Extract all rest api with payload.

21 views
Skip to first unread message

Anand M R

unread,
Aug 27, 2025, 9:23:43 AMAug 27
to zaprox...@googlegroups.com
Hi,

I have a web app that uses rest api. It uses jwt token for api authentication. I want to extract all api details with payloads used in web app automatically. I don't want to do active scan. Is it possible using zaproxy.

Thanks

Naveen Rajamannar

unread,
Aug 27, 2025, 9:37:58 AMAug 27
to zaprox...@googlegroups.com
--
ZAP by Checkmarx: https://www.zaproxy.org/
---
You received this message because you are subscribed to the Google Groups "ZAP User Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to zaproxy-user...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/zaproxy-users/CA%2BY9zv7gNwRyxFHkPhSXvgyGipe7Y%2B7r9PZLumJsbJV6idzF5w%40mail.gmail.com.
[zaproxy-users] Extract all rest api with payload..eml

Simon Bennetts

unread,
Sep 3, 2025, 11:43:06 AMSep 3
to ZAP User Group
Hiya,

ZAP is very flexible, and will only do what you tell it to do.
If you dont want to active scan then dont tell ZAP to do it!

You will however need to explore your web app effectively in order to trigger as many of the API calls as possible.

Cheers,

Simon
Reply all
Reply to author
Forward
0 new messages