MCP ZAP Server
io.github.dtkmn/mcp-zap-server · Status: active
If you find your own account name here: write informally to German.saas@web.de, stating the identifier concerned. No reason has to be given. How to object
- Registry name
io.github.dtkmn/mcp-zap-server- Package coordinate
oci:docker.io/dtkmn/mcp-zap-server:v0.11.0- Version
0.11.0- Listed in the registry
- 2026-07-27
- Changed in the registry
- 2026-07-27
- First seen by tracevero
- 2026-08-06
- Vendor's website
- https://danieltse.org/mcp-zap-server/
Safe, self-hosted OWASP ZAP operator for guided AI security scans and reports.
Vendor's own description, untranslated and unverified
Evidence for this page: The values on this page come from several collections. Each row therefore states its own origin. What the confidence levels mean
Measured values
| Credentials required | yes Raw declaration – Required secret variables (raw): MCP_API_KEY, MCP_API_KEY, ZAP_API_KEY, ZAP_API_KEY Raw declaration – Required secret headers (raw): confirmed absent Source: MCP-Register · collected on 2026-08-06 · derived |
|---|---|
| Execution location | remote Raw declaration – Transports (raw): streamable-http, streamable-http Source: MCP-Register · collected on 2026-08-06 · derived |
| Path argument present | no Raw declaration – Path arguments (raw): confirmed absent Raw declaration – Path environment variables (raw): confirmed absent Source: MCP-Register · collected on 2026-08-06 · derived |
| Repository URL listed | yes Raw declaration – Repository (raw): https://github.com/dtkmn/mcp-zap-server Source: MCP-Register · collected on 2026-08-06 · derived |
| Version | 0.11.0 Source: MCP-Register · collected on 2026-08-06 · self-declared |
Position within the holdings
How many of the 24,717 published entries carry the same measured value. A reference figure, not an assessment.
- Credentials requiredyes4,262 of 24,717 carry this value (17 %)View these entries
- Execution locationremote12,537 of 24,717 carry this value (51 %)View these entries
- Path argument presentno24,480 of 24,717 carry this value (99 %)View these entries
- Repository URL listedyes19,247 of 24,717 carry this value (78 %)View these entries
All 4 values together are carried by 748 of 24,717 entries.
This entry appears in these selections
- MCP servers requiring credentials4,262
- Remotely executed MCP servers12,537
- MCP servers with a repository URL19,247
- Remote MCP servers requiring credentials1,359
- Remote MCP servers with a repository URL7,676
- MCP servers with credentials and a repository URL3,532
- MCP servers available as a package only10,706
The source's raw values23
Evidence for this page: The values on this page come from several collections. Each row therefore states its own origin.
| Environment variables (raw) | ZAP_API_URL, ZAP_API_PORT, ZAP_API_KEY, MCP_API_KEY, MCP_SERVER_TOOLS_SURFACE, MCP_SECURITY_MODE, MCP_SECURITY_ENABLED, MCP_SECURITY_ALLOW_PLACEHOLDER_API_KEY, ZAP_API_URL, ZAP_API_PORT, ZAP_API_KEY, MCP_API_KEY, MCP_SERVER_TOOLS_SURFACE, MCP_SECURITY_MODE, MCP_SECURITY_ENABLED, MCP_SECURITY_ALLOW_PLACEHOLDER_API_KEY Source: MCP-Register · collected on 2026-08-06 · self-declared |
|---|---|
| Required secret variables (raw) | MCP_API_KEY, MCP_API_KEY, ZAP_API_KEY, ZAP_API_KEY Source: MCP-Register · collected on 2026-08-06 · self-declared |
| Transports (raw) | streamable-http, streamable-http Source: MCP-Register · collected on 2026-08-06 · self-declared |
| Path arguments (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-06 · self-declared |
| Repository (raw) | https://github.com/dtkmn/mcp-zap-server Source: MCP-Register · collected on 2026-08-06 · self-declared |
| Package registries (raw) | oci, oci Source: MCP-Register · collected on 2026-08-06 · self-declared |
| Required secret headers (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Path environment variables (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Remote URLs (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Remote hosts (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Registry status message (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| First listed in the registry (raw) | 2026-07-27 Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Last changed in the registry (raw) | 2026-07-27 Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Schema version of the raw record (raw) | https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Delivery form (raw) | paket Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Repository platform (raw) | github Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Repository subfolder (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Package identifiers (raw) | docker.io/dtkmn/mcp-zap-server:v0.11.0, ghcr.io/dtkmn/mcp-zap-server:v0.11.0 Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Package versions (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Runtime hints (raw) | docker Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Environment variable formats (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Environment variable descriptions (raw) | MCP_API_KEY=API key clients must send as X-API-Key. · MCP_SERVER_TOOLS_SURFACE=Tool surface to expose. Use guided for the safer default workflow, including report readback. Use expert only when clients need raw ZAP tools outside the guided surface. · ZAP_API_KEY=API key configured on the OWASP ZAP daemon. · ZAP_API_PORT=OWASP ZAP API port. · ZAP_API_URL=Hostname or URL of a separately running OWASP ZAP daemon reachable from this container. Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Icon formats (raw) | image/png Source: MCP-Register · collected on 2026-08-16 · self-declared |
Changes
| 2026-08-16 | Last changed in the registry (raw): – → 2026-07-27 |
|---|---|
| 2026-08-16 | First listed in the registry (raw): – → 2026-07-27 |
| 2026-08-16 | Registry status message (raw): – → – |
| 2026-08-16 | Schema version of the raw record (raw): – → https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json |
| 2026-08-16 | Icon formats (raw): – → image/png |
| 2026-08-16 | Environment variable descriptions (raw): – → MCP_API_KEY=API key clients must send as X-API-Key. · MCP_SERVER_TOOLS_SURFACE=Tool surface to expose. Use guided for the safer default workflow, including report readback. Use expert only when clients need raw ZAP tools outside the guided surface. · ZAP_API_KEY=API key configured on the OWASP ZAP daemon. · ZAP_API_PORT=OWASP ZAP API port. · ZAP_API_URL=Hostname or URL of a separately running OWASP ZAP daemon reachable from this container. |
| 2026-08-16 | Environment variable formats (raw): – → – |
| 2026-08-16 | Delivery form (raw): – → paket |
| 2026-08-16 | Remote hosts (raw): – → – |
| 2026-08-16 | Remote URLs (raw): – → – |
These are the 10 most recent changes to this entry. Full history
tracevero · https://tracevero.com/mcp/io-github-dtkmn-mcp-zap-server