mcp-flashcards-cloud
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@mcp-flashcards-cloudadd a flashcard: What's the capital of France? / Paris, topic geography"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
mcp-flashcards-cloud
A hosted, multi-user flashcards MCP server. Each person signs in with OAuth and sees only their own deck. Built on the official MCP Python SDK 2.x.
Status: work in progress. Step 1 of 4 is done: the server, per-user isolation, abuse limits, and an automated test suite that proves one user can't read or change another user's cards. Still to come: real sign-in with an identity provider, deployment, and a full security write-up. See TEST-LOG.md for what has been verified.
How isolation works
Identity comes only from the verified access token. The server takes the token's subject (
sub) after the SDK has checked the token, and keys all data by issuer plus subject. The token's own issuer must match the configured one, so the samesubfrom a different identity provider is a different person. Tool arguments, request metadata and headers are never used as identity, because a client controls all of them.Isolation is enforced in code, not in prompts. Every database query filters on the owner. There is no function that reads or changes a card without naming its owner.
Nothing leaks across users. Card numbers are per user, so they reveal nothing about other decks. A card that belongs to someone else returns exactly the same "No card with id N" error as a card that doesn't exist.
Tokens for other servers are rejected. The server only accepts tokens issued for its own URL (RFC 8707 audience check).
Related MCP server: mymlh-mcp-server
Limits
This is meant to run on free-tier hosting with open sign-up, so one account must not be able to exhaust memory, storage, or the server's attention:
Limit | Value |
Cards per user | 1,000 |
Text stored per user (question + answer + topic) | 200,000 characters |
Question / answer / topic length | 500 / 1,000 / 50 characters |
| 50 by default, 100 at most |
Tool calls per user | 120 per minute |
Tools
Tool | What it does |
| Add a card to your deck |
| List your cards a page at a time; pass |
| Draw the card you've gone longest without reviewing. Returns the question only. |
| Record a right or wrong answer |
| Delete one of your cards |
Run the tests
Requires Python 3.12+.
python -m venv .venv
# Windows: .venv\Scripts\activate macOS/Linux: source .venv/bin/activate
pip install -r requirements-dev.txt
python -m pytest
python tests/run_mutations.py # proves the tests catch deliberately broken codeLicense
MIT - see LICENSE.
This server cannot be deployed
Maintenance
Related MCP Connectors
Read, write, and conversationally review open-source flashcards through split read/write MCP tools.
Create and manage flashcards, tags, and saved decks in Nibomo, and study due cards one question at a time through MCP.
- FlipnemOAuthcom.flipnem
Build and study spaced-repetition flashcards with your agent.
Search, read, cite, create, and safely update a user's private KeepFlash knowledge library.
Related MCP Servers
- FlicenseNot gradedqualityCmaintenanceEnables remote MCP access to math tools with OAuth authentication, deployable on Cloudflare Workers.-
- FlicenseNot gradedqualityDmaintenanceEnables AI assistants to securely access and manage MyMLH user data, including profiles, education, and employment history, through OAuth-authenticated MCP tools.-
- AlicenseNot gradedqualityDmaintenanceEnables MCP-compatible assistants to securely access external systems like Slack through permission-scoped, idempotent tools with tenant isolation, delegated OAuth consent, and an immutable audit trail.MIT
- FlicenseNot gradedqualityCmaintenanceEnables MCP-compatible AI clients to securely access a user's personal context by exposing connector data, starting with recent Spotify listening activity, through per-user OAuth and tools.-