# VibeKit — the secure data layer between your AI-built app and Airtable

An agent-first proxy for building on Airtable. It keeps your API key server-side and adds caching, auth, live updates and stable media — so the app your agent builds is fast, secure, and stays inside Airtable's limits.

Airtable is a great place to keep your data. It is a hard place to build a real app against
directly: the API key ends up in the browser, attachment links expire, there is no cache, no live
updates, and it is easy to blow through the rate limits. So the app an AI agent builds against the
raw API tends to be insecure, slow, or brittle — often all three.

VibeKit sits between the app your agent builds and Airtable as a managed proxy. Your Airtable
token is stored server-side and never reaches the browser. Every request the app makes goes
through VibeKit, which checks who's asking, serves hot records from a global edge cache, keeps you
safely inside Airtable's rate limits, and hands back media links that don't expire.

It is built for agents. Point your favourite coding agent at VibeKit's SDK and MCP and it builds
the front end against a data layer that already behaves — live updates over WebSockets, login
backed by an Airtable view, per-request logs, and refresh controls that live inside Airtable. You
bring your own agent; there are no marked-up API credits.

It is not an app builder. There is no template and no drag-and-drop canvas. Your agent builds the
app you actually asked for; VibeKit is the secure, fast backend it talks to — the layer that turns
Airtable into a real backend.

## How you use it

1. **Connect** — create an app in the admin and paste your Airtable token once. It is stored
   encrypted on the server and can never be read back.
2. **Point it at your base** — choose the view and fields your app uses, and set how each behaves:
   live or cached, who can read it, how it refreshes.
3. **Hand off to your agent** — give it the SDK or MCP and let it build. The data layer underneath
   is already secure, fast, and live.

## What makes VibeKit different


## More features

- [Record-level security for your Airtable data](/md/features/rls-security.md) — Each user only sees their own records — record-level security enforced on the proxy, like Supabase's row-level security.
- [A log of every Airtable API request](/md/features/request-logs.md) — Airtable gives you no logs for individual API calls; the proxy records every one, so you can audit access, catch anything unsafe, and see who's using your API and how much.
- [Airtable image links that never expire](/md/features/stable-images.md) — Your app's photos keep loading long after Airtable's own attachment links have expired.
- [Redirects, file links and QR codes from any Airtable record](/md/features/quick-proxies.md) — Turn a field on any Airtable record into a working public link (redirect, image, download or QR code) without writing an endpoint.
- [Real-time data, synced from Airtable](/md/features/live-data.md) — Your visitors can see Airtable changes the moment they happen, without touching the refresh button.
- [Authentication and login, backed by Airtable](/md/features/airtable-auth.md) — Add real login to your app with your Airtable as the only user list you ever maintain.
- [Edge caching that keeps your app fast](/md/features/edge-cache.md) — Your pages load instantly everywhere while you stay comfortably within Airtable's API limits, even with lots of visitors.
- [Email alerts when your app slows down or errors](/md/features/metrics-alerts.md) — Get a brief email when your app hits rate-limit slow-downs or errors — and nothing at all when it's quiet.
- [Rename Airtable columns without breaking your app](/md/features/schema-field-mapping.md) — Your app keys on Airtable field IDs, so renaming columns never breaks your live site.
- [Edit text and feature flags without a deploy](/md/features/variables-flags.md) — Update your app's text, numbers, and feature switches from the admin and see them change in the live app instantly.
- [Change branding and colours without a redeploy](/md/features/instant-branding.md) — Change your app's logo and colours from the admin and see the live site update immediately, without a redeploy.
- [Ready-made prompts for your coding agent](/md/features/agent-ready-prompts.md) — Your coding agent gets a precise, self-contained brief — field map and fetch code included — instead of guessing from a bare link.
- [Rate-limit protection from runaway automations](/md/features/flood-protection.md) — Misbehaving Airtable automations are slowed, then stopped and flagged, while your site keeps serving from cache.
- [Your Airtable API token, kept secure server-side](/md/features/secure-token-vault.md) — Keep your Airtable token out of your website code entirely, so it can never leak to visitors.
- [Real-time updates, triggered from Airtable](/md/features/airtable-cache-control.md) — Refresh exactly what changed on your live site with a button or automation inside Airtable itself.
- [API keys your customers create themselves](/md/features/customer-api-keys.md) — Give customers programmatic, read-only access to their data through your app, with keys they manage and you can revoke.

## Who it is for

- [For agencies and freelancers](/md/audiences/agencies.md) — You build Airtable apps for clients — and shipping one with a hardcoded key is a liability you carry personally. VibeKit makes client work secure by default, with the client's base a clean source of truth you can hand over.
- [For tech teams](/md/audiences/tech-teams.md) — You're accountable when non-technical colleagues build on the company Airtable. VibeKit gives you control — one place to see who has access, revoke anyone without breaking a shared key, and an audit trail when something goes wrong.
- [For solo developers](/md/audiences/developers.md) — You're already building on Airtable and tired of hitting the same walls — exposed keys, no caching, expiring media links, rate limits. Keep Airtable as your backend; VibeKit removes the parts that keep breaking.
