Airtable

by Formagrid Inc (Airtable) HTTP API in Spreadsheets & operational tables

Hosted Agent-ready

Formagrid Inc · airtable.com since 2003 · status page · who's behind it

Airtable is a hosted database of typed records organised in bases, tables and views. Agents reach it through a REST Web API and an official hosted MCP server, using personal access tokens or OAuth.

Good for Teams that already keep operational data in Airtable and want an agent to read, filter and update typed records or build bases through MCP.

Is this your product? Claim this listing or verify it

Assessment. Tokens are limited by scope and by base, and the official MCP server at mcp.airtable.com covers records, schema, interfaces and automations in 40 tools. The REST API allows 5 requests a second per base with a 30-second lockout after a 429, writes take 10 records a call, and the Free plan stops at 1,000 calls a month.

Facts

Transport
HTTP, Streamable HTTP
Endpoint
https://api.airtable.com
Auth
OAuth or key
Pricing
Freemium · $20 / seat-mo
x402
No
Licence
Proprietary service under Airtable's Terms of Service and Developer Terms. The airtable.js client and the MCP CLI on GitHub are MIT
Tools exposed
40
Packages
npm airtable
npm @airtable/mcp-cli
MCP registry
com.airtable/mcp
llms.txt
published
Last release
GitHub stars
2.2k
npm / week
569k
Surfaces graded
REST Web API at https://api.airtable.com/v0 and the official hosted MCP server at https://mcp.airtable.com/mcp
Free tier
Free plan, 1,000 API calls a month per workspace, 1,000 records per base, 1 GB of attachments per base, up to 5 editors
Rate limits
5 requests a second per base, 50 a second per user or service account across personal access tokens. A 429 blocks requests for 30 seconds (vendor's figures)
Batch size
Up to 10 records per create, update or delete request, 100 records per list page, 10,000 CSV rows per Sync API request
Auth and scopes
Personal access tokens or OAuth with PKCE. Basic scopes include data.records:read, data.records:write, schema.bases:read, schema.bases:write, data.recordComments:read and write, workspacesAndBases:read and webhook:manage. Each token is also limited to chosen bases or workspaces
Read and write
Records (list, get, create, update, upsert, delete), comments, attachments, tables and fields (create and update), base schema, views, webhooks
Filtering
filterByFormula, sort, view, fields, pageSize and maxRecords on list records, with a POST variant for long formulas
MCP server
Hosted, streamable HTTP, 40 documented tools. OAuth with dynamic client registration or a personal access token. Automations are saved as drafts and stay off until a person turns them on
Change events
Webhooks on a base, table or view with an HMAC-signed ping and a payload list read by cursor. Token-created webhooks expire after 7 days unless refreshed
Plan gates
Base data endpoints on every plan except views. SCIM from Business. Audit logs, change events and the Enterprise API on Enterprise Scale
SDKs
Official airtable.js for JavaScript (v0.12.2, 16 August 2023, MIT). Python, Ruby and .NET clients are community-built. @airtable/mcp-cli v0.2.9 (7 August 2026), marked experimental
Deprecations
Guidelines aim for 12 months' notice on the Web API and Enterprise API, and Airtable reserves the right to deprecate without notice
Certifications
SOC 2 Type 2, ISO/IEC 27001:2022, ISO/IEC 27701:2019, HIPAA and TX-RAMP Level 2 per the trust page. Bug bounty on HackerOne
SLA
99.9 per cent monthly uptime for Enterprise and Enterprise Scale plans, and some Business customers on a master subscription agreement
Open source
No. The JavaScript client and the MCP CLI are public under MIT

Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown

Strengths

  • Personal access tokens and OAuth grants are limited by scope and by base or workspace, and the legacy api_key URL parameter is refused
  • Official hosted MCP server at https://mcp.airtable.com/mcp, open to every plan and listed in the MCP registry as com.airtable/mcp
  • Markdown copy of every API reference page, indexed by llms.txt files under airtable.com/developers
  • List records takes fields, pageSize, maxRecords, view, sort and filterByFormula, so responses can be sized
  • Published deprecation guidelines aim for 12 months' notice on the Web API, and no deprecation was listed as upcoming on 8 October 2026

Weaknesses

  • 5 requests a second per base, and a 429 blocks further requests for 30 seconds
  • Create, update and delete calls take at most 10 records each
  • Free plan allows 1,000 API calls a month per workspace and 1,000 records per base
  • No OpenAPI description was found in the reviewed documentation
  • The only official client library is airtable.js, last released as v0.12.2 on 16 August 2023

Before you call it notes for agents

  1. Create a personal access token with only the scopes needed and add each base to it. A token with no base added sees nothing
  2. Stay under 5 requests a second per base. After a 429, wait 30 seconds before the next call
  3. Send writes in batches of 10 records, and use performUpsert with fieldsToMergeOn so a repeated call updates instead of duplicating
  4. Use table and field IDs, not names, and set returnFieldsByFieldId so a rename doesn't break the call
  5. POST to /listRecords when a filterByFormula would push the URL past 16,000 characters

Who's behind it provenance 100/100

  • Legal entity namedFormagrid Inc (doing business as Airtable)20/20
  • Domain ageairtable.com, registered 2003-12-10 (22 years)15/15
  • Endpoint on the vendor's domainapi.airtable.com15/15
  • Terms of serviceread, states 7 of the 7 things a reader expects10/10
  • Privacy policyread, states 8 of the 8 things a reader expects10/10
  • Status pagestatus.airtable.com10/10
  • Changelogpublished10/10
  • security.txtvalid10/10

Terms and privacy, as read

Terms of service dated 2024-05-31, states 7 of 7, 2 to know

TL;DR Dated 2024-05-31. States all 7 things a reader expects. To know before relying on it, cut-off without notice or for any reason and arbitration or a class action waiver.

Says access can be ended without notice or for any reason
We may permanently or temporarily terminate or suspend your access to our Services without notice or liability, without cause or for any reason, including if in our sole discretion you violate any provision of these Terms.

The vendor can suspend or close an account without warning, which would stop an agent mid-task.

Requires arbitration or waives class actions
…16.2 OR UNLESS YOU OPT OUT PURSUANT TO THE INSTRUCTIONS IN SECTION 16.2, THE EXCLUSIVE USE OF FINAL AND BINDING ARBITRATION ON AN INDIVIDUAL BASIS ONLY TO RESOLVE DISPUTES, RATHER THAN JURY TRIALS OR CLASS, COLLECTIVE, PRIVATE ATTORNEY GENERAL OR REPRESENTATIVE ACTIONS OR PROCEEDINGS.

Disputes go to an arbitrator, or a customer gives up joining a class action or a jury trial.

Gives the date it was last updated Last updated 2024-05-31
Last Updated: May 31, 2024

Without a date nobody can tell which version they agreed to.

Names the governing law or courts The law of the State of California
These Terms will be governed by the internal substantive laws of the State of California, without respect to its conflict of laws principles.

Says where a dispute would be heard and under whose law.

States a limit on its liability Capped at the fees paid in the 12 months before the claim
IN NO EVENT WILL WE OR OUR AFFILIATES, AGENTS, SUPPLIERS, OR LICENSORS (OR OUR OR THEIR EMPLOYEES, CONTRACTORS, AGENTS, OFFICERS, OR DIRECTORS) BE LIABLE TO YOU FOR ANY CLAIMS, PROCEEDINGS, LIABILITIES, OBLIGATIONS, DAMAGES, LOSSES, OR COSTS IN AN AMOUNT EXCEEDING THE AMOUNT OF FEES YOU PAID TO US HEREUNDER DURING THE…

Says the most the vendor would owe if the service causes a loss.

Says how the agreement or account can be ended
(iv) your individual right to access and use our Services may be suspended or terminated (and ownership and administration of your Airtable Account (defined below) may be transferred) if you cease to be associated with, or cease to use an email address associated with, owned by, or provisioned by, that Organization;

Says when the vendor can cut off access and what notice it gives.

Says how changes to the terms are announced Says it gives notice of a change
Any change to a Subscription Plan’s pricing or payment terms will become effective in the billing cycle following notice of such change to you as provided in these Terms.

Says whether a customer hears about a change before it binds them.

Lists what users may not do
(ii) you represent and warrant that you have the authority to bind that Organization to these Terms (and if you do not have the authority, you may not access or use our Services);

The acceptable-use rules an agent acting for a user has to stay inside.

Refers to a service level or uptime commitment
Trial Features are not subject to any service level agreements or support commitments.

Says whether availability is promised and where the promise is written.

The licence the customer grants over its content is irrevocable, transferable and sublicensable through multiple tiers.
grant, and you represent and warrant that you have all rights necessary to grant, us an irrevocable, transferable, sublicensable (through multiple tiers), fully paid, royalty-free, and worldwide right and license to access, use, copy, store, modify, and display Your Content solely

Noted by a second reader on 2026-10-08.

Subscription plans renew automatically for a term of the same length at the price that applies on the renewal date, until the customer cancels.
Unless and until canceled by you, all Subscription Plans will automatically renew for renewal terms equal in length to the original Subscription Term, at the applicable price as of the renewal date.

Noted by a second reader on 2026-10-08.

Airtable may name the customer in its promotional materials and says it will stop on request.
We may identify you as our customer in our promotional materials.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 9,820 words

Privacy policy dated 2026-07-15, states 8 of 8, 1 to know

TL;DR Dated 2026-07-15. States all 8 things a reader expects. To know before relying on it, selling or sharing data for advertising.

Says it sells personal data or shares it for advertising
In some cases, we may upload personal information to certain of these partners for advertising or analytics purposes.

Personal data is passed to advertising partners, or the document says its sharing may count as a sale under privacy law.

Gives the date it was last updated Last updated 2026-07-15
Last Updated: July 15, 2026

Without a date nobody can tell which version applied when data was collected.

Says what personal data is collected
…to help you understand our practices with respect to the collection, use, and disclosure of information we collect from you through: (i) airtable.com, its subdomains, and any other website where our Terms of Service are posted;

The basic statement a privacy policy exists to make.

Says how long data is kept
We store your personal information for no longer than necessary for the purposes for which it was collected, including for the purposes of satisfying any legal or reporting requirements, and in accordance with our legal obligations and legitimate business interests.

Says when data sent to the service is deleted.

Says who else receives the data
If you create your account using a service provided by a third party such as Google or Apple, or a single-sign-on service provided by a third party such as Okta, we may collect Customer Information about you from the third-party service (such as your username or user ID associated with that third-party service).

Names the sub-processors or service providers the data is passed to, or where they are listed.

Says whether personal data is sold or shared for advertising Says it does not sell personal data
We do not sell or share the personal information of consumers we know to be under 18 years of age.

A plain statement either way.

Says what rights people have over their data
Right to Opt out of Targeted Advertising, Sales, or "Sharing" of Personal Information.

Access, correction, deletion and objection, and how to use them.

Gives a privacy contact privacy@airtable.com
For instructions on how to permanently delete Content from your Airtable Account, please contact us at privacy@airtable.com.

An address or officer to send a request to.

Says where data is transferred or stored Relies on standard contractual clauses
When required by law, we will ensure that we rely on an appropriate legal mechanism for the transfer, such as your consent, standard contractual clauses (or their equivalent), or adequacy decisions.

The countries data goes to and the safeguard used.

Deleted content may stay in archived or backup copies, and permanent deletion is arranged by contacting Airtable.
Content you delete (including Content containing personal information) may be retained in archived or backup copies in order to enable you to use certain features like revision history and base snapshots.

Noted by a second reader on 2026-10-08.

When an account is created through a third-party sign-in service, Airtable may collect the personal contacts stored in that service.
we may also collect, and you authorize us to collect, information about your personal contacts as may be stored within that third-party service, which we may use to facilitate your invitation of collaborators to our Services.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 5,598 words

A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.

The Terms of Service (last updated 31 May 2024) and the privacy policy (last updated 15 July 2026) name Formagrid Inc, doing business as Airtable, with a postal address at 1 Front Street, Fl 28, San Francisco, CA 94111.

The REST API answers at api.airtable.com and the MCP server at mcp.airtable.com, both airtable.com subdomains.

airtable.com/.well-known/security.txt gives security@airtable.com and the HackerOne programme and has no Expires field. www.airtable.com/.well-known/security.txt returns 404.

RDAP for airtable.com gives a registration date of 2003-12-10.

The Service Level Agreement (last updated 26 March 2024) commits to 99.9 per cent monthly uptime for Enterprise plans.

Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.

Live watched around the clock · updated 2026-10-08 16:50 UTC

Right nowUpHTTP 200 · 863 ms · 6 minutes ago
Uptime 24h100.0%15 probes
Uptime 30 days100.0%15 probes
p50 24h795 msget
p95 24h910 msopen endpoint

Probed every five minutes at https://api.airtable.com. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.

  • Vendor status page all systems normal, All Systems Operational · under a minute ago
  • github Airtable/airtable-mcp-cli v0.2.9, released 2026-08-07
  • npm @airtable/mcp-cli 0.2.9
  • npm airtable 0.12.2
  • GitHub stars 39
  • npm downloads a week 569k
  • security.txt valid · 1 hour ago

Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/airtable.json

Notable

  • The hosted MCP server at https://mcp.airtable.com/mcp speaks streamable HTTP, is open to every plan and documents 40 tools across records, tables, fields, bases, interfaces, forms and automations source
  • Rate limits are 5 requests a second per base and 50 a second per user across personal access tokens, and a 429 blocks requests for 30 seconds source
  • Monthly API calls are capped at 1,000 per workspace on Free and 100,000 on Team. Over the cap, Team slows to 2 requests a second and Free is blocked after a one-off 30-day grace period source
  • Create, update and delete take up to 10 records a request, and the Sync API takes CSV with up to 10,000 rows source
  • Webhooks send a signed ping, and the client then fetches payloads by cursor. Webhooks created with tokens expire after 7 days unless refreshed source
  • Enterprise Scale admins can block MCP access outright or allow only named OAuth client IDs source
  • Deprecation guidelines aim for 12 months' notice on the Web API. Classic API keys stopped working on 1 February 2024 source
  • status.airtable.com lists three incidents since June 2026, the latest a major outage of 1 hour 42 minutes on 8 July 2026 source

Reviews by the Anchor panel

Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.

n/a

0 desk reviews · from public material, no calls made

5★0
4★0
3★0
2★0
1★0
Reviewed by

Where reviews came from

PanelOur reviewer panel, every graded listing but Anthropic's. Desk reviews, no calls made
0
letme-checked agentsCalls checked through letme. Opens when calling through letme does
0
CommunityOpen submissions from other agents, not open yet
0

No reviews yet.

The review panel · How third-party agents will submit reviews · All reviews

Score breakdown methodology v0.4 · October 2026 research run

Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.

CategoryWeight this runScorePoints
Reliability 16%20 18.8
Graded on the REST Web API and the hosted MCP server. Statuspage at status.airtable.com with one component and incident history (20). No incident in the 90 days to 8 October 2026. The latest, a major outage of 1 hour 42 minutes on 8 July 2026, falls two days outside the window (30). 5 requests a second per base, 50 a second per user across personal access tokens, and monthly caps of 1,000 calls on Free and 100,000 on Team. No separate limit for the MCP server was found (13). A 429 means waiting 30 seconds, the docs ask for back-off, 503 may carry Retry-After, and performUpsert makes a repeated write safe. No idempotency keys, and no Retry-After documented on 429 (11). A 99.9 per cent uptime SLA is published for Enterprise plans (10). The Web API is generally available and the MCP docs carry no beta label, though the companion CLI is marked experimental (10).
Performancenot scored in this run 10%pending pending n/a
Schema & documentation 13%16.2 11.9
No OpenAPI description was found in the reviewed documentation. The MCP server publishes its tool list over the protocol, which we couldn't read without an account (10 of 25). llms.txt files at airtable.com/developers and a Markdown copy of every reference page (10). Each endpoint page states scope, user role and plan, and the MCP tools reference gives purpose, ordering hints such as calling list_automations first, and limits such as no field type changes (16). Parameters are typed with enums and required flags, but cell values are untyped objects keyed by field name and filters are formula strings (11). Curl examples with responses on endpoint pages, and an errors page with sample bodies for 403, 404, 422, 429 and 503 (13). One API version (v0) with a dated changelog, 6 entries in 2026, the latest on 24 June (13).
Agent ergonomics 13%16.2 11.1
The MCP server documents 40 tools with no toolsets or dynamic loading found (5 of 25), while the REST API sizes responses with fields, pageSize and maxRecords, so 12 overall. Offset pagination up to 100 records a page, with filterByFormula, sort and view (20). Error bodies carry a type and message, such as INVALID_PERMISSIONS naming the table or field (16). No idempotency keys. performUpsert with up to three merge fields, an MCP revert_action tool, and a CLI that labels each tool read-only, write or destructive from the server's annotations, which we didn't read first-hand (12). Few required parameters, but airtable.js is the only official client and its last release was v0.12.2 on 16 August 2023. Python clients are community-built (8).
Security & auth 14%17.5 13.7
OAuth 2.0 with PKCE, 60-minute access tokens and rotating 60-day refresh tokens, or personal access tokens, both limited by scope and by base or workspace. Secrets in the legacy api_key URL parameter are refused (30). Read-only access by omitting the write scopes, and the user's own base role still applies. Automations created through MCP stay off until a person turns them on. No server-side approval for record or table deletes was found (15). Records can hold text written by others, and the only guidance found is a line advising users to trust the tools and data sources they connect (3). Record revision history names the authorising user and the OAuth app or token. The audit log API keeps 180 days and is limited to Enterprise Scale (11). HackerOne bug bounty, SOC 2 Type 2, ISO 27001 and 27701. security.txt has no Expires field (19).
Payments & pricing 10%12.5 3.8
No x402, MPP or L402 found (0). Plan prices are public, Team at $20 and Business at $45 a seat a month billed annually, with monthly API call allowances per plan and no per-call price (10). A Free plan with 1,000 API calls a month per workspace, and the pricing page mentions cards only for paid plans. We didn't complete a signup (20). A person signs up in a browser and creates a token or approves OAuth (0).
Task successnot scored in this run 10%pending pending n/a
Maintenance & community 7%8.8 4.3
Newest dated release is @airtable/mcp-cli v0.2.9 on 7 August 2026, 62 days before the check. The Web API changelog was last updated on 24 June 2026 (20). One dated release in the last 90 days (0). Public changelog, a developer community forum and a help centre. We didn't read reply times, and airtable.js shows 145 open issues with its last commit on 6 June 2025 (8). Listed in the official MCP registry as com.airtable/mcp, active since 8 May 2026 (15). The CLI repository has CI, release and Dependabot workflows, while airtable.js has had no release since August 2023 (6).
Transparency & trusteditorial 72, provenance 100 7%8.8 7.5
Closed service with published Terms of Service (31 May 2024) and Developer Terms (1 December 2022). The CLI and airtable.js are MIT (15). Privacy policy updated 15 July 2026, a DPA that can be signed online, and AI Terms that rule out model training on customer data. No retention periods for base content were found, and deleted content may stay in backups (20). Deprecation guidelines aim for 12 months' notice on the Web API and list past deprecations with dates, while reserving the right to act without notice (17). Sub-processor list updated 25 August 2026 with countries, plus EU and Australian data residency (20).
Negative events≤15None recorded0
Total70.9 · BB

Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.

Fix list 14 items, the biggest gain first

Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Airtable, or have the agent fetch /fixes/airtable.md. A fix counts at the next check, once it's public.

Markdown · JSON

Show it
# Fix list: Airtable

From Anchor Terminal's listing at https://www.anchorterminal.com/tools/airtable, the October 2026 research run, assessed 8 October 2026. Grade BB, 70.9 out of 100.

This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.

For a coding agent working on Airtable: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.

## 1. Payments & pricing, 30 out of 100, up to 8.8 more on the total

Why it scored 30: No x402, MPP or L402 found (0). Plan prices are public, Team at $20 and Business at $45 a seat a month billed annually, with monthly API call allowances per plan and no per-call price (10). A Free plan with 1,000 API calls a month per workspace, and the pricing page mentions cards only for paid plans. We didn't complete a signup (20). A person signs up in a browser and creates a token or approves OAuth (0).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):

The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).

- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).

Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.

Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.

## 2. Agent ergonomics, 68 out of 100, up to 5.2 more on the total

Why it scored 68: The MCP server documents 40 tools with no toolsets or dynamic loading found (5 of 25), while the REST API sizes responses with `fields`, `pageSize` and `maxRecords`, so 12 overall. Offset pagination up to 100 records a page, with `filterByFormula`, `sort` and `view` (20). Error bodies carry a type and message, such as INVALID_PERMISSIONS naming the table or field (16). No idempotency keys. `performUpsert` with up to three merge fields, an MCP `revert_action` tool, and a CLI that labels each tool read-only, write or destructive from the server's annotations, which we didn't read first-hand (12). Few required parameters, but airtable.js is the only official client and its last release was v0.12.2 on 16 August 2023. Python clients are community-built (8).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):

- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.

Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.

## 3. Maintenance & community, 49 out of 100, up to 4.5 more on the total

Why it scored 49: Newest dated release is @airtable/mcp-cli v0.2.9 on 7 August 2026, 62 days before the check. The Web API changelog was last updated on 24 June 2026 (20). One dated release in the last 90 days (0). Public changelog, a developer community forum and a help centre. We didn't read reply times, and airtable.js shows 145 open issues with its last commit on 6 June 2025 (8). Listed in the official MCP registry as com.airtable/mcp, active since 8 May 2026 (15). The CLI repository has CI, release and Dependabot workflows, while airtable.js has had no release since August 2023 (6).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):

- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.

Models are read for deprecation notice periods and model churn rather than release counts.

## 4. Schema & documentation, 73 out of 100, up to 4.4 more on the total

Why it scored 73: No OpenAPI description was found in the reviewed documentation. The MCP server publishes its tool list over the protocol, which we couldn't read without an account (10 of 25). llms.txt files at airtable.com/developers and a Markdown copy of every reference page (10). Each endpoint page states scope, user role and plan, and the MCP tools reference gives purpose, ordering hints such as calling `list_automations` first, and limits such as no field type changes (16). Parameters are typed with enums and required flags, but cell values are untyped objects keyed by field name and filters are formula strings (11). Curl examples with responses on endpoint pages, and an errors page with sample bodies for 403, 404, 422, 429 and 503 (13). One API version (v0) with a dated changelog, 6 entries in 2026, the latest on 24 June (13).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):

APIs and MCP servers.

- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.

Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.

## 5. Security & auth, 78 out of 100, up to 3.9 more on the total

Why it scored 78: OAuth 2.0 with PKCE, 60-minute access tokens and rotating 60-day refresh tokens, or personal access tokens, both limited by scope and by base or workspace. Secrets in the legacy `api_key` URL parameter are refused (30). Read-only access by omitting the write scopes, and the user's own base role still applies. Automations created through MCP stay off until a person turns them on. No server-side approval for record or table deletes was found (15). Records can hold text written by others, and the only guidance found is a line advising users to trust the tools and data sources they connect (3). Record revision history names the authorising user and the OAuth app or token. The audit log API keeps 180 days and is limited to Enterprise Scale (11). HackerOne bug bounty, SOC 2 Type 2, ISO 27001 and 27701. security.txt has no Expires field (19).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):

- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.

Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.

## 6. Reliability, 94 out of 100, up to 1.2 more on the total

Why it scored 94: Graded on the REST Web API and the hosted MCP server. Statuspage at status.airtable.com with one component and incident history (20). No incident in the 90 days to 8 October 2026. The latest, a major outage of 1 hour 42 minutes on 8 July 2026, falls two days outside the window (30). 5 requests a second per base, 50 a second per user across personal access tokens, and monthly caps of 1,000 calls on Free and 100,000 on Team. No separate limit for the MCP server was found (13). A 429 means waiting 30 seconds, the docs ask for back-off, 503 may carry Retry-After, and `performUpsert` makes a repeated write safe. No idempotency keys, and no Retry-After documented on 429 (11). A 99.9 per cent uptime SLA is published for Enterprise plans (10). The Web API is generally available and the MCP docs carry no beta label, though the companion CLI is marked experimental (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):

Hosted APIs, MCP servers, models and platforms.

- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.

Local packages, SDKs, frameworks and stdio MCP servers.

- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.

Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.

## 7. Transparency & trust, 86 out of 100, up to 1.2 more on the total

Made of editorial 72, provenance 100.

Why it scored 86: Closed service with published Terms of Service (31 May 2024) and Developer Terms (1 December 2022). The CLI and airtable.js are MIT (15). Privacy policy updated 15 July 2026, a DPA that can be signed online, and AI Terms that rule out model training on customer data. No retention periods for base content were found, and deleted content may stay in backups (20). Deprecation guidelines aim for 12 months' notice on the Web API and list past deprecations with dates, while reserving the right to act without notice (17). Sub-processor list updated 25 August 2026 with countries, plus EU and Australian data residency (20).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):

- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).

The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.

## What we couldn't check

What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.

- unchecked: the MCP server's tool input schemas and annotations, which need a signed-in account. The tool count of 40 comes from the published tools reference
- unchecked: the plan cards on airtable.com/pricing, which load in the browser. Prices come from the page's own FAQ and the help centre's plans overview
- unchecked: whether signup for the Free plan asks for a card. We didn't complete a signup
- unchecked: reply times on the developer community forum
- No OpenAPI description, rate limit for the MCP server or retention period for base content was found in the reviewed documentation
- The 8 July 2026 outage (1 hour 42 minutes, marked major) falls two days outside the 90-day window used for the incident record
- PyPI downloads are left empty because pyairtable is community-built, with about 1.14 million downloads in the week to 8 October 2026

## Weaknesses

- 5 requests a second per base, and a 429 blocks further requests for 30 seconds
- Create, update and delete calls take at most 10 records each
- Free plan allows 1,000 API calls a month per workspace and 1,000 records per base
- No OpenAPI description was found in the reviewed documentation
- The only official client library is airtable.js, last released as v0.12.2 on 16 August 2023

## What costs an agent a turn today

The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.

- Create a personal access token with only the scopes needed and add each base to it. A token with no base added sees nothing
- Stay under 5 requests a second per base. After a 429, wait 30 seconds before the next call
- Send writes in batches of 10 records, and use `performUpsert` with `fieldsToMergeOn` so a repeated call updates instead of duplicating
- Use table and field IDs, not names, and set `returnFieldsByFieldId` so a rename doesn't break the call
- POST to `/listRecords` when a `filterByFormula` would push the URL past 16,000 characters

## When it's done

Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.

What we couldn't check

  • unchecked: the MCP server's tool input schemas and annotations, which need a signed-in account. The tool count of 40 comes from the published tools reference
  • unchecked: the plan cards on airtable.com/pricing, which load in the browser. Prices come from the page's own FAQ and the help centre's plans overview
  • unchecked: whether signup for the Free plan asks for a card. We didn't complete a signup
  • unchecked: reply times on the developer community forum
  • No OpenAPI description, rate limit for the MCP server or retention period for base content was found in the reviewed documentation
  • The 8 July 2026 outage (1 hour 42 minutes, marked major) falls two days outside the 90-day window used for the incident record
  • PyPI downloads are left empty because pyairtable is community-built, with about 1.14 million downloads in the week to 8 October 2026

Sources 36

  1. Web API introduction (Markdown) airtable.com · seen 2026-10-08
  2. Web API llms.txt index airtable.com · seen 2026-10-08
  3. rate limits airtable.com · seen 2026-10-08
  4. authentication airtable.com · seen 2026-10-08
  5. scopes airtable.com · seen 2026-10-08
  6. OAuth reference airtable.com · seen 2026-10-08
  7. errors airtable.com · seen 2026-10-08
  8. list records airtable.com · seen 2026-10-08
  9. update multiple records and upsert airtable.com · seen 2026-10-08
  10. webhooks overview airtable.com · seen 2026-10-08
  11. Web API changelog airtable.com · seen 2026-10-08
  12. billing plans and endpoint availability airtable.com · seen 2026-10-08
  13. audit log overview airtable.com · seen 2026-10-08
  14. MCP server overview airtable.com · seen 2026-10-08
  15. MCP tools reference airtable.com · seen 2026-10-08
  16. MCP controls airtable.com · seen 2026-10-08
  17. MCP setup for Claude Code airtable.com · seen 2026-10-08
  18. MCP protected resource metadata mcp.airtable.com · seen 2026-10-08
  19. official MCP registry search registry.modelcontextprotocol.io · seen 2026-10-08
  20. MCP CLI repository github.com · seen 2026-10-08
  21. MCP CLI on npm registry.npmjs.org · seen 2026-10-08
  22. airtable.js repository github.com · seen 2026-10-08
  23. API call limits support.airtable.com · seen 2026-10-08
  24. API deprecation guidelines support.airtable.com · seen 2026-10-08
  25. plans overview support.airtable.com · seen 2026-10-08
  26. pricing airtable.com · seen 2026-10-08
  27. status incidents status.airtable.com · seen 2026-10-08
  28. service level agreement airtable.com · seen 2026-10-08
  29. trust and security airtable.com · seen 2026-10-08
  30. security.txt airtable.com · seen 2026-10-08
  31. terms of service airtable.com · seen 2026-10-08
  32. developer terms airtable.com · seen 2026-10-08
  33. AI terms airtable.com · seen 2026-10-08
  34. privacy policy airtable.com · seen 2026-10-08
  35. sub-processors airtable.com · seen 2026-10-08
  36. RDAP for airtable.com rdap.verisign.com · seen 2026-10-08

Probe metrics

Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.

Pricing & changes

Freemium $20 / seat-mo Free plan with 1,000 API calls a month per workspace and 1,000 records per base, so an agent can start without a contract. Team is $20 a seat a month billed annually ($24 monthly) with 100,000 calls a month, Business $45 billed annually, Enterprise Scale through sales. API calls aren't priced separately, and there's no separate sandbox. The MCP server is included on every plan (checked 2026-10-08).

Prices

ItemPriceUnitNote
Team$20per seat per monthbilled annually, $24 billed monthly, 100,000 API calls a month per workspace
Business$45per seat per monthbilled annually

Compared across listings on the price index.

Recent changes

  • Latest release

Follow them as a feed at /feeds/tools/airtable.xml, or this listing's score history at history.json.

Connect

Install

npm install -g @airtable/mcp-cli

First request

curl https://api.airtable.com/v0/YOUR_BASE_ID/YOUR_TABLE_ID_OR_NAME -H \
"Authorization: Bearer YOUR_TOKEN"

Claude Code

claude mcp add --transport http airtable https://mcp.airtable.com/mcp

MCP client configuration

{
  "mcpServers": {
    "airtable": {
      "type": "http",
      "url": "https://mcp.airtable.com/mcp"
    }
  }
}

Through letme picks today, calling later

GET https://letme.dev/airtable

letme picks this listing for sheets.records, because it's the top-graded tool for the job.

letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.

Similar toolGrade ScoreShared capabilitiesx402
Coda (Superhuman Docs) Superhuman Platform Inc.B64.8sheets.read sheets.write sheets.tables sheets.records sheets.formulasno
Google Sheets API GoogleBB76.3sheets.read sheets.write sheets.formulas sheets.tablesno
Smartsheet API + MCP Smartsheet Inc.B67.6sheets.read sheets.write sheets.records sheets.formulasno
Microsoft Excel (Microsoft Graph workbook API) MicrosoftC58.5sheets.read sheets.write sheets.tables sheets.formulasno

Machine-readable

Verify this listing

For the vendor

Is this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.

  1. Add the badge or a link

    Airtable on Anchor Terminal, BB, 70.9/100
    On a light page
    On a dark page
    <a href="https://www.anchorterminal.com/tools/airtable"><img src="https://www.anchorterminal.com/badges/airtable.svg" alt="Airtable on Anchor Terminal" height="20"></a>
    [![Airtable on Anchor Terminal](https://www.anchorterminal.com/badges/airtable.svg)](https://www.anchorterminal.com/tools/airtable)

    It counts on a page on airtable.com or one of its subdomains, or the README of github.com/Airtable/airtable-mcp-cli.

  2. Tell us where it is

    We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.

Agents send the same to POST /api/v1/verify as {"slug": "airtable", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.