YnabSAFE
Model Context Protocol for YNAB (you need a budget)
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) server for interacting with your YNAB plans at https://ynab.com
In order to have an AI interact with this tool, you will need to get your Personal Access Token from YNAB: https://api.ynab.com/#personal-access-tokens. When adding this MCP server to any client, you will need to provide your personal access token as YNABAPITOKEN. This token is never directly sent to the LLM. It is stored privately in an environment variable for use with the YNAB api.
A Model Context Protocol server that lets an AI assistant read and modify a YNAB plan.
The server talks to the YNAB API through the official `ynab` SDK. Your Personal Access Token lives in an environment variable and is never sent to the model.
It runs two ways from one codebase:
- Local (stdio) — a child process of Claude Code or Claude Desktop on your
own machine. Simplest, but only works on that machine while it is running.
- Remote (Cloudflare Worker) — deployed behind GitHub sign-in and added to
claude.ai as a custom connector, so it works from the web and the mobile app with your computer switched off. See DEPLOY.md.
Both entry points register the same tools from src/registry.ts, so a tool written once is available in both.
Other providers:
[](https://lightnow.ai/servers/io.github.calebl/ynab-mcp-server)
Setup
Get a Personal Access Token from , then:
npm install npm run build
Environment variables:
5bf0d3a89e4aOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add ynab-mcp-server --env TYPESAFE_API_KEY=${TYPESAFE_API_KEY} --env YNAB_API_TOKEN=${YNAB_API_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"ynab-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"TYPESAFE_API_KEY": "${TYPESAFE_API_KEY}",
"YNAB_API_TOKEN": "${YNAB_API_TOKEN}"
}
}
}
}Exposed tools (6)
6 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
failing_result_tool_test | read | test |
null_normalization_test | read | test |
success_result_tool_test | read | test |
throwing_tool_test | read | test |
ynab_budget_summary | read | Former name of ynab_plan_summary. |
ynab_list_budgets | read | Former name of ynab_list_plans. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (5)
it.each([CLAUDE_CB, CHATGPT_CB, LOOPBACK_CB, "http://127.0.0.1:9000/cb", "http://[::1]:9000/cb"])(
"http://127.0.0.2:9000/cb",
const der = Uint8Array.from(atob(body), (c) => c.charCodeAt(0));
@cloudflare/workers-oauth-provider, @modelcontextprotocol/sdk, @modelcontextprotocol/server, ynab, zod, @cloudflare/workers-types, @types/node, @vitest/coverage-v8
The tool modules read `process.env` directly. The Worker has no ambient
Gates applied: no_behavioural_pass.
5bf0d3a89e4afull audit observations/trust-audit/mcp-server/calebl__ynab.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 5bf0d3a89e4a | SAFE | B | 89 | first audit |
Questions
What is the Ynab MCP server?
Model Context Protocol for YNAB (you need a budget)
What tools does Ynab expose?
6 in total: 6 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Ynab safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Ynab need?
It reads TYPESAFE_API_KEY and YNAB_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Ynab run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as ynab-mcp-server at 0.4.1.
How current is this page?
The grade is for one exact copy of the source (5bf0d3a89e4a), read on 2026-10-07. The repository is watched and re-audited when it changes.