Releases: Jonah-Lam/ynab-mcp-server
Releases · Jonah-Lam/ynab-mcp-server
Release list
v1.0.2
Security
- With
ALLOWED_REDIRECT_HOSTS="*", custom redirect schemes must now be reverse-domain app schemes (e.g.com.example.app:). Previouslyvbscript:andfile:were not rejected. The default configuration was not affected. - Generated owner passwords now use unbiased random sampling.
v1.0.1
Changed
- Settings are now managed in the Cloudflare dashboard and kept across deploys (
keep_vars). Defaults moved fromwrangler.jsoncinto the code, so updating no longer resets settings or causes merge conflicts inwrangler.jsonc. - An unset or empty
ALLOWED_REDIRECT_HOSTSnow means the default list (Claude, ChatGPT, localhost).
Added
- README section on updating a deployment.
v1.0.0
First release.
Added
- Remote MCP server for YNAB on Cloudflare Workers, compatible with Claude and ChatGPT (Streamable HTTP at
/mcp). - Read tools:
list_plans,list_accounts,get_budget_month,list_months,list_payees,list_transactions,get_transaction,list_scheduled_transactions,list_money_movements, plus ChatGPT-stylesearchandfetch. - Write tools:
create_transactions,update_transactions,delete_transaction,set_category_assigned,move_money,update_category,create_category,rename_payee,create_scheduled_transaction,delete_scheduled_transaction. - OAuth 2.1 authorization with an owner-password login page: PKCE, dynamic client registration and client ID metadata documents, CSRF protection, rate limiting, redirect allowlist, and read-only or read/write access chosen per app.
- Rotating the owner password revokes every connected app.
YNAB_READ_ONLY,YNAB_DEFAULT_PLAN_ID,ALLOWED_REDIRECT_HOSTSandPUBLIC_URLconfiguration.bun run setup,rotate-passwordandset-ynab-tokenhelper scripts, and Deploy to Cloudflare support.- Plain HTTP requests redirect to HTTPS.