Back to Directory/Developer Tools

io.github.danpillay87/mcp-yoto

MCP server for Yoto: manage cards, tracks, icons and family devices from any MCP client.

Developer ToolsTypeScriptv0.1.0

For parents

What you can do once it's connected:

  • See every card in your Yoto library (your own MYO cards and your family library) from inside Claude or ChatGPT.
  • Ask your AI assistant to build a new card — turn an audio file, a story, or a set of tracks into a card on your Yoto.
  • Add tracks to a card you've already made, without opening the Yoto app.
  • Search and set pixel-art icons for your cards and chapters.
  • Check on your family's Yoto players — see what's connected, without being able to control them remotely.
  • Coming when Yoto allows it: ask what's on a player right now — which card is loaded, battery, volume, nightlight, headphones.

What you can say

Once it's connected, just ask in plain English:

  • "Make a bedtime card from these three files and give each track a moon icon."
  • "Show me every card in my Yoto library."
  • "Add this new song to the 'Car Songs' card."
  • "Find a pixel-art icon of a dinosaur for chapter two."
  • "Which of my kids' Yoto players are online right now?"

How sign-in works

You paste one link into your AI app. That takes you to Yoto's own sign-in page — you sign in there, not here. We never see your password. Your Yoto tokens are stored encrypted, and the key is never written to our storage — it's wrapped using your AI app's own token, of which we keep only a hash, so a copy of our database alone decrypts nothing. Two honest caveats: the wrapping method is a fixed constant from the open-source library we use, not a secret unique to this server, so a live client token could decrypt the matching record; and because we run the server, we could in principle change its code to capture tokens in transit. The accurate claim is "nothing readable is stored, and we have no routine means to read it" — not "we are incapable of reading it". You can revoke access at any time from your Yoto account settings, which disconnects this instantly. See PRIVACY.md for the full, plain-English explanation.

🚧 Rebuild in progress (Sept 2026). The command-line version works today; the paste-one-link version for claude.ai / ChatGPT lands in ~2 weeks.

For developers

Connect

🚧 Rebuild in progress (September 2026). The npx route below works today. The paste-one-link route for claude.ai and ChatGPT goes live once the website address ships — expected September 2026.

claude.ai — Add the Yoto connector (or Settings → Connectors → Add custom connector, prefilled).

ChatGPT — Settings → Connectors → Advanced → Developer mode → Add connector → paste https://mcp-yoto.danpillay87.workers.dev/mcp.

Claude Code:

claude mcp add --transport http yoto https://mcp-yoto.danpillay87.workers.dev/mcp

Power users — run it locally today:

npx -y mcp-yoto

Tools

15 tools, all yoto_*, each shipped with a title, description, icon, and all four MCP annotation hints (read-only / destructive / idempotent / open-world):

ToolPurposeKey inputsRead-only
yoto_statusAuth state, scopes, token-store kind (CLI), API reachability–yes
yoto_sign_inCLI: launch loopback PKCE. Remote: sign in via your client's connector settingsopenBrowser?no
yoto_sign_outCLI: delete local token. Remote: how to disconnect + revoke at Yotoconfirmdestructive
yoto_list_cardsMy MYO cards or family librarysource: myo|family, limit?, cursor?yes
yoto_get_cardFull card with chapters/trackscardIdyes
yoto_create_cardNew MYO card, optional tracks + icontitle, tracks[]?, iconRef?no
yoto_update_cardRename / reorder / set iconscardId, patchdestructive, idempotent
yoto_delete_cardDelete a MYO cardcardId, confirmdestructive
yoto_upload_audioUpload + transcode → yoto:#shaCLI audioFilePath · Remote audioUrl (https, size-capped, streamed)no
yoto_add_trackUpload and append to a cardcardId, audioFilePath|audioUrl, trackTitle?, iconRef?no
yoto_search_iconsSearch the public 16×16 icon cataloguequery?, tags?, limit?yes
yoto_upload_iconUpload a custom 16×16 iconimagePath|imageUrl, title, autoConvert?no
yoto_list_devicesFamily players (view only)–yes
yoto_get_device_configDevice config incl. right-hand-button shortcuts; 403 → friendly FORBIDDEN_SCOPEdeviceIdyes
yoto_player_statusLive status: card, battery, volume, nightlight, headphones (not yet available — waiting on Yoto); uses a Yoto endpoint marked deprecated (no replacement published yet)deviceId?, refresh?yes

Architecture

One Cloudflare Worker runs the official MCP TypeScript SDK v2 (stateless Streamable HTTP) behind Cloudflare's own @cloudflare/workers-oauth-provider — the reference implementation for remote-MCP auth, so this project writes only the small Yoto-specific upstream handler, not its own OAuth server. The same core (Yoto client + tool definitions) also powers npx mcp-yoto, a local stdio server for direct use from Claude Code, Cursor, or any stdio-based MCP client. Requested scopes are profile offline_access user:content:view user:content:manage user:icons:manage family:library:view family:devices:view — deliberately no family:devices:control or family:devices:manage, which is what keeps this app eligible for Yoto's Verified listing. (family:device-status:view, needed for the still-registered yoto_player_status tool, isn't requested either: a live sign-in attempt with it included was refused outright by Yoto, so it currently can't be granted to third-party apps at all.)

Roadmap

WhenWhat
Week of 14 SepScaffold + this outreach post (you're reading it)
Week of 14 SepYoto client + the 15 tools, tested against a mocked API
Week of 14 Sepnpx mcp-yoto — local sign-in working end to end
Week of 21 SepRemote connector: Cloudflare Worker + Yoto OAuth, live for claude.ai / ChatGPT
Week of 21 SepSecurity pass, real-client verification, Yoto Verified submission

Prior art

This isn't the first Yoto MCP server. bperkinspdx/yoto-mcp-server is the origin this project was forked from and is rebuilt on top of. tmcinerney/yoto-mcp is another independent Yoto MCP server on npm, built separately.

Privacy & Security

  • PRIVACY.md — what we can and can't see, in plain English.
  • SECURITY.md — how to report a vulnerability, and how token storage is designed.

License

MIT — see LICENSE. Portions originally derived from bperkinspdx/yoto-mcp-server (MIT).

Installation

Source-derived launch command. Check the maintainer’s required arguments and credentials before running:

bash
npx -y mcp-yoto

Set up in your AI client

Merge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.

json
{
  "mcpServers": {
    "io-github-danpillay87-mcp-yoto": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-yoto"
      ]
    }
  }
}

Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.

Claude Desktop setup reference

Package

mcp-yotonpm

Compatible MCP Clients

io.github.danpillay87/mcp-yoto works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.

  • Claude Desktop~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.
  • Cursor~/.cursor/mcp.jsonRestart Cursor for changes to take effect.
  • VS Code.vscode/mcp.jsonReload VS Code window for changes to take effect.
  • Windsurf~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect.
  • Claude Code.mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.

Learn More