OWASP ZAP
OWASP ZAP (Zed Attack Proxy) is an open source web application security scanner for finding vulnerabilities in APIs and web applications during development and testing. ZAP exposes a comprehensive HTTP API for controlling and automating scans, spidering, authentication, alerts, reporting, and more.
OWASP ZAP publishes 49 APIs on the APIs.io network, including accessControl API, acsrf API, ajaxSpider API, and 46 more. Tagged areas include Security Testing, Application Security, Vulnerability Scanning, Testing, and Open-Source.
OWASP ZAP’s developer surface includes authentication, engineering blog, documentation, and 9 more developer resources.
Kin Score
APIs 49
Individual APIs this provider publishes, each with its own machine-readable definition.
OWASP ZAP accessControl API
The accessControl API from OWASP ZAP — 4 operation(s) for accesscontrol.
OWASP ZAP acsrf API
The acsrf API from OWASP ZAP — 6 operation(s) for acsrf.
OWASP ZAP ajaxSpider API
The ajaxSpider API from OWASP ZAP — 41 operation(s) for ajaxspider.
OWASP ZAP alert API
The alert API from OWASP ZAP — 13 operation(s) for alert.
OWASP ZAP alertFilter API
The alertFilter API from OWASP ZAP — 12 operation(s) for alertfilter.
OWASP ZAP ascan API
The ascan API from OWASP ZAP — 90 operation(s) for ascan.
OWASP ZAP authentication API
The authentication API from OWASP ZAP — 8 operation(s) for authentication.
OWASP ZAP authorization API
The authorization API from OWASP ZAP — 2 operation(s) for authorization.
OWASP ZAP automation API
The automation API from OWASP ZAP — 3 operation(s) for automation.
OWASP ZAP autoupdate API
The autoupdate API from OWASP ZAP — 32 operation(s) for autoupdate.
OWASP ZAP break API
The break API from OWASP ZAP — 11 operation(s) for break.
OWASP ZAP client API
The client API from OWASP ZAP — 5 operation(s) for client.
OWASP ZAP clientSpider API
The clientSpider API from OWASP ZAP — 3 operation(s) for clientspider.
OWASP ZAP context API
The context API from OWASP ZAP — 21 operation(s) for context.
OWASP ZAP core API
The core API from OWASP ZAP — 97 operation(s) for core.
OWASP ZAP custompayloads API
The custompayloads API from OWASP ZAP — 8 operation(s) for custompayloads.
OWASP ZAP dev API
The dev API from OWASP ZAP — 1 operation(s) for dev.
OWASP ZAP exim API
The exim API from OWASP ZAP — 9 operation(s) for exim.
OWASP ZAP forcedUser API
The forcedUser API from OWASP ZAP — 4 operation(s) for forceduser.
OWASP ZAP graphql API
The graphql API from OWASP ZAP — 20 operation(s) for graphql.
OWASP ZAP httpSessions API
The httpSessions API from OWASP ZAP — 16 operation(s) for httpsessions.
OWASP ZAP hud API
The hud API from OWASP ZAP — 37 operation(s) for hud.
OWASP ZAP keyboard API
The keyboard API from OWASP ZAP — 2 operation(s) for keyboard.
OWASP ZAP localProxies API
The localProxies API from OWASP ZAP — 3 operation(s) for localproxies.
OWASP ZAP network API
The network API from OWASP ZAP — 48 operation(s) for network.
OWASP ZAP oast API
The oast API from OWASP ZAP — 11 operation(s) for oast.
OWASP ZAP openapi API
The openapi API from OWASP ZAP — 2 operation(s) for openapi.
OWASP ZAP paramDigger API
The paramDigger API from OWASP ZAP — 1 operation(s) for paramdigger.
OWASP ZAP params API
The params API from OWASP ZAP — 1 operation(s) for params.
OWASP ZAP pnh API
The pnh API from OWASP ZAP — 8 operation(s) for pnh.
OWASP ZAP postman API
The postman API from OWASP ZAP — 2 operation(s) for postman.
OWASP ZAP pscan API
The pscan API from OWASP ZAP — 17 operation(s) for pscan.
OWASP ZAP quickstartlaunch API
The quickstartlaunch API from OWASP ZAP — 1 operation(s) for quickstartlaunch.
OWASP ZAP replacer API
The replacer API from OWASP ZAP — 4 operation(s) for replacer.
OWASP ZAP reports API
The reports API from OWASP ZAP — 3 operation(s) for reports.
OWASP ZAP retest API
The retest API from OWASP ZAP — 1 operation(s) for retest.
OWASP ZAP reveal API
The reveal API from OWASP ZAP — 2 operation(s) for reveal.
OWASP ZAP revisit API
The revisit API from OWASP ZAP — 3 operation(s) for revisit.
OWASP ZAP ruleConfig API
The ruleConfig API from OWASP ZAP — 5 operation(s) for ruleconfig.
OWASP ZAP script API
The script API from OWASP ZAP — 24 operation(s) for script.
OWASP ZAP search API
The search API from OWASP ZAP — 18 operation(s) for search.
OWASP ZAP selenium API
The selenium API from OWASP ZAP — 22 operation(s) for selenium.
OWASP ZAP sessionManagement API
The sessionManagement API from OWASP ZAP — 4 operation(s) for sessionmanagement.
OWASP ZAP soap API
The soap API from OWASP ZAP — 2 operation(s) for soap.
OWASP ZAP spider API
The spider API from OWASP ZAP — 71 operation(s) for spider.
OWASP ZAP stats API
The stats API from OWASP ZAP — 13 operation(s) for stats.
OWASP ZAP users API
The users API from OWASP ZAP — 15 operation(s) for users.
OWASP ZAP wappalyzer API
The wappalyzer API from OWASP ZAP — 3 operation(s) for wappalyzer.
OWASP ZAP websocket API
The websocket API from OWASP ZAP — 6 operation(s) for websocket.
Scroll for all 49
Open Collections 51
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
API Collection
OPEN COLLECTIONZAP accessControl API
OPEN COLLECTIONZAP accessControl acsrf API
OPEN COLLECTIONZAP accessControl ajaxSpider API
OPEN COLLECTIONZAP accessControl alert API
OPEN COLLECTIONZAP accessControl alertFilter API
OPEN COLLECTIONZAP accessControl ascan API
OPEN COLLECTIONZAP accessControl authentication API
OPEN COLLECTIONZAP accessControl authorization API
OPEN COLLECTIONZAP accessControl automation API
OPEN COLLECTIONZAP accessControl autoupdate API
OPEN COLLECTIONZAP accessControl break API
OPEN COLLECTIONZAP accessControl client API
OPEN COLLECTIONZAP accessControl clientSpider API
OPEN COLLECTIONZAP accessControl context API
OPEN COLLECTIONZAP accessControl core API
OPEN COLLECTIONZAP accessControl custompayloads API
OPEN COLLECTIONZAP accessControl dev API
OPEN COLLECTIONZAP accessControl exim API
OPEN COLLECTIONZAP accessControl forcedUser API
OPEN COLLECTIONZAP accessControl graphql API
OPEN COLLECTIONZAP accessControl httpSessions API
OPEN COLLECTIONZAP accessControl hud API
OPEN COLLECTIONZAP accessControl keyboard API
OPEN COLLECTIONZAP accessControl localProxies API
OPEN COLLECTIONZAP accessControl network API
OPEN COLLECTIONZAP accessControl oast API
OPEN COLLECTIONZAP accessControl openapi API
OPEN COLLECTIONZAP accessControl paramDigger API
OPEN COLLECTIONZAP accessControl params API
OPEN COLLECTIONZAP accessControl pnh API
OPEN COLLECTIONZAP accessControl postman API
OPEN COLLECTIONZAP accessControl pscan API
OPEN COLLECTIONZAP accessControl quickstartlaunch API
OPEN COLLECTIONZAP accessControl replacer API
OPEN COLLECTIONZAP accessControl reports API
OPEN COLLECTIONZAP accessControl retest API
OPEN COLLECTIONZAP accessControl reveal API
OPEN COLLECTIONZAP accessControl revisit API
OPEN COLLECTIONZAP accessControl ruleConfig API
OPEN COLLECTIONZAP accessControl script API
OPEN COLLECTIONZAP accessControl search API
OPEN COLLECTIONZAP accessControl selenium API
OPEN COLLECTIONZAP accessControl sessionManagement API
OPEN COLLECTIONZAP accessControl soap API
OPEN COLLECTIONZAP accessControl spider API
OPEN COLLECTIONZAP accessControl stats API
OPEN COLLECTIONZAP accessControl users API
OPEN COLLECTIONZAP accessControl wappalyzer API
OPEN COLLECTIONZAP accessControl websocket API
OPEN COLLECTIONZAP API
OPEN COLLECTIONScroll for all 51
Pricing Plans 1
Published pricing tiers and plan structures.
Rate Limits 1
Documented rate limits and quota policies.
Owasp Zap Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals for API financial operations.
Owasp Zap Finops
FINOPSSecurity Posture 3
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Agentic Access 1
Recommended x-agentic-access execution contracts for AI agents.
Resources
Documentation 2
Reference material describing how the API behaves
Agent Surfaces 1
MCP servers, agent skills, and machine-readable catalogs
Build 1
SDKs, sample code, and the tooling you integrate with
Access & Security 3
Authentication, authorization, and security posture
Operate 1
Status, limits, changes, and where to get help
Commercial 1
Pricing, plans, and the legal terms of use
Company 2
The organization behind the API
Other 1
Properties that don't map to a standard resource type
Source (apis.yml)
Work with this as data
Every provider here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for providers
9 MCP tools reach this
find_providersBrowse and filter every provider in the catalog.get_provider_artifactsEvery artifact this provider publishes, grouped by type.get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.get_provider_toolsEvery MCP tool they ship, with the operation each wraps.get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.get_provider_ratingPRO — composite, band, trend and facet scores.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
curl "https://apis.io/api/v1/providers/owasp-zap"
curl "https://apis.io/api/v1/providers?limit=25"
curl "https://apis.io/api/v1/providers/owasp-zap/operations?limit=25"
curl "https://apis.io/api/v1/providers/owasp-zap/evidence"
Discovery needs no key. Ratings and market analysis are Pro.