Pain point · Permissions & security · Causes churn
Airtable API keys are not scoped
1 source thread · first seen 2020-05
Summary
The author says an Airtable API key can let anyone who obtains it modify the base, making it risky to use Airtable directly as a website data source.
- Affects
- Developers using Airtable as a website data source
- Workaround
- Built Flairtable as a go-between that blocks writes to the Airtable base.
Evidence
Excerpts are copied word for word from the source; follow the link to read it in full.
“Basically anyone who has that key can mess up your Airtable bases”