Atlas / MCP servers / rashidazarang / Airtable

AirtableCAUTION

mcp/rashidazarang/airtable-3

Airtable integration for AI-powered applications via Anthropic's Model Context Protocol (MCP)

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
122 96r · 20w · 6d
Transport
streamable-http
License
MIT
Stars
87
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://archestra.ai/mcp-catalog/rashidazarang__airtable-mcp) [](https://smithery.ai/server/@rashidazarang/airtable-mcp) [](https://github.com/rashidazarang/airtable-mcp) [](https://www.typescriptlang.org/) [](https://github.com/rashidazarang/airtable-mcp) [](https://github.com/rashidazarang/airtable-mcp) [](https://modelcontextprotocol.io/)

A Model Context Protocol (MCP) server for Airtable with full CRUD operations, schema management, record comments, webhooks, batch operations, governance controls, and AI-powered analytics.

Version 5.1.0 | MCP Protocol 2026-07-28 (stateless core, legacy 2025-era clients still served) | Works with Claude, Codex, Cursor, Windsurf, VS Code, and any MCP client | [](https://www.npmjs.com/package/@rashidazarang/airtable-mcp)

Quick Start (Claude Desktop)

No installation required — just add this to your Claude Desktop config and restart:

macOS: ~/Library/Application Support/Claude/claude_desktop_config.json Windows: %APPDATA%\Claude\claude_desktop_config.json

{
"mcpServers": {
"airtable": {
"command": "npx",
"args": ["-y", "@rashidazarang/airtable-mcp"],
"env": {
"AIRTABLE_TOKEN": "YOUR_AIRTABLE_TOKEN",
"AIRTABLE_BASE_ID": "YOUR_BASE_ID"
}
}
}
}

That's it. npx downloads and

Read from source at commit ef100a5a20b7OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add airtable-mcp --env AIRTABLE_API_KEY=${AIRTABLE_API_KEY} --env AIRTABLE_API_TOKEN=${AIRTABLE_API_TOKEN} --env AIRTABLE_PERSONAL_ACCESS_TOKEN=${AIRTABLE_PERSONAL_ACCESS_TOKEN} --env AIRTABLE_TOKEN=${AIRTABLE_TOKEN} -- npx -y @rashidazarang/[email protected]
claude-desktop
{
  "mcpServers": {
    "airtable-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@rashidazarang/[email protected]"
      ],
      "env": {
        "AIRTABLE_API_KEY": "${AIRTABLE_API_KEY}",
        "AIRTABLE_API_TOKEN": "${AIRTABLE_API_TOKEN}",
        "AIRTABLE_PERSONAL_ACCESS_TOKEN": "${AIRTABLE_PERSONAL_ACCESS_TOKEN}",
        "AIRTABLE_TOKEN": "${AIRTABLE_TOKEN}"
      }
    }
  }
}
03

Exposed tools (122)

96 read · 20 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
algorithmreadPrediction algorithm to use
analysis_typereadType of analysis (trends, statistical, patterns, predictive, anomaly_detection, correlation_matrix)
analyze_datareadAdvanced AI data analysis with statistical insights, pattern recognition, and predictive modeling
audit_typereadType of quality check
auto_fix_suggestionsreadInclude automated fix suggestions (true/false)
automation_recommendationsreadGenerate intelligent automation suggestions based on workflow patterns and data analysis
automation_scopereadScope (single_table, multi_table, cross_base, external_integration)
base_overviewreadOverview of the base structure and current workflows
batch_create_recordswriteCreate multiple records at once (up to 10)
batch_delete_recordsdestructiveDelete multiple records at once (up to 10)
batch_update_recordswriteUpdate multiple records at once (up to 10)
batch_upsert_recordswriteUpdate existing records or create new ones based on key fields
business_contextreadBusiness domain context (sales, marketing, operations, finance, customer_success)
clarifying_questionsreadAsk clarifying questions if needed
complexity_tolerancereadAcceptable automation complexity (simple, moderate, advanced)
compliance_requirementsreadData compliance needs (gdpr, hipaa, sox, none)
confidence_levelreadStatistical confidence level (0.90, 0.95, 0.99)
confidence_thresholdreadMinimum confidence for responses
context_awarenessreadUse context from previous queries
context_tablesreadTables that might contain relevant data
createwrite
create_basewriteCreate a new Airtable base
create_commentwrite
create_fieldwriteAdd a new field to an existing table
create_recordwriteCreate a new record in a table
create_reportwriteGenerate intelligent reports with AI-powered insights, visualizations, and actionable recommendations
create_tablewriteCreate a new table in the base
create_viewwriteCreate a new view for a table
create_webhookwriteCreate a new webhook for a table
current_pain_pointsreadKnown issues or bottlenecks in current workflow
data_insightsreadDiscover hidden patterns, correlations, and business insights using advanced AI algorithms
data_quality_auditreadComprehensive AI-powered data quality assessment with cleansing recommendations
data_volumereadExpected data volume (small, medium, large, enterprise)
date_fieldreadField name for date tracking
delete_commentdestructive
delete_fielddestructiveDelete a field from a table (WARNING: This will permanently delete all data in this field)
delete_recorddestructiveDelete a record from a table
delete_tabledestructiveDelete a table (WARNING: This will permanently delete all data)
delete_webhookdestructiveDelete a webhook
depthreadAnalysis depth
describeread
describe_tablereadGet detailed information about a specific table including all fields
existing_base_idreadBase ID to analyze existing schema (optional)
external_factorsreadExternal factors to consider
feature_fieldsreadFields to use as predictive features
field_focusreadSpecific fields to focus the analysis on
field_mappingreadExplicit field mapping (JSON)
focus_areareadArea to focus automation recommendations
format_preferencereadPreferred report format
frequency_patternsreadHow often tasks are performed
get_base_schemareadGet complete schema information for a base
get_recordreadGet a single record by ID
get_table_viewsreadList all views for a specific table
get_view_metadatareadGet detailed metadata for a specific view
get_webhook_payloadsreadGet webhook payload history
historical_periodsreadHistorical periods for training
include_confidencereadInclude confidence scores for answers (true/false)
include_confidence_intervalsreadInclude confidence intervals
include_recommendationsreadInclude AI-generated actionable recommendations (true/false)
insight_depthreadAnalysis depth (surface, moderate, deep, comprehensive)
insight_typereadType of insights (correlations, outliers, trends, predictions, segmentation, attribution, churn_analysis)
integration_capabilitiesreadAvailable integration tools (zapier, make, custom_api, native_automations)
integration_needsreadExternal systems to integrate with
integration_preferencesreadPreferred integration tools
list_basesreadList all accessible Airtable bases
list_collaboratorsreadList collaborators and their permissions for the current base
list_commentsread
list_exceptionsread
list_field_typesreadGet a reference of all available Airtable field types and their schemas
list_governanceread
list_recordsreadList records from a specific table
list_sharesreadList shared views and their configurations
list_tablesreadList all tables in the Airtable base
list_webhooksreadList all webhooks for the base
model_typereadPrediction model (trend_analysis, seasonal_forecast, regression, classification, time_series)
natural_language_queryreadProcess natural language questions about your data and provide intelligent answers
optimization_focusreadFocus area (automation, data_quality, collaboration, performance, integration, user_experience)
optimization_goalreadPrimary optimization goal
optimize_workflowreadAI-powered workflow optimization with automation recommendations and efficiency improvements
prediction_horizonreadForecast period (next_week, next_month, next_quarter, next_year)
prediction_periodsreadNumber of periods to predict
predictive_analyticsreadAdvanced predictive modeling and forecasting using historical Airtable data
preserve_historyreadMaintain audit trail of changes (true/false)
prioritiesreadDesign priorities
quality_dimensionsreadQuality aspects to check (completeness, accuracy, consistency, validity, uniqueness, timeliness)
quality_ruleswriteData quality rules to apply during transformation
queryread
questionreadNatural language question about your data
refresh_webhookreadRefresh a webhook to extend its expiration
report_typereadType of report (executive_summary, operational_dashboard, analytical_deep_dive, performance_metrics, predictive_forecast)
response_formatreadDesired response format (narrative, data_summary, visualization_suggestion, action_items)
scalereadExpected data scale
search_recordsreadSearch records with filtering and sorting
severity_thresholdreadMinimum severity level to report (low, medium, high, critical)
smart_data_transformationreadAI-assisted data transformation, cleaning, and enrichment with intelligent suggestions
smart_schema_designreadAI-assisted database schema optimization and field relationship analysis
source_tablereadSource table for transformation
stakeholder_levelreadTarget audience (executive, manager, analyst, operational)
status_fieldreadField name representing workflow status/stage
tablereadTable name or ID to analyze
tablesreadComma-separated list of table names to analyze
target_audiencereadPrimary audience for the report
target_fieldreadField to predict or forecast
target_formatreadDesired output format or structure
target_tablereadTarget table name or ID (can be new)
team_sizereadNumber of users working with this base
time_dimensionreadTime field for temporal analysis
time_periodreadTime period for analysis (last_7_days, last_30_days, last_quarter, year_to_date, custom)
transformation_goalreadGoal (normalize, standardize, enrich, cleanse, aggregate, pivot)
transformation_typereadType of transformation
updatewrite
update_commentwrite
update_fieldwriteUpdate field properties
update_recordwriteUpdate an existing record
update_tablewriteUpdate table name or description
upload_attachmentwriteUpload/attach a file from URL to a record
upsertread
use_casereadPrimary use case (crm, project_management, inventory, content_management, hr, finance)
validation_ruleswriteValidation rules to apply
whoamiread
workflow_descriptionreadDescription of current manual processes
workflow_typereadType of workflow to optimize
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (15)

MEDIUMInventory / provenance · inv.binary · CWE-1104
docker/Dockerfile.node
Dockerfile.node
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
batch_delete_records, delete_comment, delete_field, delete_record, delete_table, delete_webhook
Why it matters. 6 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.eslintrc.js
.eslintrc.js
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
tests/test_mcp_comprehensive.js:71
console.log(`Token: ${TEST_TOKEN.substring(0, 10)}...${TEST_TOKEN.substring(TEST_TOKEN.length - 10)}`);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/typescript/app/prompts/index.ts:3
import { AI_PROMPT_TEMPLATES, PromptSchema } from '../../prompt-templates';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/typescript/app/tools/describe.ts:11
import { GovernanceError, NotFoundError } from '../../errors';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/typescript/app/tools/handleError.ts:1
import { AirtableBrainError } from '../../errors';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/e2e/harness.ts:3
import { AppConfig } from '../../src/typescript/app/config';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/e2e/harness.ts:4
import { AppContext } from '../../src/typescript/app/context';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/node, @modelcontextprotocol/server, dotenv, zod, zod-to-json-schema, @modelcontextprotocol/client, @types/dotenv, @types/jest
Why it matters. 20 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/guides/INSTALLATION.md:39
* Airtable Personal Access Token (API Key)
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
examples/building-mcp.md:3352
load_dotenv()  # load environment variables from .env
Why it matters. asks the agent to read credentials
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:51
curl -fsSL https://raw.githubusercontent.com/rashidazarang/airtable-mcp/main/setup.sh | bash
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:59
curl -fsSL https://raw.githubusercontent.com/rashidazarang/airtable-mcp/main/setup.sh | bash -s -- YOUR_AIRTABLE_TOKEN
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
examples/building-mcp.md:4333
curl -LsSf https://astral.sh/uv/install.sh | sh

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha ef100a5a20b7full audit observations/trust-audit/mcp-server/rashidazarang__airtable-3.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07ef100a5a20b7CAUTIONB89first audit
06

Questions

What is the Airtable MCP server?

Airtable integration for AI-powered applications via Anthropic's Model Context Protocol (MCP)

What tools does Airtable expose?

122 in total: 96 read-only, 20 that write, and 6 that can delete or overwrite (batch_delete_records, delete_comment, delete_field, delete_record, delete_table). Every one is listed on this page with its risk.

Is Airtable safe to connect to an agent?

With care. The audit graded it B (89/100) and found 15 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Airtable need?

It reads AIRTABLE_API_KEY, AIRTABLE_API_TOKEN, AIRTABLE_PERSONAL_ACCESS_TOKEN and AIRTABLE_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Airtable run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as @rashidazarang/airtable-mcp at 5.1.0.

How current is this page?

The grade is for one exact copy of the source (ef100a5a20b7), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement