Last updated: October 9, 2026
Storage and Cloudflare: the connector stores your YNAB OAuth access and refresh tokens, YNAB user ID, MCP client ID, consent credential ID, read-only/write choice, and operation/undo journals of connector-performed writes (operation and transaction IDs, relevant before/after field values, and recovery status). Credentials and journals are separate for each consent. Cloudflare hosts the Worker and provides the Durable Objects and Workers KV storage used by the connector. Tokens and journals are encrypted with AES-GCM before they enter durable storage. Older shared encrypted records remain inaccessible in KV until deletion.
Retention: encrypted token records, authorization grants, and undo entries are retained until you use the deletion page. Temporary OAuth consent and callback state expires automatically within 10 minutes.
Data delivery: when you make an MCP request, the connector exchanges OAuth and budget data with YNAB (including app.ynab.com for sign-in and api.ynab.com for API requests) and returns the result to the MCP client you connected. That client may receive budget data returned by the tool; its handling is governed by its own terms and privacy policy.
Session memory: ordinary budget results may be cached temporarily for read performance, and expiring write previews hold the proposed changes in the MCP session's memory. Writes re-read relevant state. These ordinary caches and previews are not written to durable storage.
What it does not do: store your YNAB password, sell your data, use budget data for advertising, or persist ordinary budget results outside the encrypted credential and operation/undo records described above.
Deletion: use the deletion page to revoke this connector's grants and erase stored tokens and journal entries. You can also revoke the application from your YNAB account settings.
A non-financial deletion marker remains to invalidate earlier pending consent forms. An authorization already in progress can briefly leave an unusable provider grant while revocation propagates; the removed credential cannot make API requests.
Contact: file an issue at github.com/oliverames/ynab-mcp-server.