<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Api on ZAP</title>
    <link>/tags/api/</link>
    <description>Recent content in Api on ZAP</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Thu, 21 May 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="/tags/api/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Scanning MCP Servers with ZAP</title>
      <link>/blog/2026-05-21-scanning-mcp-servers-with-zap/</link>
      <pubDate>Thu, 21 May 2026 00:00:00 +0000</pubDate>
      <guid>/blog/2026-05-21-scanning-mcp-servers-with-zap/</guid>
      <description>ZAP can now scan MCP (Model Context Protocol) servers as a first-class target. Import an MCP server from the ZAP desktop or the Automation Framework, or run the new action-mcp-scan GitHub Action to scan one from CI.</description>
    </item>
    <item>
      <title>The ZAP MCP Server</title>
      <link>/blog/2026-04-02-zap-mcp-server/</link>
      <pubDate>Thu, 02 Apr 2026 00:00:00 +0000</pubDate>
      <guid>/blog/2026-04-02-zap-mcp-server/</guid>
      <description>Connect AI assistants like Claude and ChatGPT to ZAP via the Model Context Protocol. Start scans, read alerts, and explore your application—all through natural conversation.</description>
    </item>
    <item>
      <title>Scanning APIs with ZAP</title>
      <link>/blog/2017-06-19-scanning-apis-with-zap/</link>
      <pubDate>Mon, 19 Jun 2017 00:00:00 +0000</pubDate>
      <guid>/blog/2017-06-19-scanning-apis-with-zap/</guid>
      <description>&lt;p&gt;The previous ZAP blog post explained how you could &lt;a href=&#34;/blog/2017-04-03-exploring-apis-with-zap/&#34;&gt;Explore APIs with ZAP&lt;/a&gt;.&lt;br&gt;&#xA;This blog post goes one step further, and explains how you can both explore and perform security scanning of APIs using ZAP from the command&#xA;line.&lt;br&gt;&#xA;This allows you to easily automate the scanning of your APIs.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exploring APIs with ZAP</title>
      <link>/blog/2017-04-03-exploring-apis-with-zap/</link>
      <pubDate>Mon, 03 Apr 2017 00:00:00 +0000</pubDate>
      <guid>/blog/2017-04-03-exploring-apis-with-zap/</guid>
      <description>&lt;p&gt;APIs can be challenging for security testing for a variety of reasons.&lt;br&gt;&#xA;The first problem you will encounter is how to effectively explore an API - most APIs cannot be explored using browsing or standard spidering&#xA;techniques.&lt;br&gt;&#xA;However many APIs are described using technologies such as:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://en.wikipedia.org/wiki/SOAP&#34;&gt;SOAP&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://www.openapis.org/&#34;&gt;OpenAPI / Swagger&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;These standards define the API endpoints and can be imported into ZAP using 2 optional add-ons.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
