Friction

Pain point · Permissions & security · Causes churn

Airtable API keys are not scoped

1 source thread · first seen 2020-05

Summary

The author says an Airtable API key can let anyone who obtains it modify the base, making it risky to use Airtable directly as a website data source.

Affects
Developers using Airtable as a website data source
Workaround
Built Flairtable as a go-between that blocks writes to the Airtable base.

Evidence

Excerpts are copied word for word from the source; follow the link to read it in full.

“Basically anyone who has that key can mess up your Airtable bases”

Report this item