts summary #
GET /JSON/core/view/childNodes/ Core view child nodes #
GET /JSON/core/view/excludedFromProxy/ Core view excluded from proxy #
GET /JSON/core/view/getLogLevel/ Core view get log level #
GET /JSON/core/view/homeDirectory/ Core view home directory #
GET /JSON/core/view/hosts/ Core view hosts #
GET /JSON/core/view/message/ Core view message #
GET /JSON/core/view/messages/ Core view messages #
GET /JSON/core/view/messagesById/ Core view messages by id #
GET /JSON/core/view/mode/ Core view mode #
GET /JSON/core/view/numberOfAlerts/ Core view number of alerts #
GET /JSON/core/view/numberOfMessages/ Core view number of messages #
GET /JSON/core/view/optionAlertOverridesFilePath/ Core view option alert overrides file path #
GET /JSON/core/view/optionDefaultUserAgent/ Core view option default user agent #
GET /JSON/core/view/optionDnsTtlSuccessfulQueries/ Core view option dns ttl successful queries #
GET /JSON/core/view/optionHttpState/ Core view option http state #
GET /JSON/core/view/optionHttpStateEnabled/ Core view option http state enabled #
GET /JSON/core/view/optionMaximumAlertInstances/ Core view option maximum alert instances #
GET /JSON/core/view/optionMergeRelatedAlerts/ Core view option merge related alerts #
GET /JSON/core/view/optionProxyChainName/ Core view option proxy chain name #
GET /JSON/core/view/optionProxyChainPassword/ Core view option proxy chain password #
GET /JSON/core/view/optionProxyChainPort/ Core view option proxy chain port #
GET /JSON/core/view/optionProxyChainPrompt/ Core view option proxy chain prompt #
GET /JSON/core/view/optionProxyChainRealm/ Core view option proxy chain realm #
GET /JSON/core/view/optionProxyChainSkipName/ Core view option proxy chain skip name #
GET /JSON/core/view/optionProxyChainUserName/ Core view option proxy chain user name #
GET /JSON/core/view/optionProxyExcludedDomains/ Core view option proxy excluded domains #
GET /JSON/core/view/optionProxyExcludedDomainsEnabled/ Core view option proxy excluded domains enabled #
GET /JSON/core/view/optionSingleCookieRequestHeader/ Core view option single cookie request header #
GET /JSON/core/view/optionTimeoutInSecs/ Core view option timeout in secs #
GET /JSON/core/view/optionUseProxyChain/ Core view option use proxy chain #
GET /JSON/core/view/optionUseProxyChainAuth/ Core view option use proxy chain auth #
GET /JSON/core/view/optionUseSocksProxy/ Core view option use socks proxy #
GET /JSON/core/view/proxyChainExcludedDomains/ Core view proxy chain excluded domains #
GET /JSON/core/view/sessionLocation/ Core view session location #
GET /JSON/core/view/sites/ Core view sites #
GET /JSON/core/view/urls/ Core view urls #
GET /JSON/core/view/version/ Core view version #
GET /JSON/core/view/zapHomePath/ Core view zap home path #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/owasp-zap-core-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

owasp-zap-core-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: ZAP Core API
  description: The HTTP API for controlling and accessing ZAP.
  contact:
    name: ZAP User Group
    url: https://groups.google.com/group/zaproxy-users
    email: zaproxy-users@googlegroups.com
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0.html
  version: 2.16.1
servers:
- url: http://zap
  description: The URL while proxying through ZAP.
- url: http://{address}:{port}
  description: The URL of a Local Proxy of ZAP.
  variables:
    address:
      description: The address ZAP is listening on.
      default: 127.0.0.1
    port:
      description: The port ZAP is bound to.
      default: '8080'
security:
- {}
- apiKeyHeader: []
- apiKeyQuery: []
tags:


# --- truncated at 32 KB (47 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/owasp-zap/refs/heads/main/openapi/owasp-zap-core-api-openapi.yml