The information in this FAQ is based on details from: This user group thread The Vaadin framework makes heavy use of JavaScript, so it seems the Ajax Spider is the way to go. As you work to figure things out and get them configured correctly it makes sense to starting by proxying your browser through ZAP, identifying the http session and then flagging it as the ‘active session’ before starting the Ajax Spider.