# Airtable MCP Server

> Airtable MCP Server is an officially published MCP server from Airtable. Anomity scores its risk at 45 out of 100 (medium). It matches 1 dangerous capability combination.

- **Canonical URL:** https://catalog.anomity.ai/mcp/airtable-mcp-server
- **Kind:** MCP server
- **Publisher:** Airtable
- **Trust level:** official
- **Risk score:** 45/100 (medium)
- **Website:** https://airtable.com/developers/web/api/introduction
- **Documentation:** https://airtable.com/developers/web/api/introduction
- **Last updated:** 2026-09-02
- **JSON:** https://catalog.anomity.ai/api/entries/mcp/airtable-mcp-server

## Description

Airtable's official server exposes bases, tables, and records so an agent can query structured operational data and create or update rows.

Declared capabilities are outbound network access, credential access, and database reads and writes over the base contents. Airtable's role in most organisations — the place a team put the thing that was too important for a spreadsheet and too small for a database — means bases often hold operational data with no schema review and no access review behind them. Scope a token to a single base, and prefer read access unless a workflow genuinely needs to write.

## Why it scored 45

The score starts at the catalog's neutral base of 50 and moves only through the signals below. The formula is published at https://catalog.anomity.ai/about — there is no model and no hidden heuristic.

| Signal | Contribution | Severity | Evidence |
| --- | --- | --- | --- |
| Published by the vendor | -40 | trust offset |  |
| 2 high-risk capabilities: credentials:access, database:write | +20 | critical |  |
| Database exfiltration risk (high) | +15 | high | Database read combined with outbound network can exfiltrate production data. |

Clamped result: **45/100**, band **medium**.

## Capabilities

| Capability | Name | Security implication |
| --- | --- | --- |
| `network:outbound` | Outbound network | Can make outbound network requests. Required for hosted model providers and remote APIs; also the path for data exfiltration if combined with read access. |
| `credentials:access` | Credentials access | Reads provider API keys, OAuth tokens, or other secrets from the host keychain or environment. |
| `database:read` | Database read | Reads from connected databases. Useful for query and analytics agents; risky when combined with outbound network. |
| `database:write` | Database write | Writes to connected databases. High-impact; combined with outbound network is treated as exfiltration-class. |

## Dangerous combinations matched

### Database exfiltration risk (high)

Database read combined with outbound network can exfiltrate production data.

Capabilities: `database:read`, `network:outbound`

## Related MCP servers

- [Cloudflare MCP Server](https://catalog.anomity.ai/mcp/cloudflare-mcp-server) — risk 45 (medium)
- [MongoDB MCP Server](https://catalog.anomity.ai/mcp/mongodb-mcp-server) — risk 45 (medium)
- [Neon MCP Server](https://catalog.anomity.ai/mcp/neon-mcp-server) — risk 45 (medium)
- [PostgreSQL](https://catalog.anomity.ai/mcp/postgres) — risk 45 (medium)
- [Supabase MCP Server](https://catalog.anomity.ai/mcp/supabase-mcp-server) — risk 45 (medium)
- [Grafana MCP Server](https://catalog.anomity.ai/mcp/grafana-mcp-server) — risk 35 (medium)

---

Source: Anomity Catalog (https://catalog.anomity.ai/). Scoring methodology: https://catalog.anomity.ai/about. Machine-readable index: https://catalog.anomity.ai/llms.txt · https://catalog.anomity.ai/openapi.json
