ZAP:API探索——如何在UI中设置请求头参数(如API密钥)?
Hey Alex, I’ve dealt with this exact issue before while working with ZAP—let me break down the straightforward steps to add request headers like API keys directly in the UI:
Access the global header settings:
Head to the top menu bar, click Tools, then select Options. In the options window that pops up, look for the HTTP Session category in the left sidebar and click into it.Add your API key (or other header):
Inside the HTTP Session settings, switch to the Request Headers tab. Hit the Add button (the little plus icon) to create a new header entry:- Type your header’s name (like
X-API-Key) in the Name field. - Paste your actual API key value into the Value field.
- Make sure the Enabled box is checked—this ensures ZAP automatically includes this header in every outgoing request.
- Type your header’s name (like
Verify it’s working:
To double-check, use the Request Editor (under the Tools menu) to send a test request to your target API. After sending, look at the Request tab in the bottom panel—you should see your custom header listed alongside the default ones.
Optional: Apply headers to specific sites only
If you don’t want the header sent to every single request (just your target API), you can tie it to a ZAP context instead:
- Go to the Contexts tab on the left sidebar, right-click your target context, and choose Edit Context.
- In the editor, navigate to the Request Headers section.
- Click Add to input your header details, then save the changes. Now the header will only be applied when ZAP interacts with URLs in that context.
I’ve found these steps work for most recent stable versions of ZAP—if you were following an older guide, the UI might have shifted a bit, but this should get you sorted.
内容的提问来源于stack exchange,提问作者Alex

