Airtable
AIRTABLE · DATA & ANALYTICS
Bases, tables, and records reached with that person’s own token.
Connecting Airtable in practice
Airtable’s real ceiling is per base, not per token: 5 requests per second per base, and after a 429 the documentation tells you to wait 30 seconds before retrying. One hot base throttles the agent no matter how much of the 50-per-second personal access token budget is unused.
Scopes that draw scrutiny
schema.bases:writeChanges base structure rather than data, so an agent holding it can rewrite the shape of the table other automations depend on.enterprise.auditLogs:readEnterprise admin only. Reads the audit log for the whole enterprise account.enterprise.scim.usersAndGroups:manageEnterprise admin only. Manages users and groups through SCIM, which is identity administration.workspacesAndBases:manageEnterprise admin only. Administers workspaces and bases across the account.user.email:readExposes the authorizing user’s email address, the join key most integrations want and most reviewers ask about.
Rate limits
- 5 requests per second per base.
- 50 requests per second for all traffic using personal access tokens from a given user or service account.
- After a 429 you must wait 30 seconds before issuing further requests.
Who has to approve
A block of scopes — enterprise.auditLogs:read, enterprise.scim.usersAndGroups:manage, enterprise.exports:manage, enterprise.user:write, workspacesAndBases:manage and others — is marked enterprise-admin only, so a token minted by an ordinary member can never carry them. Airtable also notes that "On top of requesting the correct scope, the user and token must also have the required resources and permissions to perform the action", so a granted scope is not an entitlement.
Worth knowing
- Because the hard limit is per base, splitting work across tokens does not help; splitting data across bases does.
- The scope grant and the underlying record permissions are two separate checks, so the same token succeeds on one base and 403s on another with no scope change.
- Airtable reserves the right to change these thresholds or add further restrictions that vary by subscription tier, so the 5-per-second figure is not a contract.
Checked against Airtable API rate limits (2026-09-29), Airtable OAuth scopes (2026-09-29)
What an agent can do
Each action is granted on its own. An agent allowed to read is not thereby allowed to write, and the scope beside each row is what the acting user must have connected for it to run at all.
Often connected alongside
Put Airtable behind one governed endpoint.
Same permissions, same audit trail, whatever else you connect next.