Tutorials NocoDB

NocoDB API Quickstart: Tokens, Records, Automation

NocoDB auto-generates a REST API for every table. Get an API token, find your Table ID, and run queries, inserts, updates and deletes with curl.

E
Eric Founder, Roamer Tech · · 6 min read

Want to start now? Deploy your NocoDB in 60 seconds

Smart spreadsheet — the open-source Airtable alternative. From NT$499/mo.

Subscribe to NocoDB

The most useful and least used feature in NocoDB is that it automatically generates a REST API for every table you create. Without writing a line of backend code, you can let other systems read and write that data.

That makes NocoDB a good lightweight backend for internal tools: manage the data through the interface, and give programs or automation workflows access through the API. This guide gets your first request working from scratch.

The 30-second version

ItemDetail
Where the API comes fromGenerated automatically per table; nothing to enable
What you needOne API token
What you can doRead, create, update and delete records
What to pair it withn8n, website forms, your own code
Security rule of thumbOne token per use case

Step 1: Get an API token

An API token is the credential for calling the API. It carries your account's permissions, so treat it like a password.

  1. Log in to your NocoDB
  2. Click your avatar at the top right and choose "Account Settings"
  3. Open the "Tokens" tab
  4. Click "Add New Token" and give it a name you will recognize (n8n-integration, for example)
  5. Copy the token that appears — this is the only time it is shown in full
Create a separate token for each use case. When you later want to shut down one integration, you can revoke just that token without affecting the other systems.

Step 2: Find the Table ID

The NocoDB v2 API addresses tables by Table ID, not by table name. A Table ID is an alphanumeric string that looks like m1a2b3c4d5e6f7g.

To find it: open the table in the NocoDB interface and look at the browser address bar, or use "Copy Table ID" in the table's right-click menu.

You can also use the built-in API Snippet feature — for the table you currently have open it generates copy-ready curl, JavaScript and Python examples with the correct IDs already filled in. When you are unsure, this is the fastest route.

Step 3: Query records

Every request has to carry the xc-token header. Replace YOUR_TOKEN and TABLE_ID below with your own values, and the domain with your own subdomain:

curl -X GET \
  'https://your-instance.roamerhost.com/api/v2/tables/TABLE_ID/records?limit=25' \
  -H 'xc-token: YOUR_TOKEN'

Commonly used query parameters:

ParameterPurposeExample
limitRecords per pagelimit=50
offsetHow many records to skip (for pagination)offset=50
whereFilter conditionwhere=(Status,eq,Active)
sortSort order; prefix with - for descendingsort=-CreatedAt
fieldsReturn only the listed fieldsfields=Name,Email

Step 4: Create records

curl -X POST \
  'https://your-instance.roamerhost.com/api/v2/tables/TABLE_ID/records' \
  -H 'xc-token: YOUR_TOKEN' \
  -H 'Content-Type: application/json' \
  -d '{"Name": "Jane Doe", "Email": "[email protected]", "Status": "Active"}'

The JSON keys have to match your table's field names exactly, including capitalization. This is the single most common source of errors.

Step 5: Update and delete

Both update and delete put the target record's Id in the request body rather than in the URL:

# Update
curl -X PATCH \
  'https://your-instance.roamerhost.com/api/v2/tables/TABLE_ID/records' \
  -H 'xc-token: YOUR_TOKEN' \
  -H 'Content-Type: application/json' \
  -d '{"Id": 12, "Status": "Closed"}'

# Delete
curl -X DELETE \
  'https://your-instance.roamerhost.com/api/v2/tables/TABLE_ID/records' \
  -H 'xc-token: YOUR_TOKEN' \
  -H 'Content-Type: application/json' \
  -d '{"Id": 12}'

Troubleshooting common errors

SymptomUsual cause
401 UnauthorizedWrong token, or the header was written as Authorization — it has to be xc-token
404 Not FoundWrong Table ID, or the v1 URL format used by mistake
The record is created but the fields are emptyThe JSON keys do not match the field names exactly (capitalization and spaces included)
Only 25 records come backThat is the default limit; pass limit and offset yourself for more
NocoDB changed its API paths between v1 and v2. If an example you find online uses the /api/v1/db/data/noco/... format, it is for the old version. The safest reference is the API Snippet inside your own instance.

Using it with n8n

The most common combination is NocoDB as the data layer and n8n as the automation layer: n8n has a ready-made NocoDB node, so you fill in the instance URL and API token and can read and write without assembling HTTP requests yourself.

Typical uses look like this: write a submitted form into NocoDB, compile NocoDB data into a report and email it on a daily schedule, or trigger a LINE notification when a new record appears in NocoDB. Both services run in your own environment, so the data never passes through a third party.

FAQ

Q: Does the API cost extra?

No. Every table gets a REST API automatically; it is a default feature, not an add-on. It is also the main reason many people move over from services that bill by quota.

Q: Do tokens expire?

A token is a key that stays valid indefinitely, so how you manage them matters: issue one per use case (one for n8n, one for the website form) so that revoking one does not affect the other systems.

Q: Can I put a token in front-end code?

No — that is the same as publishing it. If the front end needs to read data, route it through your own backend instead of leaving the token somewhere the browser can see.

Q: How do I connect it to n8n?

Call the API from an HTTP Request node with the token attached. The fuller two-way setup, where changes in NocoDB trigger n8n in return, is covered in n8n plus NocoDB.

Q: Is there a call limit?

Billing is not per call; the limit comes from your instance's compute resources. With high-frequency calls, resources are what to watch, not a quota.

Sources and further reading

For NocoDB field types and the permission model, the official documentation is authoritative:

Further reading

Want someone to build it for you?

Once the data volume grows, or the system has to plug into what your company already runs, this stops being a question of picking a tool. Roamer Tech takes on enterprise system customization and API integration:

Ready to get started with NocoDB?

60 seconds after you subscribe, NocoDB is installed for you — an isolated container with hard resource limits you never share, and HTTPS out of the box.

Subscribe to NocoDB

Billed monthly · no contract · cancel anytime

Hi, I'm Roamer! Tap me anytime with a question and I'll help you out.

Roamer

Roamer - AI assistant

Online
Roamer

Ask me anything, anytime — I'll do my best to help!

Powered by RoamerHost AI