Atlas / MCP servers / calebl / Ynab

YnabSAFE

mcp/calebl/ynab

Model Context Protocol for YNAB (you need a budget)

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
6 6r · 0w · 0d
Transport
stdio
License
MIT
Stars
150
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server for interacting with your YNAB plans at https://ynab.com

In order to have an AI interact with this tool, you will need to get your Personal Access Token from YNAB: https://api.ynab.com/#personal-access-tokens. When adding this MCP server to any client, you will need to provide your personal access token as YNABAPITOKEN. This token is never directly sent to the LLM. It is stored privately in an environment variable for use with the YNAB api.

A Model Context Protocol server that lets an AI assistant read and modify a YNAB plan.

The server talks to the YNAB API through the official `ynab` SDK. Your Personal Access Token lives in an environment variable and is never sent to the model.

It runs two ways from one codebase:

  • Local (stdio) — a child process of Claude Code or Claude Desktop on your

own machine. Simplest, but only works on that machine while it is running.

  • Remote (Cloudflare Worker) — deployed behind GitHub sign-in and added to

claude.ai as a custom connector, so it works from the web and the mobile app with your computer switched off. See DEPLOY.md.

Both entry points register the same tools from src/registry.ts, so a tool written once is available in both.

Other providers:

[](https://lightnow.ai/servers/io.github.calebl/ynab-mcp-server)

Setup

Get a Personal Access Token from , then:

npm install
npm run build

Environment variables:

Read from source at commit 5bf0d3a89e4aOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add ynab-mcp-server --env TYPESAFE_API_KEY=${TYPESAFE_API_KEY} --env YNAB_API_TOKEN=${YNAB_API_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "ynab-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "TYPESAFE_API_KEY": "${TYPESAFE_API_KEY}",
        "YNAB_API_TOKEN": "${YNAB_API_TOKEN}"
      }
    }
  }
}
03

Exposed tools (6)

6 read · 0 write · 0 destructive.

ToolRiskDescription
failing_result_tool_testreadtest
null_normalization_testreadtest
success_result_tool_testreadtest
throwing_tool_testreadtest
ynab_budget_summaryreadFormer name of ynab_plan_summary.
ynab_list_budgetsreadFormer name of ynab_list_plans.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (5)

LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/tests/oauth.test.ts:169
it.each([CLAUDE_CB, CHATGPT_CB, LOOPBACK_CB, "http://127.0.0.1:9000/cb", "http://[::1]:9000/cb"])(
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/tests/oauth.test.ts:185
"http://127.0.0.2:9000/cb",
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/worker/google-calendar.ts:38
const der = Uint8Array.from(atob(body), (c) => c.charCodeAt(0));
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@cloudflare/workers-oauth-provider, @modelcontextprotocol/sdk, @modelcontextprotocol/server, ynab, zod, @cloudflare/workers-types, @types/node, @vitest/coverage-v8
Why it matters. 11 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
AGENTS.md:51
The tool modules read `process.env` directly. The Worker has no ambient
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 5bf0d3a89e4afull audit observations/trust-audit/mcp-server/calebl__ynab.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-075bf0d3a89e4aSAFEB89first audit
06

Questions

What is the Ynab MCP server?

Model Context Protocol for YNAB (you need a budget)

What tools does Ynab expose?

6 in total: 6 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Ynab safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Ynab need?

It reads TYPESAFE_API_KEY and YNAB_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Ynab run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as ynab-mcp-server at 0.4.1.

How current is this page?

The grade is for one exact copy of the source (5bf0d3a89e4a), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement