AirtableCAUTION
🗂️🤖 Airtable Model Context Protocol Server, for allowing AI systems to interact with your Airtable bases
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol server that provides read and write access to Airtable databases. This server enables LLMs to inspect database schemas, then read and write records.
https://github.com/user-attachments/assets/c8285e76-d0ed-4018-94c7-20535db6c944
Installation
Follow the instructions on install-mcp, which generates the right config for your MCP client (Claude Code, Claude Desktop, Cursor, Cline, VS Code, and more).
You'll need an Airtable personal access token — create one here with scopes schema.bases:read and data.records:read (and optionally schema.bases:write, data.records:write, data.recordComments:read, data.recordComments:write), and access to the bases you want to use. It looks something like pat123.abc123 (but longer). Set it as AIRTABLE_API_KEY (replacing the placeholder in the generated config).
Components
Tools
- list_records
- Lists records from a specified Airtable table
- Input parameters:
baseId(string, required): The ID of the Airtable basetableId(string, required): The ID of the table to querymaxRecords(number, optional): Maximum number of records to return. Defaults to 100.filterByFormula(string, optional): Airtable formula to filter records
- search_records
- Search for records containing specific text
- Input parameters:
baseId(string, required): The ID of the Airtable basetableId(string, required): The ID of the table to querysearchTerm(string, required): Text to search for in recordsfieldIds(array, optional): Specific field IDs to search in. If not provided, searches all text-based fields.maxRecords(number, optional): Maximum number of records t
51f1a6481b29OBSERVED · 2026-09-30Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add airtable-mcp-server --env AIRTABLE_API_KEY=${AIRTABLE_API_KEY} --env AIRTABLE_API_KEY=${AIRTABLE_API_KEY} -- npx -y airtable-mcp-server@{{VERSION}}claude mcp add airtable-mcp-server:{{VERSION}} --env AIRTABLE_API_KEY=${AIRTABLE_API_KEY} --env AIRTABLE_API_KEY=${AIRTABLE_API_KEY} -- docker run -i --rm docker.io/domdomegg/airtable-mcp-server:{{VERSION}}:NoneExposed tools (16)
7 read · 8 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
create_comment | write | |
create_field | write | |
create_record | write | |
create_table | write | |
delete_records | destructive | |
describe_table | read | |
get_record | read | |
list_bases | read | |
list_comments | read | |
list_records | read | |
list_tables | read | |
search_records | read | |
update_field | write | |
update_records | write | |
update_table | write | |
upload_attachment | write |
Trust audit
CAUTIONgrade C · trust 80/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (7)
const apiKey = 'pat1.abcdefghijklmnopqrstuvwxyz1234567890abcdefghijklmnopqrstuvwxyz123456';
const apiKey = 'pat1.abcdefghijklmnopqrstuvwxyz1234567890abcdefghijklmnopqrstuvwxyz123456';
const apiKey = 'pat1.too.many.dots.in.key';
const apiKey = 'pat1.validkey1234567890abcdefghijklmnopqrstuvwxyz1234567890abcdefghijk';
const apiKey = 'pat1.validkey1234567890abcdefghijklmnopqrstuvwxyz1234567890abcdefghijk';
delete_records
@modelcontextprotocol/sdk, express, zod, @tsconfig/node-lts, @types/express, @types/node, eslint, eslint-config-domdomegg
Gates applied: no_behavioural_pass.
51f1a6481b29full audit observations/trust-audit/mcp-server/domdomegg__airtable-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-30 | 51f1a6481b29 | CAUTION | C | 80 | first audit |
Questions
What is the Airtable MCP server?
🗂️🤖 Airtable Model Context Protocol Server, for allowing AI systems to interact with your Airtable bases
What tools does Airtable expose?
16 in total: 7 read-only, 8 that write, and 1 that can delete or overwrite (delete_records). Every one is listed on this page with its risk.
Is Airtable safe to connect to an agent?
With care. The audit graded it C (80/100) and found 7 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Airtable need?
It reads AIRTABLE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Airtable run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as airtable-mcp-server at 1.14.0.
How current is this page?
The grade is for one exact copy of the source (51f1a6481b29), read on 2026-09-30. The repository is watched and re-audited when it changes.