By default ZAP will now also only allow connections from the local machine. You can set which IP addresses can connect to the API using the command line: -config api.addrs.addr.name=123.456.789.123 If you are using ZAP in a completely isolated environment you can allow all IP addresses to connect to the ZAP API using: