Connect an AI assistant
Let ChatGPT, Claude, Cursor or another MCP client read and change your decks and cards - by signing in, or with an API key.
Yalango speaks MCP, the protocol assistants use to call outside tools. Once connected, you can ask an assistant to add the words from an article to a deck, clean up a card's translation, or tell you what you have due for review - and it does the work in your account directly, instead of handing you a list to copy in.
There are two ways to connect, and they reach exactly the same tools:
- Sign in - for ChatGPT, Claude.ai and any assistant that supports OAuth. You paste one address, sign in to Yalango, and choose what it may do. Nothing to copy.
- API key - for Cursor, Claude Code and other clients where you can set a header yourself. The same key works with the REST API.
The endpoint
https://yalango.com/mcp
It is a streamable HTTP MCP server. Both ways of connecting use this one address.
Connect ChatGPT
- In ChatGPT, open Settings > Apps & Connectors and turn on developer mode under Advanced settings if your plan requires it.
- Choose Create and enter
https://yalango.com/mcpas the MCP server URL. Choose OAuth as the authentication. - ChatGPT opens a Yalango page. Sign in if you are not already, tick the permissions you want, and choose Allow.
Connect Claude.ai or Claude Desktop
- Open Settings > Connectors and choose Add custom connector.
- Enter
https://yalango.com/mcpas the URL and leave the advanced settings empty. - Choose Connect, then sign in to Yalango and choose Allow.
Choosing permissions
When an assistant connects by signing in, Yalango shows you which permissions it is asking for. If it does not ask for anything in particular, every permission is listed with only the read permissions ticked - tick the others if you want it to be able to create decks or add cards. You can only grant what is listed, and you can untick anything.
The page will say Yalango has not verified the app. That is true of every app connected this way: the name shown is what the app calls itself. Only allow a connection you started yourself. You need a verified email address to allow one.
Get a key
Create an API key in settings. Tick every scope you want the assistant to have, because scopes decide which tools it can even see:
| Scope | Tools it unlocks |
|---|---|
decks:read | list_decks, get_deck, list_custom_fields |
cards:read | list_cards |
vocabulary:read | search_vocabulary, get_review_summary |
decks:write | create_deck, update_deck, create_custom_field, delete_custom_field |
cards:write | add_cards, update_cards, delete_cards |
A tool you have not granted is not just refused - it never appears in the assistant's list, so it will not try to use it and will not invent a workaround. If you would rather the assistant could only look and never touch, give it the three read scopes on their own.
The same scopes are the permissions on the sign-in page, so this table applies to both ways of connecting.
Connect Cursor
Add this to ~/.cursor/mcp.json, or to .cursor/mcp.json inside a project:
{
"mcpServers": {
"yalango": {
"url": "https://yalango.com/mcp",
"headers": {
"Authorization": "Bearer yal_your_key_here"
}
}
}
}
Restart Cursor, then enable the server under Customize > MCPs.
Connect Claude Code
claude mcp add --transport http yalango https://yalango.com/mcp \
--header "Authorization: Bearer yal_your_key_here"
Connect another client
Any client that supports a remote MCP server over streamable HTTP will work. If it supports OAuth, point it at https://yalango.com/mcp and it will find the sign-in page on its own. Otherwise have it send the header:
Authorization: Bearer yal_your_key_here
Clients that only speak stdio can bridge to it with mcp-remote.
What the assistant can do
| Tool | What it does |
|---|---|
list_decks | List your decks, most recently updated first |
get_deck | Read one deck, its languages and its card count |
list_cards | List the cards in a deck |
list_custom_fields | List a deck's custom fields and their ids |
search_vocabulary | Look a word up across everything you study |
get_review_summary | See what is due now and what is coming |
create_deck | Create a private deck |
update_deck | Change a deck's name, description or tags |
add_cards | Add up to 100 cards at once |
update_cards | Change up to 100 cards at once |
delete_cards | Delete up to 100 cards at once |
create_custom_field | Add a custom field to a deck |
delete_custom_field | Delete a custom field and its values |
Cards added this way are ordinary cards. They get pronunciation audio and pinyin the same way cards added in the web app do, and they enter your review queue on the same schedule.
Things worth knowing
Deleting has no undo. delete_cards takes a card's review history with it, and delete_custom_field clears that field on every card in the deck. Both tools are marked as destructive so a well-behaved client asks you first, but that is the client's choice, not something Yalango can enforce. Read back what it says it is about to delete.
Ask it to check for duplicates. Your vocabulary is shared across decks, so the same word added twice comes up twice in every review session. Assistants are told to call search_vocabulary before adding, which needs vocabulary:read - without that scope it cannot check.
A duplicate can slip in after a timeout. If an add_cards call times out, the cards may have been written anyway. Have the assistant look before it retries.
Languages are fixed once a deck has cards. Getting source and target the wrong way round is the one mistake that cannot be corrected later, so confirm which language is which when it creates a deck.
Limits
MCP calls draw on the same rate limits as the REST API - 60 requests a minute and 5000 a day, with writes weighted more heavily than reads. See Errors and rate limits.
Your plan's deck and card limits still apply. An assistant that hits one gets an error explaining which limit it was, and will normally tell you rather than silently stopping.
Revoking access
Assistants you connected by signing in are listed under Connected apps in Settings > API. Choose Disconnect and the assistant loses access on its next request.
For a key, revoke it in the same place and the connection dies immediately. Since one key is one connection, you can give each assistant its own key and cut off just that one.
An OAuth connection only works with the MCP endpoint. To call the REST API from a script, use an API key.