mcp-yoto
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@mcp-yotoBuild a bedtime card from my 3 audio files, moon icon per track"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
For parents
What you can do once it's connected:
See every card in your Yoto library (your own MYO cards and your family library) from inside Claude or ChatGPT.
Ask your AI assistant to build a new card — turn an audio file, a story, or a set of tracks into a card on your Yoto.
Add tracks to a card you've already made, without opening the Yoto app.
Search and set pixel-art icons for your cards and chapters.
Check on your family's Yoto players — see what's connected, without being able to control them remotely.
Coming when Yoto allows it: ask what's on a player right now — which card is loaded, battery, volume, nightlight, headphones.
What you can say
Once it's connected, just ask in plain English:
"Make a bedtime card from these three files and give each track a moon icon."
"Show me every card in my Yoto library."
"Add this new song to the 'Car Songs' card."
"Find a pixel-art icon of a dinosaur for chapter two."
"Which of my kids' Yoto players are online right now?"
How sign-in works
You paste one link into your AI app. That takes you to Yoto's own sign-in page — you sign in there, not here. We never see your password. Your Yoto tokens are stored encrypted, and the key is never written to our storage — it's wrapped using your AI app's own token, of which we keep only a hash, so a copy of our database alone decrypts nothing. Two honest caveats: the wrapping method is a fixed constant from the open-source library we use, not a secret unique to this server, so a live client token could decrypt the matching record; and because we run the server, we could in principle change its code to capture tokens in transit. The accurate claim is "nothing readable is stored, and we have no routine means to read it" — not "we are incapable of reading it". You can revoke access at any time from your Yoto account settings, which disconnects this instantly. See PRIVACY.md for the full, plain-English explanation.
🚧 Rebuild in progress (Sept 2026). The command-line version works today; the paste-one-link version for claude.ai / ChatGPT lands in ~2 weeks.
Related MCP server: Obsidian Nexus
For developers
Connect
🚧 Rebuild in progress (September 2026). The
npxroute below works today. The paste-one-link route for claude.ai and ChatGPT goes live once the website address ships — expected September 2026.
claude.ai — Add the Yoto connector (or Settings → Connectors → Add custom connector, prefilled).
ChatGPT — Settings → Connectors → Advanced → Developer mode → Add connector → paste https://mcp-yoto.danpillay87.workers.dev/mcp.
Claude Code:
claude mcp add --transport http yoto https://mcp-yoto.danpillay87.workers.dev/mcpPower users — run it locally today:
npx -y mcp-yotoCursor: Add to Cursor
VS Code: Install in VS Code
Tools
15 tools, all yoto_*, each shipped with a title, description, icon, and all four MCP annotation hints (read-only / destructive / idempotent / open-world):
Tool | Purpose | Key inputs | Read-only |
| Auth state, scopes, token-store kind (CLI), API reachability | – | yes |
| CLI: launch loopback PKCE. Remote: sign in via your client's connector settings |
| no |
| CLI: delete local token. Remote: how to disconnect + revoke at Yoto |
| destructive |
| My MYO cards or family library |
| yes |
| Full card with chapters/tracks |
| yes |
| New MYO card, optional tracks + icon |
| no |
| Rename / reorder / set icons |
| destructive, idempotent |
| Delete a MYO card |
| destructive |
| Upload + transcode → | CLI | no |
| Upload and append to a card |
| no |
| Search the public 16×16 icon catalogue |
| yes |
| Upload a custom 16×16 icon |
| no |
| Family players (view only) | – | yes |
| Device config incl. right-hand-button shortcuts; 403 → friendly |
| yes |
| Live status: card, battery, volume, nightlight, headphones (not yet available — waiting on Yoto); uses a Yoto endpoint marked deprecated (no replacement published yet) |
| yes |
Architecture
One Cloudflare Worker runs the official MCP TypeScript SDK v2 (stateless Streamable HTTP) behind Cloudflare's own @cloudflare/workers-oauth-provider — the reference implementation for remote-MCP auth, so this project writes only the small Yoto-specific upstream handler, not its own OAuth server. The same core (Yoto client + tool definitions) also powers npx mcp-yoto, a local stdio server for direct use from Claude Code, Cursor, or any stdio-based MCP client. Requested scopes are profile offline_access user:content:view user:content:manage user:icons:manage family:library:view family:devices:view — deliberately no family:devices:control or family:devices:manage, which is what keeps this app eligible for Yoto's Verified listing. (family:device-status:view, needed for the still-registered yoto_player_status tool, isn't requested either: a live sign-in attempt with it included was refused outright by Yoto, so it currently can't be granted to third-party apps at all.)
Roadmap
When | What |
Week of 14 Sep | Scaffold + this outreach post (you're reading it) |
Week of 14 Sep | Yoto client + the 15 tools, tested against a mocked API |
Week of 14 Sep |
|
Week of 21 Sep | Remote connector: Cloudflare Worker + Yoto OAuth, live for claude.ai / ChatGPT |
Week of 21 Sep | Security pass, real-client verification, Yoto Verified submission |
Prior art
This isn't the first Yoto MCP server. bperkinspdx/yoto-mcp-server is the origin this project was forked from and is rebuilt on top of. tmcinerney/yoto-mcp is another independent Yoto MCP server on npm, built separately.
Privacy & Security
PRIVACY.md — what we can and can't see, in plain English.
SECURITY.md — how to report a vulnerability, and how token storage is designed.
License
MIT — see LICENSE. Portions originally derived from bperkinspdx/yoto-mcp-server (MIT).
This server cannot be deployed
Maintenance
Related MCP Connectors
Garmin data in Claude & ChatGPT via the Garmin Health API. OAuth sign-in, no password sharing.
WHOOP recovery, strain, sleep and workouts in Claude via official WHOOP OAuth. Free, open source.
- platform7nOAuthtech.p7n
Connect Claude to your Platform7n workspaces — chat, links, and tasks. One-click OAuth.
Build and supervise fleets of agents from Claude Code, Codex or Cursor. Connects over OAuth.
Related MCP Servers
- AlicenseAqualityDmaintenanceConnects AI assistants to a self-hosted Your Spotify instance and Spotify's Web API for deep listening analytics and playback control. It enables users to query unlimited listening history, generate custom Wrapped summaries, and manage playlists through natural language.18Apache 2.0
- FlicenseNot gradedqualityDmaintenanceConnects Claude Desktop to Obsidian vaults to enable reading, writing, searching, and intelligent organization of markdown notes. It features pre-configured structures for personal and family data management through natural conversation.2-
- FlicenseAqualityDmaintenanceEnables audio uploads and MYO card creation for Yoto players directly from the terminal, using OAuth authentication and Warp AI integration.62-
- AlicenseAqualityAmaintenanceConnects a MyToyota or MyLexus Europe account to Claude and other MCP clients, enabling natural-language access to fuel, range, location, trips, health, climate, charging data, and remote commands such as lock, climate, and charging.2629 PyPI1MIT