The most useful and least used feature in NocoDB is that it automatically generates a REST API for every table you create. Without writing a line of backend code, you can let other systems read and write that data.
That makes NocoDB a good lightweight backend for internal tools: manage the data through the interface, and give programs or automation workflows access through the API. This guide gets your first request working from scratch.
The 30-second version
| Item | Detail |
|---|---|
| Where the API comes from | Generated automatically per table; nothing to enable |
| What you need | One API token |
| What you can do | Read, create, update and delete records |
| What to pair it with | n8n, website forms, your own code |
| Security rule of thumb | One token per use case |
Step 1: Get an API token
An API token is the credential for calling the API. It carries your account's permissions, so treat it like a password.
- Log in to your NocoDB
- Click your avatar at the top right and choose "Account Settings"
- Open the "Tokens" tab
- Click "Add New Token" and give it a name you will recognize (
n8n-integration, for example) - Copy the token that appears — this is the only time it is shown in full
Create a separate token for each use case. When you later want to shut down one integration, you can revoke just that token without affecting the other systems.
Step 2: Find the Table ID
The NocoDB v2 API addresses tables by Table ID, not by table name. A Table ID is an alphanumeric string that looks like m1a2b3c4d5e6f7g.
To find it: open the table in the NocoDB interface and look at the browser address bar, or use "Copy Table ID" in the table's right-click menu.
You can also use the built-in API Snippet feature — for the table you currently have open it generates copy-ready curl, JavaScript and Python examples with the correct IDs already filled in. When you are unsure, this is the fastest route.
Step 3: Query records
Every request has to carry the xc-token header. Replace YOUR_TOKEN and TABLE_ID below with your own values, and the domain with your own subdomain:
curl -X GET \
'https://your-instance.roamerhost.com/api/v2/tables/TABLE_ID/records?limit=25' \
-H 'xc-token: YOUR_TOKEN'
Commonly used query parameters:
| Parameter | Purpose | Example |
|---|---|---|
limit | Records per page | limit=50 |
offset | How many records to skip (for pagination) | offset=50 |
where | Filter condition | where=(Status,eq,Active) |
sort | Sort order; prefix with - for descending | sort=-CreatedAt |
fields | Return only the listed fields | fields=Name,Email |
Step 4: Create records
curl -X POST \
'https://your-instance.roamerhost.com/api/v2/tables/TABLE_ID/records' \
-H 'xc-token: YOUR_TOKEN' \
-H 'Content-Type: application/json' \
-d '{"Name": "Jane Doe", "Email": "[email protected]", "Status": "Active"}'
The JSON keys have to match your table's field names exactly, including capitalization. This is the single most common source of errors.
Step 5: Update and delete
Both update and delete put the target record's Id in the request body rather than in the URL:
# Update
curl -X PATCH \
'https://your-instance.roamerhost.com/api/v2/tables/TABLE_ID/records' \
-H 'xc-token: YOUR_TOKEN' \
-H 'Content-Type: application/json' \
-d '{"Id": 12, "Status": "Closed"}'
# Delete
curl -X DELETE \
'https://your-instance.roamerhost.com/api/v2/tables/TABLE_ID/records' \
-H 'xc-token: YOUR_TOKEN' \
-H 'Content-Type: application/json' \
-d '{"Id": 12}'
Troubleshooting common errors
| Symptom | Usual cause |
|---|---|
| 401 Unauthorized | Wrong token, or the header was written as Authorization — it has to be xc-token |
| 404 Not Found | Wrong Table ID, or the v1 URL format used by mistake |
| The record is created but the fields are empty | The JSON keys do not match the field names exactly (capitalization and spaces included) |
| Only 25 records come back | That is the default limit; pass limit and offset yourself for more |
NocoDB changed its API paths between v1 and v2. If an example you find online uses the /api/v1/db/data/noco/... format, it is for the old version. The safest reference is the API Snippet inside your own instance.
Using it with n8n
The most common combination is NocoDB as the data layer and n8n as the automation layer: n8n has a ready-made NocoDB node, so you fill in the instance URL and API token and can read and write without assembling HTTP requests yourself.
Typical uses look like this: write a submitted form into NocoDB, compile NocoDB data into a report and email it on a daily schedule, or trigger a LINE notification when a new record appears in NocoDB. Both services run in your own environment, so the data never passes through a third party.
FAQ
Q: Does the API cost extra?
No. Every table gets a REST API automatically; it is a default feature, not an add-on. It is also the main reason many people move over from services that bill by quota.
Q: Do tokens expire?
A token is a key that stays valid indefinitely, so how you manage them matters: issue one per use case (one for n8n, one for the website form) so that revoking one does not affect the other systems.
Q: Can I put a token in front-end code?
No — that is the same as publishing it. If the front end needs to read data, route it through your own backend instead of leaving the token somewhere the browser can see.
Q: How do I connect it to n8n?
Call the API from an HTTP Request node with the token attached. The fuller two-way setup, where changes in NocoDB trigger n8n in return, is covered in n8n plus NocoDB.
Q: Is there a call limit?
Billing is not per call; the limit comes from your instance's compute resources. With high-frequency calls, resources are what to watch, not a quota.
Sources and further reading
For NocoDB field types and the permission model, the official documentation is authoritative:
Further reading
- Introduction to NocoDB
- Build your first table and view
- NocoDB self-hosted vs managed
- RoamerHost managed NocoDB plans
Want someone to build it for you?
Once the data volume grows, or the system has to plug into what your company already runs, this stops being a question of picking a tool. Roamer Tech takes on enterprise system customization and API integration: