Connect an AI assistant

Let ChatGPT, Claude, Cursor or another MCP client read and change your decks and cards - by signing in, or with an API key.

By Peder HellandUpdated October 1, 2026

Yalango speaks MCP, the protocol assistants use to call outside tools. Once connected, you can ask an assistant to add the words from an article to a deck, clean up a card's translation, or tell you what you have due for review - and it does the work in your account directly, instead of handing you a list to copy in.

There are two ways to connect, and they reach exactly the same tools:

  • Sign in - for ChatGPT, Claude.ai and any assistant that supports OAuth. You paste one address, sign in to Yalango, and choose what it may do. Nothing to copy.
  • API key - for Cursor, Claude Code and other clients where you can set a header yourself. The same key works with the REST API.

The endpoint

https://yalango.com/mcp

It is a streamable HTTP MCP server. Both ways of connecting use this one address.

Connect ChatGPT

  1. In ChatGPT, open Settings > Apps & Connectors and turn on developer mode under Advanced settings if your plan requires it.
  2. Choose Create and enter https://yalango.com/mcp as the MCP server URL. Choose OAuth as the authentication.
  3. ChatGPT opens a Yalango page. Sign in if you are not already, tick the permissions you want, and choose Allow.

Connect Claude.ai or Claude Desktop

  1. Open Settings > Connectors and choose Add custom connector.
  2. Enter https://yalango.com/mcp as the URL and leave the advanced settings empty.
  3. Choose Connect, then sign in to Yalango and choose Allow.

Choosing permissions

When an assistant connects by signing in, Yalango shows you which permissions it is asking for. If it does not ask for anything in particular, every permission is listed with only the read permissions ticked - tick the others if you want it to be able to create decks or add cards. You can only grant what is listed, and you can untick anything.

The page will say Yalango has not verified the app. That is true of every app connected this way: the name shown is what the app calls itself. Only allow a connection you started yourself. You need a verified email address to allow one.

Get a key

Create an API key in settings. Tick every scope you want the assistant to have, because scopes decide which tools it can even see:

ScopeTools it unlocks
decks:readlist_decks, get_deck, list_custom_fields
cards:readlist_cards
vocabulary:readsearch_vocabulary, get_review_summary
decks:writecreate_deck, update_deck, create_custom_field, delete_custom_field
cards:writeadd_cards, update_cards, delete_cards

A tool you have not granted is not just refused - it never appears in the assistant's list, so it will not try to use it and will not invent a workaround. If you would rather the assistant could only look and never touch, give it the three read scopes on their own.

The same scopes are the permissions on the sign-in page, so this table applies to both ways of connecting.

Connect Cursor

Add this to ~/.cursor/mcp.json, or to .cursor/mcp.json inside a project:

{
  "mcpServers": {
    "yalango": {
      "url": "https://yalango.com/mcp",
      "headers": {
        "Authorization": "Bearer yal_your_key_here"
      }
    }
  }
}

Restart Cursor, then enable the server under Customize > MCPs.

Connect Claude Code

claude mcp add --transport http yalango https://yalango.com/mcp \
  --header "Authorization: Bearer yal_your_key_here"

Connect another client

Any client that supports a remote MCP server over streamable HTTP will work. If it supports OAuth, point it at https://yalango.com/mcp and it will find the sign-in page on its own. Otherwise have it send the header:

Authorization: Bearer yal_your_key_here

Clients that only speak stdio can bridge to it with mcp-remote.

What the assistant can do

ToolWhat it does
list_decksList your decks, most recently updated first
get_deckRead one deck, its languages and its card count
list_cardsList the cards in a deck
list_custom_fieldsList a deck's custom fields and their ids
search_vocabularyLook a word up across everything you study
get_review_summarySee what is due now and what is coming
create_deckCreate a private deck
update_deckChange a deck's name, description or tags
add_cardsAdd up to 100 cards at once
update_cardsChange up to 100 cards at once
delete_cardsDelete up to 100 cards at once
create_custom_fieldAdd a custom field to a deck
delete_custom_fieldDelete a custom field and its values

Cards added this way are ordinary cards. They get pronunciation audio and pinyin the same way cards added in the web app do, and they enter your review queue on the same schedule.

Things worth knowing

Deleting has no undo. delete_cards takes a card's review history with it, and delete_custom_field clears that field on every card in the deck. Both tools are marked as destructive so a well-behaved client asks you first, but that is the client's choice, not something Yalango can enforce. Read back what it says it is about to delete.

Ask it to check for duplicates. Your vocabulary is shared across decks, so the same word added twice comes up twice in every review session. Assistants are told to call search_vocabulary before adding, which needs vocabulary:read - without that scope it cannot check.

A duplicate can slip in after a timeout. If an add_cards call times out, the cards may have been written anyway. Have the assistant look before it retries.

Languages are fixed once a deck has cards. Getting source and target the wrong way round is the one mistake that cannot be corrected later, so confirm which language is which when it creates a deck.

Limits

MCP calls draw on the same rate limits as the REST API - 60 requests a minute and 5000 a day, with writes weighted more heavily than reads. See Errors and rate limits.

Your plan's deck and card limits still apply. An assistant that hits one gets an error explaining which limit it was, and will normally tell you rather than silently stopping.

Revoking access

Assistants you connected by signing in are listed under Connected apps in Settings > API. Choose Disconnect and the assistant loses access on its next request.

For a key, revoke it in the same place and the connection dies immediately. Since one key is one connection, you can give each assistant its own key and cut off just that one.

An OAuth connection only works with the MCP endpoint. To call the REST API from a script, use an API key.

Next steps

Was this article helpful?
0

Comments

Sign in to join the conversation.