AirtableBLOCK
Search, create and update Airtable bases, tables, fields, and records using Claude Desktop and MCP (Model Context Protocol) clients
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol server that provides tools for interacting with Airtable's API. This server enables programmatic management of Airtable bases, tables, fields, and records through Claude Desktop or other MCP clients.
This MCP server features a specialized implementation that allows it to build tables in stages, leveraging Claude's agentic capabilities and minimizing the failure rate typically seen in other MCP servers for Airtable when building complex tables. It also includes system prompt and project knowledge markdown files to provide additional guidance for the LLM when leveraging projects in Claude Desktop.
Requirements: Node.js
- Install Node.js (version 18 or higher) and npm from nodejs.org
- Verify installation:
node --version npm --version
⚠️ Important: Before running, make sure to setup your Airtable API key
Obtaining an Airtable API Key
- Log in to your Airtable account at airtable.com
- Create a personal access token at Airtable's Builder Hub
- In the Personal access token section select these scopes:
- data.records:read
- data.records:write
- schema.bases:read
- schema.bases:write
- Select the workspace or bases you want to give access to the personal access token
- Keep this key secure - you'll need it for configuration
Installation
Method 1: Using npx (Recommended)
- Navigate to the Claude configuration directory:
- Windows:
C:\Users\NAME\AppData\Roaming\Claude - macOS:
~/Library/Application Support/Claude/
You can also find these directories inside the Claude Desktop app: Claude Desktop > Settings > Developer > Edit Config
- Create or edit
claude_desktop_config.json:
{
"m74ad4c590fbfOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add airtable-mcp-server --env AIRTABLE_API_KEY=${AIRTABLE_API_KEY} -- npx -y @felores/[email protected]{
"mcpServers": {
"airtable-mcp-server": {
"command": "npx",
"args": [
"-y",
"@felores/[email protected]"
],
"env": {
"AIRTABLE_API_KEY": "${AIRTABLE_API_KEY}"
}
}
}
}Exposed tools (12)
5 read · 6 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
create_field | write | Create a new field in a table |
create_record | write | Create a new record in a table |
create_table | write | Create a new table in a base |
delete_record | destructive | Delete a record from a table |
get_record | read | Get a single record by its ID |
list_bases | read | List all accessible Airtable bases |
list_records | read | List records in a table |
list_tables | read | List all tables in a base |
search_records | read | Search for records in a table |
update_field | write | Update a field in a table |
update_record | write | Update an existing record in a table |
update_table | write | Update a table |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (10)
# Airtable API Documentation
# Field types and cell values
delete_record
axios, @types/node, typescript
4. Select the workspace or bases you want to give access to the personal access token
Passing personal access tokens and OAuth access tokens via the legacy `api_key` URL parameter is not supported.
We currently support using personal access tokens and OAuth access tokens during the authentication process.
[Personal access tokens](https://airtable.com/developers/web/guides/personal-access-tokens) and [OAuth access tokens](https://airtable.com/developers/web/guides/oauth-integrations) can only access API
Check that both you and the token have access to the resource. For example, to access a base using a personal access token,
curl -LsSf https://astral.sh/uv/install.sh | sh
Gates applied: no_behavioural_pass.
74ad4c590fbffull audit observations/trust-audit/mcp-server/felores__airtable.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 74ad4c590fbf | BLOCK | D | 69 | first audit |
Questions
What is the Airtable MCP server?
Search, create and update Airtable bases, tables, fields, and records using Claude Desktop and MCP (Model Context Protocol) clients
What tools does Airtable expose?
12 in total: 5 read-only, 6 that write, and 1 that can delete or overwrite (delete_record). Every one is listed on this page with its risk.
Is Airtable safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Airtable need?
It reads AIRTABLE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Airtable run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @felores/airtable-mcp-server at 0.3.0.
How current is this page?
The grade is for one exact copy of the source (74ad4c590fbf), read on 2026-10-07. The repository is watched and re-audited when it changes.