The Vault
Credits & thanks
The Vault is a small, free, fan-made tool. It exists because other people built wonderful things and share them generously. This page lists every service and project the Vault relies on: what it does for you, what (if anything) the Vault sends to it, and where to find it. Thank you all.
Card data, images and prices
Scryfall
Almost everything you see about a card comes from Scryfall: names, rules text, types, mana costs, set information, card images and daily prices. Scryfall's free API and daily bulk data files are the foundation of the Vault.
How we use it: the server downloads Scryfall's daily bulk file once a day to match your cards and record prices. After an import, when prices are older than today, or when you press "Update now", the Vault's server asks Scryfall's API for current prices and card data of your cards; your browser never contacts Scryfall's API. Your browser loads card images and set icons from Scryfall's image servers, so Scryfall sees your IP address for those images, but never your name or account.
Thank you, Scryfall. If the Vault is useful to you, please consider supporting Scryfall.
The Vault isn't produced by or endorsed by Scryfall.
Card prices: TCGplayer, Cardmarket and Cardhoarder
The prices Scryfall publishes come from these marketplaces: US dollar prices from TCGplayer, euro prices from Cardmarket, and MTGO ticket prices from Cardhoarder. They're refreshed about once a day, so treat them as an estimate, not a live quote.
How we use it: indirectly, through Scryfall. The Vault never contacts these marketplaces.
Artists
Every card image is the work of an illustrator, credited under the image wherever the Vault shows one ("Illustrated by …"). Card images are shown whole, without cropping or covering the artist and copyright lines.
Rules, roles and combos
Wizards of the Coast: Comprehensive Rules and Commander Brackets
The rules text the Vault's assistants quote is Wizards' Magic: The Gathering Comprehensive Rules, and the bracket hint for Commander decks follows the Commander Brackets and Game Changers list Wizards publishes. Card rulings are Wizards' too, published through Scryfall.
How we use it: the Vault keeps no copy of the rules. The server reads the current edition from Wizards' site when a rules question is asked (the rules page names the file), shows the rule number, the edition date and a link to Wizards' document with each quote, and nothing about you is sent. The Vault is not approved or endorsed by Wizards.
Scryfall Tagger contributors
Roles such as ramp, card draw, removal and sweepers come from the functional tags that volunteers attach to cards in Scryfall's Tagger project. Scryfall publishes them in its bulk data; the Vault shows each one as "tagged by Scryfall's community Tagger", with its weight, never as a rule. When a card has no Tagger tag, the Vault may show a role it worked out itself from the card's Oracle text, and says so ("computed by the Vault").
How we use it: the server downloads the tag file with Scryfall's other bulk data. Nothing about you is sent.
Thank you to everyone who tags cards.
Commander Spellbook
When you ask which combos a Commander deck contains, the Vault asks Commander Spellbook, a community-built database of Magic combos. Each combo, its description and its steps were written by its community and are shown as theirs, with a link to the combo's own page.
How we use it: only when you ask, the server sends the deck's card names (no account, name or address) to Commander Spellbook's public service and shortens the answer. The Vault keeps no copy of their data. The Vault isn't affiliated with or endorsed by Commander Spellbook.
Thank you to the Commander Spellbook maintainers and everyone who adds combos.
EDHREC
The popularity rank shown for a Commander card is EDHREC's, from the community's deck lists, as Scryfall includes it with each card. Popularity is not power.
How we use it: indirectly, through Scryfall. The Vault never contacts EDHREC.
Limited statistics
17Lands
Per-card win rates and pick positions in the Limited expert's answers come from 17Lands' public data sets, which are licensed under the Creative Commons Attribution 4.0 International licence (CC BY 4.0) (which also states that the data is provided without warranty). They describe Magic Arena games and drafts by people who use the 17Lands tracker, not paper Magic and not every player. The Vault's server reads the game and draft files of a few recent sets once in a while, keeps only per-card counts and throws the files away; the percentages, ranges and sample-size warnings are computed by the Vault, so they can differ from the figures on 17lands.com. Every answer says which set, which format and which date the figures are from, and how many games are behind each rate.
How we use it: the server downloads the files itself, one at a time and only when 17Lands has published a new version; nothing about you is sent to 17Lands. The Vault isn't produced or endorsed by 17Lands.
Thank you, 17Lands. Consider supporting them on Patreon.
Where to buy
Magic Madhouse, Card Kingdom, Cardmarket and the Wizards Store & Event Locator
The "Where to buy" menu on a card you do not own links to the search page of a shop on its own site and to Wizards' official Store & Event Locator, where official retailers are listed. The shops, their names, prices, stock and pages belong to them, and the locator belongs to Wizards of the Coast.
How we use it: plain links only, opened by you in a new tab. The Vault never contacts these sites, shows no price or stock from them, copies nothing from them, and earns nothing from a click. Shops you type in Account are shown as links and never opened by the Vault. The Vault is not affiliated with or endorsed by any of them.
Decks and collections
Archidekt
When you paste an Archidekt deck link on the Decks tab, the Vault reads that public deck from Archidekt and links back to it ("View on Archidekt"). Deck lists and their authors belong to the Archidekt community. Credit and thanks to every brewer.
How we use it: the Vault's server fetches only the public deck you asked for, sending the deck id and nothing about you, and keeps that public deck for ten minutes so repeat reads do not reach Archidekt again (copies are deleted after seven days). It only reads: it never writes, searches or crawls.
Thank you, Archidekt, for keeping public decks open to tools like this one. Support Archidekt on Patreon.
Dragon Shield Card Manager
The Vault imports the CSV file the Dragon Shield app exports, and exports your collection back in the same format, so you can keep scanning and organising in Dragon Shield.
How we use it: only the file you choose to upload. The Vault never connects to your Dragon Shield account. Dragon Shield is a trademark of Arcane Tinmen ApS, and the Vault isn't affiliated with or endorsed by them.
Moxfield
The Vault reads Moxfield's collection CSV export, and writes your collection in the format Moxfield imports, so you can move between the two whenever you like. Decks copied from Moxfield as text work in deck coverage too.
How we use it: only the file you choose to upload, or the file you download. The Vault never connects to Moxfield or your Moxfield account. Moxfield isn't affiliated with or endorsing the Vault.
Signing in
Google, Microsoft, Apple and Facebook
Sign-in is handled by the account you already have, or a passkey, so the Vault never sees or stores a password.
How we use it: only the provider you pick. It tells the Vault your name, e-mail address and an account id, and nothing else.
Where the Vault runs
Vercel, Neon and GitHub
Vercel hosts the app, Neon hosts the database, and GitHub hosts the code and runs the daily price update. Resend delivers the one e-mail the Vault can send: the code that confirms it is you, only when you ask for it. Vercel Web Analytics and Speed Insights count visits and measure page speed anonymously, without cookies and without anything after a page's name in its address. See the privacy notice for exactly what each one handles.
Open source
The Vault is built on open-source software. Thank you to every maintainer and contributor.
| Project | What it does here | License |
|---|---|---|
| mtg-toolkits | reading and writing Dragon Shield, Moxfield and Archidekt files, matching cards to Scryfall, collection changes, decklists | MIT |
| React | the user interface | MIT |
| esbuild | compiles the interface code before it reaches your browser | MIT |
| FastAPI & Starlette | the server | MIT / BSD-3-Clause |
| Pydantic | validating requests | MIT |
| SQLAlchemy | the database layer | MIT |
| Alembic, Mako, MarkupSafe | database schema migrations | MIT, MIT, BSD-3-Clause |
| Psycopg | connecting to Postgres (used unmodified as a library) | LGPL-3.0 |
| py_webauthn, cbor2, pyOpenSSL, pyasn1 | passkeys (WebAuthn) | BSD-3-Clause, MIT, Apache-2.0, BSD-2-Clause |
| Authlib & joserfc | signing in with Google, Microsoft, Apple and Facebook | BSD-3-Clause |
| cryptography | signing and verifying tokens | Apache-2.0 or BSD-3-Clause |
| HTTPX | talking to Scryfall and Archidekt | BSD-3-Clause |
| ItsDangerous | signed session cookies | BSD-3-Clause |
| python-multipart | file uploads | Apache-2.0 |
The Vault is unofficial Fan Content permitted under the Fan Content Policy. Not approved/endorsed by Wizards. Portions of the materials used are property of Wizards of the Coast. ©Wizards of the Coast LLC. Magic: The Gathering, card names, mana symbols and card images are property of Wizards of the Coast LLC.
Scryfall, 17Lands, Commander Spellbook, Archidekt, Dragon Shield, Moxfield, TCGplayer, Cardmarket, Cardhoarder and the sign-in providers are trademarks of their respective owners. Naming them here is an acknowledgement, not a claim of partnership or endorsement.