---
name: pp-ynab
description: "Every YNAB feature, plus a local mirror that makes reconciliation, payee trend analysis, and a ready-made ProjectionLab export instant instead of manual. Trigger phrases: `check my YNAB budget`, `what's left in my dining category`, `sync my YNAB balances`, `reconcile my checking account`, `will I overspend this month`, `export my YNAB balances`, `use ynab`, `run ynab`."
author: "mikesnowbie"
license: "Apache-2.0"
argument-hint: "<command> [args] | install cli|mcp"
allowed-tools: "Read Bash"
metadata:
  openclaw:
    requires:
      bins:
        - ynab-pp-cli
    install:
      - kind: go
        bins: [ynab-pp-cli]
        module: github.com/mvanhorn/printing-press-library/library/other/ynab/cmd/ynab-pp-cli
---
<!-- GENERATED FILE — DO NOT EDIT.
     This file is a verbatim mirror of library/other/ynab/SKILL.md,
     regenerated post-merge by tools/generate-skills/. Hand-edits here are
     silently overwritten on the next regen. Edit the library/ source instead.
     See the repository agent guide, section "Generated artifacts: registry.json, cli-skills/". -->

# YNAB — Printing Press CLI

## Prerequisites: Install the CLI

This skill drives the `ynab-pp-cli` binary. **You must verify the CLI is installed before invoking any command from this skill.** If it is missing, install it first:

1. Install via the Printing Press installer. It defaults binaries to `$HOME/.local/bin` on macOS/Linux and `%LOCALAPPDATA%\Programs\PrintingPress\bin` on Windows:
   ```bash
   npx -y @mvanhorn/printing-press-library install ynab --cli-only
   ```
2. Verify: `ynab-pp-cli --version`
3. Ensure the reported install directory is on `$PATH` for the agent/runtime that will invoke this skill.

If the `npx` install fails (no Node, offline, etc.), fall back to a direct Go install (requires Go 1.26.5 or newer). This installs into `$GOPATH/bin` (default `$HOME/go/bin`), so add that directory to `$PATH` instead:

```bash
go install github.com/mvanhorn/printing-press-library/library/other/ynab/cmd/ynab-pp-cli@latest
```

If `--version` reports "command not found" after install, the runtime cannot see the binary directory on `$PATH`. Do not proceed with skill commands until verification succeeds.

This CLI mirrors your budget locally so bank reconciliation and payee spend history become instant, offline, agent-native commands instead of manual math against a live API and a 200-request-per-hour ceiling. It also ships a one-shot export shaped for downstream net-worth tools like ProjectionLab.

## When to Use This CLI

Reach for this CLI for anything touching a YNAB budget: reading balances/categories/transactions, entering or approving transactions, funding categories, and — distinctly — trend/forecast/reconciliation questions that need history the live API doesn't retain.

## Anti-triggers

Do not use this CLI for:
- Do not use this CLI to manage non-YNAB institutions (bank, brokerage, credit union) directly — it only talks to YNAB.
- Do not use this CLI to create YNAB categories, category groups, or payees — the YNAB API itself doesn't support that; use the YNAB app.
- Do not use 'export balances' as a general-purpose account API; it's shaped specifically for downstream net-worth tooling.

## Unique Capabilities

These capabilities aren't available in any other tool for this API.

### Agent-native plumbing
- **`export balances`** — One-shot export of current account balances reshaped into ProjectionLab's expected schema, ready to sync into a net-worth projection tool.

  _Use this to feed another finance tool's import step; it's the direct replacement for a hand-maintained account-mapping script._

  ```bash
  ynab-pp-cli export balances --format projectionlab --agent
  ```

### Local state that compounds
- **`accounts reconcile`** — Diff the local cleared-transaction total against a bank statement balance and surface the transaction(s) most likely responsible for the gap.

  _Use this monthly instead of eyeballing a statement line by line._

  ```bash
  ynab-pp-cli accounts reconcile a1b2c3d4 --statement-balance 1042.17 --agent
  ```
- **`payees profile`** — Aggregated monthly spend stats, average transaction size, and typical categories for a single payee.

  _Use this to understand a recurring payee's spend pattern rather than scanning raw transaction lists._

  ```bash
  ynab-pp-cli payees profile a1b2c3d4 --period 6m --agent
  ```

## Command Reference

**accounts** — The accounts for a plan. Every transaction belongs to an account, and an account is either "on budget", where its activity is categorized and planned, or a tracking account, where only its balance is tracked (see the on_budget flag).

- `ynab-pp-cli accounts create` — Creates a new account
- `ynab-pp-cli accounts get` — Returns all accounts
- `ynab-pp-cli accounts get-by-id` — Returns a single account

**categories** — The categories for a plan, organized into category groups. Category amounts (assigned, activity, available) are specific to a month, and can be read and updated through the month-scoped category endpoints.

- `ynab-pp-cli categories create-category` — Creates a new category
- `ynab-pp-cli categories get` — Returns all categories grouped by category group. Amounts (assigned, activity, available, etc.
- `ynab-pp-cli categories get-category-by-id` — Returns a single category. Amounts (assigned, activity, available, etc.) are specific to the current plan month (UTC).
- `ynab-pp-cli categories update-category` — Update a category

**category-groups** — Manage category groups

- `ynab-pp-cli category-groups create` — Creates a new category group
- `ynab-pp-cli category-groups update` — Update a category group

**money-movement-groups** — Manage money movement groups

- `ynab-pp-cli money-movement-groups <plan_id>` — Returns all money movement groups

**money-movements** — Money movements record money moved between two categories, or between a category and Ready to Assign, within a plan month. Movements performed together as a single action are linked by a money movement group.

- `ynab-pp-cli money-movements <plan_id>` — Returns all money movements

**months** — Each plan contains one or more months, which is where Ready to Assign, Age of Money and category (assigned / activity / available) amounts are available.

- `ynab-pp-cli months get-plan` — Returns all plan months
- `ynab-pp-cli months get-plan-plans` — Returns a single plan month

**payee-locations** — When you enter a transaction and specify a payee on the YNAB mobile apps, the GPS coordinates for that location are stored, with your permission, so that the next time you are in the same place (like the Grocery store) we can pre-populate nearby payees for you!  It’s handy and saves you time. This resource makes these locations available.  Locations will not be available for all payees.

- `ynab-pp-cli payee-locations get` — Returns all payee locations
- `ynab-pp-cli payee-locations get-by-id` — Returns a single payee location

**payees** — The payees for a plan. Transfers between accounts are represented with special transfer payees; a payee with transfer_account_id set is the transfer payee for that account.

- `ynab-pp-cli payees create` — Creates a new payee
- `ynab-pp-cli payees get` — Returns all payees
- `ynab-pp-cli payees get-by-id` — Returns a single payee
- `ynab-pp-cli payees update` — Update a payee

**plans** — Plans are the top-level container for your YNAB data; accounts, categories, payees, and transactions all belong to a plan. Most endpoints require a plan_id, which can be obtained from "Get all plans". Alternatively, "last-used" can be used in place of a plan_id to specify the most recently used plan, and "default" can be used if [default plan selection](https://api.ynab.com/#oauth-default-plan) is enabled.

- `ynab-pp-cli plans get` — Returns plans list with summary information
- `ynab-pp-cli plans get-by-id` — Returns a single plan with all related entities. This resource is effectively a full plan export.

**scheduled-transactions** — The scheduled transactions for a plan; upcoming and recurring transactions that have not yet been entered into an account. Each has a frequency along with the first and next dates it will occur (date_first and date_next).

- `ynab-pp-cli scheduled-transactions create` — Creates a single scheduled transaction (a transaction with a future date).
- `ynab-pp-cli scheduled-transactions delete` — Deletes a scheduled transaction
- `ynab-pp-cli scheduled-transactions get` — Returns all scheduled transactions
- `ynab-pp-cli scheduled-transactions get-by-id` — Returns a single scheduled transaction
- `ynab-pp-cli scheduled-transactions update` — Updates a single scheduled transaction

**settings** — Manage settings

- `ynab-pp-cli settings <plan_id>` — Returns settings for a plan

**transactions** — The transactions for a plan. Transaction amounts are specified in [milliunits format](https://api.ynab.com/#formats). Split transactions are represented with subtransactions, and transfers between accounts are represented with transfer payees.

- `ynab-pp-cli transactions create` — Creates a single transaction or multiple transactions.
- `ynab-pp-cli transactions delete` — Deletes a transaction
- `ynab-pp-cli transactions get` — Returns plan transactions, excluding any pending transactions
- `ynab-pp-cli transactions get-by-id` — Returns a single transaction
- `ynab-pp-cli transactions import` — Imports available transactions on all linked accounts for the given plan.
- `ynab-pp-cli transactions update` — Updates multiple transactions, by `id` or `import_id`.
- `ynab-pp-cli transactions update-plans` — Updates a single transaction

**user** — The currently authenticated user

- `ynab-pp-cli user` — Returns authenticated user information


### Finding the right command

When you know what you want to do but not which command does it, ask the CLI directly:

```bash
ynab-pp-cli which "<capability in your own words>"
```

`which` resolves a natural-language capability query to the best matching command from this CLI's curated feature index. Exit code `0` means at least one match; exit code `2` means no confident match — fall back to `--help` or use a narrower query.

## Recipes

### Feed ProjectionLab

```bash
ynab-pp-cli export balances --format projectionlab --agent --select accounts.name,accounts.balance,accounts.type
```

Narrow the ProjectionLab-shaped export down to just the fields the downstream tool needs, keeping agent context small.

### Batch-approve pending transactions

```bash
ynab-pp-cli transactions get 550e8400-e29b-41d4-a716-446655440000 --type unapproved --json
```

List everything awaiting approval before approving in bulk.

### Reconcile against a bank statement

```bash
ynab-pp-cli accounts reconcile <account-id> --statement-balance 1042.17 --agent
```

Surfaces the exact transaction(s) causing a mismatch instead of scanning line by line.

### Understand a recurring payee

```bash
ynab-pp-cli payees profile <payee-id> --period 6m --agent
```

Shows monthly spend, average transaction size, and typical categories for one payee instead of scanning raw transactions.

## Auth Setup

Uses a YNAB Personal Access Token (Account Settings -> Developer Settings -> New Token in the YNAB web app). Set YNAB_API_TOKEN, or run auth login to store it in the OS keychain.

Run `ynab-pp-cli doctor` to verify setup.

## Agent Mode

Add `--agent` to any command. Expands to: `--json --compact --no-input --no-color --yes`.

- **Pipeable** — JSON on stdout, errors on stderr
- **Filterable** — `--select` keeps a subset of fields. Dotted paths descend into nested structures; arrays traverse element-wise. Critical for keeping context small on verbose APIs:

  ```bash
  ynab-pp-cli accounts get mock-value --agent --select data
  ```
- **Previewable** — `--dry-run` shows the request without sending
- **Offline-friendly** — sync/search commands can use the local SQLite store when available
- **Non-interactive** — never prompts, every input is a flag
- **Explicit retries** — use `--idempotent` only when an already-existing create should count as success, and use `--ignore-missing` only when a missing delete target should count as success

### Response envelope

Commands that read from the local store or the API wrap output in a provenance envelope:

```json
{
  "meta": {"source": "live" | "local", "synced_at": "...", "reason": "..."},
  "results": <data>
}
```

Parse `.results` for data and `.meta.source` to know whether it's live or local. A human-readable `N results (live)` summary is printed to stderr only when stdout is a terminal AND no machine-format flag (`--json`, `--csv`, `--compact`, `--quiet`, `--plain`, `--select`) is set — piped/agent consumers and explicit-format runs get pure JSON on stdout.

## Paths and state

Agents should treat the CLI's path resolver as part of the runtime contract:

- Use `--home <dir>` for one invocation, or set `YNAB_HOME=<dir>` to relocate all four path kinds under one root.
- Use per-kind env vars only when a specific kind must diverge: `YNAB_CONFIG_DIR`, `YNAB_DATA_DIR`, `YNAB_STATE_DIR`, `YNAB_CACHE_DIR`.
- Resolution order is per-kind env var, `--home`, `YNAB_HOME`, XDG (`XDG_CONFIG_HOME`, `XDG_DATA_HOME`, `XDG_STATE_HOME`, `XDG_CACHE_HOME`), then platform defaults.
- `config` contains settings like `config.toml` and profiles. `data` contains `credentials.toml`, `data.db`, cookies, and auth sidecars. `state` contains persisted queries, jobs, and `teach.log`. `cache` contains regenerable HTTP/cache files.
- Stored secrets live in `credentials.toml` under the data dir. Existing legacy `config.toml` secrets are read for compatibility and leave `config.toml` on the first auth write.
- Run `ynab-pp-cli doctor --fail-on warn` to surface path and credential-location warnings. `agent-context` exposes a schema v4 `paths` block for agents that need the resolved dirs.
- For MCP, pass relocation through the MCP host config. The MCP binary does not inherit CLI flags:

  ```json
  {
    "mcpServers": {
      "ynab": {
        "command": "ynab-pp-mcp",
        "env": {
          "YNAB_HOME": "/srv/ynab"
        }
      }
    }
  }
  ```

Fleet precedence: an inherited per-kind env var overrides an explicit `--home` for that kind. Use `YNAB_HOME` or per-kind vars as durable fleet levers, and use `--home` only for a single invocation. Relocation is not reversible by unsetting env vars; move files manually before clearing `YNAB_HOME`, or `doctor` will not find credentials left under the former root.

## Automatic learning

This CLI ships a self-capturing learning loop. The CLI does its own bookkeeping: every invocation is journaled locally, a failed flag followed by a corrected retry auto-derives a `flag_alias` candidate, and a `teach` on a query family without a playbook auto-synthesizes a `playbook_candidate` from the session's journal. Your job is judgment only: `recall` first, act on surfaced candidates, `teach` the final answer, `playbook amend` when you observe a correction. You never record failures by hand.

### Step 1: `recall` before any discovery

Before list/search/drill commands on a new user question, run:

```bash
ynab-pp-cli recall "<user's question>" --agent
```

The response envelope:

```json
{
  "query": "...",
  "normalized": "<normalized form>",
  "query_entities": ["..."],
  "found": true | false,
  "match_score": 0.0,
  "results": [
    { "resource_id": "...", "resource_type": "...", "venue": "...",
      "confidence": 2, "entity_match": "exact|partial|unknown",
      "source": "taught|preseed|pattern", "warnings": ["..."] }
  ],
  "mismatches": [ /* only when --debug-mismatches */ ],
  "warnings": [ /* top-level */ ],
  "candidates": [
    { "id": 12, "class": "flag_alias | playbook_candidate",
      "summary": "...", "sightings": 3, "last_seen": "...",
      "rationale": "...",
      "next_action": ["<trial command>", "ynab-pp-cli learnings confirm 12"] }
  ],
  "playbook": {
    "query_family": "...",
    "playbook": {
      "steps": [ { "cmd": "<command with {slot} substitution>", "purpose": "..." } ],
      "entity_slots": ["$ENTITY"],
      "expected_tool_calls": 3
    },
    "slots_resolved": { "$ENTITY": { "token": "<live token>", "canonical": "<canonical>" } },
    "notes": "<workarounds + gotchas for this query family>"
  },
  "notes": "<duplicate surface for non-playbook callers>"
}
```

Empty-store short-circuit: if the store has no learnings, playbooks, or candidates yet (recall finds nothing and `learnings list` and `learnings candidates` are both empty), skip recall for the rest of this session instead of taxing every query; resume recall-first once something has been taught.

### Step 2: decision tree

Read `candidates`, `playbook`, `notes`, `results[0]`, and warnings in that order:

```
if Candidates present (warnings include "candidates_present"):
    -> candidates are try-then-confirm, never facts. Follow each candidate's
       two-step next_action verbatim: run the trial command first, then run
       `learnings confirm <id>` only after the trial verified the behavior.
       Reject a wrong candidate with `learnings reject <id>`.
    -> NEVER re-teach something recall surfaced as a candidate; confirm or
       reject that candidate instead of teaching a duplicate.
    -> candidates ride alongside playbooks and resource hits, not instead of
       them; continue with the branches below after acting on them.

if Playbook present:
    -> READ Playbook.notes verbatim FIRST (workarounds + gotchas the CLI surface doesn't expose)
    -> replay Playbook.steps in order, substituting Playbook.slots_resolved entries
       for the entity slot tokens. If a step's slot is unresolved, fall back to
       discovery for that step only.
    -> the Playbook's expected_tool_calls is a budget; if you find yourself running
       materially more, record the divergence via `ynab-pp-cli playbook amend`
       at end-of-session.

elif Notes present (no Playbook):
    -> read Notes verbatim before any discovery step; they carry known gotchas
       for this query family even when no structured choreography exists yet.

elif Found AND Results[0].EntityMatch == "exact" AND Results[0].Confidence >= 2:
    -> skip discovery; fetch live data for Results[*].ResourceID in parallel

elif Found AND Results[0].EntityMatch == "partial":
    -> candidate hint, NOT a hit; read the resource title to validate before trusting

elif (any row in Mismatches[] when --debug-mismatches was passed):
    -> treat as cold start; the stored learning is for a different entity
       (different canonical resolved from query_entities)

else:  // Found == false, no playbook, no notes
    -> cold start; run discovery normally; teach the answer afterward (Step 4).
       If the family has no playbook yet, that teach auto-synthesizes a
       playbook candidate from this session's journal - you do not need to
       record one by hand.
```

Playbook and Notes are orthogonal to the per-resource path. A recall response can carry both a Playbook AND a `Results[]` hit - use both: the Playbook tells you which choreography to run; the resource hits short-circuit specific steps. Default to skipping `mismatches`; pass `--debug-mismatches` only when investigating cold-start surprises.

Candidate judgment details: `learnings confirm <id>` prints the candidate's full payload before materializing it - check that the printed payload matches the behavior you verified. `learnings reject <id>` tombstones the derivation signature so the same candidate does not resurface. The envelope carries only the few candidates worth acting on now; `ynab-pp-cli learnings candidates` lists the full open set.

Graceful degradation: if `learnings confirm` is an unknown command, you are driving an older binary - ignore the candidates guidance and follow the rest of the protocol.

### Step 3: always read `warnings`

- `low_confidence`: row exists at `confidence<2`. Treat a