AirtableCAUTION
Airtable integration for AI-powered applications via Anthropic's Model Context Protocol (MCP)
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://archestra.ai/mcp-catalog/rashidazarang__airtable-mcp) [](https://smithery.ai/server/@rashidazarang/airtable-mcp) [](https://github.com/rashidazarang/airtable-mcp) [](https://www.typescriptlang.org/) [](https://github.com/rashidazarang/airtable-mcp) [](https://github.com/rashidazarang/airtable-mcp) [](https://modelcontextprotocol.io/)
A Model Context Protocol (MCP) server for Airtable with full CRUD operations, schema management, record comments, webhooks, batch operations, governance controls, and AI-powered analytics.
Version 5.1.0 | MCP Protocol 2026-07-28 (stateless core, legacy 2025-era clients still served) | Works with Claude, Codex, Cursor, Windsurf, VS Code, and any MCP client | [](https://www.npmjs.com/package/@rashidazarang/airtable-mcp)
Quick Start (Claude Desktop)
No installation required — just add this to your Claude Desktop config and restart:
macOS: ~/Library/Application Support/Claude/claude_desktop_config.json Windows: %APPDATA%\Claude\claude_desktop_config.json
{
"mcpServers": {
"airtable": {
"command": "npx",
"args": ["-y", "@rashidazarang/airtable-mcp"],
"env": {
"AIRTABLE_TOKEN": "YOUR_AIRTABLE_TOKEN",
"AIRTABLE_BASE_ID": "YOUR_BASE_ID"
}
}
}
}That's it. npx downloads and
ef100a5a20b7OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add airtable-mcp --env AIRTABLE_API_KEY=${AIRTABLE_API_KEY} --env AIRTABLE_API_TOKEN=${AIRTABLE_API_TOKEN} --env AIRTABLE_PERSONAL_ACCESS_TOKEN=${AIRTABLE_PERSONAL_ACCESS_TOKEN} --env AIRTABLE_TOKEN=${AIRTABLE_TOKEN} -- npx -y @rashidazarang/[email protected]{
"mcpServers": {
"airtable-mcp": {
"command": "npx",
"args": [
"-y",
"@rashidazarang/[email protected]"
],
"env": {
"AIRTABLE_API_KEY": "${AIRTABLE_API_KEY}",
"AIRTABLE_API_TOKEN": "${AIRTABLE_API_TOKEN}",
"AIRTABLE_PERSONAL_ACCESS_TOKEN": "${AIRTABLE_PERSONAL_ACCESS_TOKEN}",
"AIRTABLE_TOKEN": "${AIRTABLE_TOKEN}"
}
}
}
}Exposed tools (122)
96 read · 20 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
algorithm | read | Prediction algorithm to use |
analysis_type | read | Type of analysis (trends, statistical, patterns, predictive, anomaly_detection, correlation_matrix) |
analyze_data | read | Advanced AI data analysis with statistical insights, pattern recognition, and predictive modeling |
audit_type | read | Type of quality check |
auto_fix_suggestions | read | Include automated fix suggestions (true/false) |
automation_recommendations | read | Generate intelligent automation suggestions based on workflow patterns and data analysis |
automation_scope | read | Scope (single_table, multi_table, cross_base, external_integration) |
base_overview | read | Overview of the base structure and current workflows |
batch_create_records | write | Create multiple records at once (up to 10) |
batch_delete_records | destructive | Delete multiple records at once (up to 10) |
batch_update_records | write | Update multiple records at once (up to 10) |
batch_upsert_records | write | Update existing records or create new ones based on key fields |
business_context | read | Business domain context (sales, marketing, operations, finance, customer_success) |
clarifying_questions | read | Ask clarifying questions if needed |
complexity_tolerance | read | Acceptable automation complexity (simple, moderate, advanced) |
compliance_requirements | read | Data compliance needs (gdpr, hipaa, sox, none) |
confidence_level | read | Statistical confidence level (0.90, 0.95, 0.99) |
confidence_threshold | read | Minimum confidence for responses |
context_awareness | read | Use context from previous queries |
context_tables | read | Tables that might contain relevant data |
create | write | |
create_base | write | Create a new Airtable base |
create_comment | write | |
create_field | write | Add a new field to an existing table |
create_record | write | Create a new record in a table |
create_report | write | Generate intelligent reports with AI-powered insights, visualizations, and actionable recommendations |
create_table | write | Create a new table in the base |
create_view | write | Create a new view for a table |
create_webhook | write | Create a new webhook for a table |
current_pain_points | read | Known issues or bottlenecks in current workflow |
data_insights | read | Discover hidden patterns, correlations, and business insights using advanced AI algorithms |
data_quality_audit | read | Comprehensive AI-powered data quality assessment with cleansing recommendations |
data_volume | read | Expected data volume (small, medium, large, enterprise) |
date_field | read | Field name for date tracking |
delete_comment | destructive | |
delete_field | destructive | Delete a field from a table (WARNING: This will permanently delete all data in this field) |
delete_record | destructive | Delete a record from a table |
delete_table | destructive | Delete a table (WARNING: This will permanently delete all data) |
delete_webhook | destructive | Delete a webhook |
depth | read | Analysis depth |
describe | read | |
describe_table | read | Get detailed information about a specific table including all fields |
existing_base_id | read | Base ID to analyze existing schema (optional) |
external_factors | read | External factors to consider |
feature_fields | read | Fields to use as predictive features |
field_focus | read | Specific fields to focus the analysis on |
field_mapping | read | Explicit field mapping (JSON) |
focus_area | read | Area to focus automation recommendations |
format_preference | read | Preferred report format |
frequency_patterns | read | How often tasks are performed |
get_base_schema | read | Get complete schema information for a base |
get_record | read | Get a single record by ID |
get_table_views | read | List all views for a specific table |
get_view_metadata | read | Get detailed metadata for a specific view |
get_webhook_payloads | read | Get webhook payload history |
historical_periods | read | Historical periods for training |
include_confidence | read | Include confidence scores for answers (true/false) |
include_confidence_intervals | read | Include confidence intervals |
include_recommendations | read | Include AI-generated actionable recommendations (true/false) |
insight_depth | read | Analysis depth (surface, moderate, deep, comprehensive) |
insight_type | read | Type of insights (correlations, outliers, trends, predictions, segmentation, attribution, churn_analysis) |
integration_capabilities | read | Available integration tools (zapier, make, custom_api, native_automations) |
integration_needs | read | External systems to integrate with |
integration_preferences | read | Preferred integration tools |
list_bases | read | List all accessible Airtable bases |
list_collaborators | read | List collaborators and their permissions for the current base |
list_comments | read | |
list_exceptions | read | |
list_field_types | read | Get a reference of all available Airtable field types and their schemas |
list_governance | read | |
list_records | read | List records from a specific table |
list_shares | read | List shared views and their configurations |
list_tables | read | List all tables in the Airtable base |
list_webhooks | read | List all webhooks for the base |
model_type | read | Prediction model (trend_analysis, seasonal_forecast, regression, classification, time_series) |
natural_language_query | read | Process natural language questions about your data and provide intelligent answers |
optimization_focus | read | Focus area (automation, data_quality, collaboration, performance, integration, user_experience) |
optimization_goal | read | Primary optimization goal |
optimize_workflow | read | AI-powered workflow optimization with automation recommendations and efficiency improvements |
prediction_horizon | read | Forecast period (next_week, next_month, next_quarter, next_year) |
prediction_periods | read | Number of periods to predict |
predictive_analytics | read | Advanced predictive modeling and forecasting using historical Airtable data |
preserve_history | read | Maintain audit trail of changes (true/false) |
priorities | read | Design priorities |
quality_dimensions | read | Quality aspects to check (completeness, accuracy, consistency, validity, uniqueness, timeliness) |
quality_rules | write | Data quality rules to apply during transformation |
query | read | |
question | read | Natural language question about your data |
refresh_webhook | read | Refresh a webhook to extend its expiration |
report_type | read | Type of report (executive_summary, operational_dashboard, analytical_deep_dive, performance_metrics, predictive_forecast) |
response_format | read | Desired response format (narrative, data_summary, visualization_suggestion, action_items) |
scale | read | Expected data scale |
search_records | read | Search records with filtering and sorting |
severity_threshold | read | Minimum severity level to report (low, medium, high, critical) |
smart_data_transformation | read | AI-assisted data transformation, cleaning, and enrichment with intelligent suggestions |
smart_schema_design | read | AI-assisted database schema optimization and field relationship analysis |
source_table | read | Source table for transformation |
stakeholder_level | read | Target audience (executive, manager, analyst, operational) |
status_field | read | Field name representing workflow status/stage |
table | read | Table name or ID to analyze |
tables | read | Comma-separated list of table names to analyze |
target_audience | read | Primary audience for the report |
target_field | read | Field to predict or forecast |
target_format | read | Desired output format or structure |
target_table | read | Target table name or ID (can be new) |
team_size | read | Number of users working with this base |
time_dimension | read | Time field for temporal analysis |
time_period | read | Time period for analysis (last_7_days, last_30_days, last_quarter, year_to_date, custom) |
transformation_goal | read | Goal (normalize, standardize, enrich, cleanse, aggregate, pivot) |
transformation_type | read | Type of transformation |
update | write | |
update_comment | write | |
update_field | write | Update field properties |
update_record | write | Update an existing record |
update_table | write | Update table name or description |
upload_attachment | write | Upload/attach a file from URL to a record |
upsert | read | |
use_case | read | Primary use case (crm, project_management, inventory, content_management, hr, finance) |
validation_rules | write | Validation rules to apply |
whoami | read | |
workflow_description | read | Description of current manual processes |
workflow_type | read | Type of workflow to optimize |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (15)
Dockerfile.node
batch_delete_records, delete_comment, delete_field, delete_record, delete_table, delete_webhook
.eslintrc.js
console.log(`Token: ${TEST_TOKEN.substring(0, 10)}...${TEST_TOKEN.substring(TEST_TOKEN.length - 10)}`);import { AI_PROMPT_TEMPLATES, PromptSchema } from '../../prompt-templates';import { GovernanceError, NotFoundError } from '../../errors';import { AirtableBrainError } from '../../errors';import { AppConfig } from '../../src/typescript/app/config';import { AppContext } from '../../src/typescript/app/context';@modelcontextprotocol/node, @modelcontextprotocol/server, dotenv, zod, zod-to-json-schema, @modelcontextprotocol/client, @types/dotenv, @types/jest
* Airtable Personal Access Token (API Key)
load_dotenv() # load environment variables from .env
curl -fsSL https://raw.githubusercontent.com/rashidazarang/airtable-mcp/main/setup.sh | bash
curl -fsSL https://raw.githubusercontent.com/rashidazarang/airtable-mcp/main/setup.sh | bash -s -- YOUR_AIRTABLE_TOKEN
curl -LsSf https://astral.sh/uv/install.sh | sh
Gates applied: no_behavioural_pass.
ef100a5a20b7full audit observations/trust-audit/mcp-server/rashidazarang__airtable-3.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | ef100a5a20b7 | CAUTION | B | 89 | first audit |
Questions
What is the Airtable MCP server?
Airtable integration for AI-powered applications via Anthropic's Model Context Protocol (MCP)
What tools does Airtable expose?
122 in total: 96 read-only, 20 that write, and 6 that can delete or overwrite (batch_delete_records, delete_comment, delete_field, delete_record, delete_table). Every one is listed on this page with its risk.
Is Airtable safe to connect to an agent?
With care. The audit graded it B (89/100) and found 15 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Airtable need?
It reads AIRTABLE_API_KEY, AIRTABLE_API_TOKEN, AIRTABLE_PERSONAL_ACCESS_TOKEN and AIRTABLE_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Airtable run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as @rashidazarang/airtable-mcp at 5.1.0.
How current is this page?
The grade is for one exact copy of the source (ef100a5a20b7), read on 2026-10-07. The repository is watched and re-audited when it changes.