The Vault

Credits & thanks

The Vault is a small, free, fan-made tool. It exists because other people built wonderful things and share them generously. This page lists every service and project the Vault relies on: what it does for you, what (if anything) the Vault sends to it, and where to find it. Thank you all.

Card data, images and prices

Scryfall

Almost everything you see about a card comes from Scryfall: names, rules text, types, mana costs, set information, card images and daily prices. Scryfall's free API and daily bulk data files are the foundation of the Vault.

How we use it: the server downloads Scryfall's daily bulk file once a day to match your cards and record prices. After an import, when prices are older than today, or when you press "Update now", the Vault's server asks Scryfall's API for current prices and card data of your cards; your browser never contacts Scryfall's API. Your browser loads card images and set icons from Scryfall's image servers, so Scryfall sees your IP address for those images, but never your name or account.

Thank you, Scryfall. If the Vault is useful to you, please consider supporting Scryfall.

The Vault isn't produced by or endorsed by Scryfall.

Card prices: TCGplayer, Cardmarket and Cardhoarder

The prices Scryfall publishes come from these marketplaces: US dollar prices from TCGplayer, euro prices from Cardmarket, and MTGO ticket prices from Cardhoarder. They're refreshed about once a day, so treat them as an estimate, not a live quote.

How we use it: indirectly, through Scryfall. The Vault never contacts these marketplaces.

Artists

Every card image is the work of an illustrator, credited under the image wherever the Vault shows one ("Illustrated by …"). Card images are shown whole, without cropping or covering the artist and copyright lines.

Rules, roles and combos

Wizards of the Coast: Comprehensive Rules and Commander Brackets

The rules text the Vault's assistants quote is Wizards' Magic: The Gathering Comprehensive Rules, and the bracket hint for Commander decks follows the Commander Brackets and Game Changers list Wizards publishes. Card rulings are Wizards' too, published through Scryfall.

How we use it: the Vault keeps no copy of the rules. The server reads the current edition from Wizards' site when a rules question is asked (the rules page names the file), shows the rule number, the edition date and a link to Wizards' document with each quote, and nothing about you is sent. The Vault is not approved or endorsed by Wizards.

Scryfall Tagger contributors

Roles such as ramp, card draw, removal and sweepers come from the functional tags that volunteers attach to cards in Scryfall's Tagger project. Scryfall publishes them in its bulk data; the Vault shows each one as "tagged by Scryfall's community Tagger", with its weight, never as a rule. When a card has no Tagger tag, the Vault may show a role it worked out itself from the card's Oracle text, and says so ("computed by the Vault").

How we use it: the server downloads the tag file with Scryfall's other bulk data. Nothing about you is sent.

Thank you to everyone who tags cards.

Commander Spellbook

When you ask which combos a Commander deck contains, the Vault asks Commander Spellbook, a community-built database of Magic combos. Each combo, its description and its steps were written by its community and are shown as theirs, with a link to the combo's own page.

How we use it: only when you ask, the server sends the deck's card names (no account, name or address) to Commander Spellbook's public service and shortens the answer. The Vault keeps no copy of their data. The Vault isn't affiliated with or endorsed by Commander Spellbook.

Thank you to the Commander Spellbook maintainers and everyone who adds combos.

EDHREC

The popularity rank shown for a Commander card is EDHREC's, from the community's deck lists, as Scryfall includes it with each card. Popularity is not power.

How we use it: indirectly, through Scryfall. The Vault never contacts EDHREC.

Limited statistics

17Lands

Per-card win rates and pick positions in the Limited expert's answers come from 17Lands' public data sets, which are licensed under the Creative Commons Attribution 4.0 International licence (CC BY 4.0) (which also states that the data is provided without warranty). They describe Magic Arena games and drafts by people who use the 17Lands tracker, not paper Magic and not every player. The Vault's server reads the game and draft files of a few recent sets once in a while, keeps only per-card counts and throws the files away; the percentages, ranges and sample-size warnings are computed by the Vault, so they can differ from the figures on 17lands.com. Every answer says which set, which format and which date the figures are from, and how many games are behind each rate.

How we use it: the server downloads the files itself, one at a time and only when 17Lands has published a new version; nothing about you is sent to 17Lands. The Vault isn't produced or endorsed by 17Lands.

Thank you, 17Lands. Consider supporting them on Patreon.

Where to buy

Magic Madhouse, Card Kingdom, Cardmarket and the Wizards Store & Event Locator

The "Where to buy" menu on a card you do not own links to the search page of a shop on its own site and to Wizards' official Store & Event Locator, where official retailers are listed. The shops, their names, prices, stock and pages belong to them, and the locator belongs to Wizards of the Coast.

How we use it: plain links only, opened by you in a new tab. The Vault never contacts these sites, shows no price or stock from them, copies nothing from them, and earns nothing from a click. Shops you type in Account are shown as links and never opened by the Vault. The Vault is not affiliated with or endorsed by any of them.

Decks and collections

Archidekt

When you paste an Archidekt deck link on the Decks tab, the Vault reads that public deck from Archidekt and links back to it ("View on Archidekt"). Deck lists and their authors belong to the Archidekt community. Credit and thanks to every brewer.

How we use it: the Vault's server fetches only the public deck you asked for, sending the deck id and nothing about you, and keeps that public deck for ten minutes so repeat reads do not reach Archidekt again (copies are deleted after seven days). It only reads: it never writes, searches or crawls.

Thank you, Archidekt, for keeping public decks open to tools like this one. Support Archidekt on Patreon.

Dragon Shield Card Manager

The Vault imports the CSV file the Dragon Shield app exports, and exports your collection back in the same format, so you can keep scanning and organising in Dragon Shield.

How we use it: only the file you choose to upload. The Vault never connects to your Dragon Shield account. Dragon Shield is a trademark of Arcane Tinmen ApS, and the Vault isn't affiliated with or endorsed by them.

Moxfield

The Vault reads Moxfield's collection CSV export, and writes your collection in the format Moxfield imports, so you can move between the two whenever you like. Decks copied from Moxfield as text work in deck coverage too.

How we use it: only the file you choose to upload, or the file you download. The Vault never connects to Moxfield or your Moxfield account. Moxfield isn't affiliated with or endorsing the Vault.

Signing in

Google, Microsoft, Apple and Facebook

Sign-in is handled by the account you already have, or a passkey, so the Vault never sees or stores a password.

How we use it: only the provider you pick. It tells the Vault your name, e-mail address and an account id, and nothing else.

Where the Vault runs

Vercel, Neon and GitHub

Vercel hosts the app, Neon hosts the database, and GitHub hosts the code and runs the daily price update. Resend delivers the one e-mail the Vault can send: the code that confirms it is you, only when you ask for it. Vercel Web Analytics and Speed Insights count visits and measure page speed anonymously, without cookies and without anything after a page's name in its address. See the privacy notice for exactly what each one handles.

Open source

The Vault is built on open-source software. Thank you to every maintainer and contributor.

ProjectWhat it does hereLicense
mtg-toolkitsreading and writing Dragon Shield, Moxfield and Archidekt files, matching cards to Scryfall, collection changes, decklistsMIT
Reactthe user interfaceMIT
esbuildcompiles the interface code before it reaches your browserMIT
FastAPI & Starlettethe serverMIT / BSD-3-Clause
Pydanticvalidating requestsMIT
SQLAlchemythe database layerMIT
Alembic, Mako, MarkupSafedatabase schema migrationsMIT, MIT, BSD-3-Clause
Psycopgconnecting to Postgres (used unmodified as a library)LGPL-3.0
py_webauthn, cbor2, pyOpenSSL, pyasn1passkeys (WebAuthn)BSD-3-Clause, MIT, Apache-2.0, BSD-2-Clause
Authlib & joserfcsigning in with Google, Microsoft, Apple and FacebookBSD-3-Clause
cryptographysigning and verifying tokensApache-2.0 or BSD-3-Clause
HTTPXtalking to Scryfall and ArchidektBSD-3-Clause
ItsDangeroussigned session cookiesBSD-3-Clause
python-multipartfile uploadsApache-2.0