# App API and MCP

> Part of the NocoDB documentation (Apps). Index of all pages: https://nocodb.com/llms.txt. Any docs page is available as Markdown by adding `.md` to its URL.

URL: https://nocodb.com/docs/apps/api-and-mcp
Last updated: 2026-10-05

Call the actions of a NocoDB app from scripts, services and AI agents through its REST API and MCP server, with app API tokens.

Each deployed NocoDB app has its own REST API and its own MCP server. Both expose the actions of the app: "Let programs and AI agents call this app's actions from outside." Every call needs an app API token. You manage tokens and see the API in **App Settings** → **API / MCP**.

The **API / MCP** tab has three tabs:

| Tab          | What it shows                                                                            |
| ------------ | ---------------------------------------------------------------------------------------- |
| **Tokens**   | The app API tokens, and **Create New API Token**.                                        |
| **API Spec** | The address of the API and each action you can call, with its input fields and response. |
| **MCP**      | The setup steps and the config block for MCP clients.                                    |

The API and MCP server start when you [deploy](/docs/apps/deploy-app) the app. Before the first deploy, the tab shows **Not published yet**.

## Create an app API token

"A token acts as the person who created it, and reaches every action that person can run."

1. Open **App Settings** → **API / MCP** → **Tokens**.
2. Click **Create New API Token**.
3. Type a **Token name**, for example "Billing sync".
4. Select **Expires on**: 30, 60, 90 or 365 days, or **No expiration**. The default is 90 days.
5. Select **Access**:
   * **Everything I can do in this app**: the token can run every action that you can run.
   * **Only the actions I choose**: select the actions that the token can run.
6. Click **Create**. NocoDB shows the token one time.
7. Click **Copy**, then **Done**. "Copy it now. Only a digest is stored, so it cannot be shown again."

<img alt="Create New API Token" src={__img0} placeholder="blur" />

The token list shows the **Name**, **Token**, **Access**, **Last used** and **Expires on** of each token. To change a token, open its menu and select **Edit**. Only the person who created a token can edit it. To revoke a token, select **Delete**.

<img alt="App API tokens" src={__img1} placeholder="blur" />

## Call an action with the API

Send the request to the action address on the app domain. Put the token in the `Authorization` header and the input of the action under `input`:

```bash
curl -X POST "https://<app address>/api/v1/actions/<action id>" \
  -H "Authorization: Bearer <your-token>" \
  -H "Content-Type: application/json" \
  -d '{"input": {"email": "ada@example.com"}}'
```

The response returns the result of the action under `data`. The **API Spec** tab shows the action IDs, the input fields of each action and the OpenAPI document.

## Connect an MCP client

"This app is its own MCP server." Its tools are the actions that your token can run.

1. Create a token on the **Tokens** tab and copy it.
2. Open the **MCP** tab and copy the config block.
3. Add the block to the MCP config of your client. Replace `<your-token>` with the token.
4. Restart the client. The tools appear under the name of the app.

The config block has this shape:

```json
{
  "mcpServers": {
    "<app name>": {
      "command": "npx",
      "args": ["mcp-remote", "https://<app address>/mcp", "--header", "Authorization: Bearer <your-token>"]
    }
  }
}
```

"Claude Code, Claude Desktop, Cursor and VS Code all read this shape." The config file is different for each client.

<img alt="The MCP tab" src={__img2} placeholder="blur" />

## Good to know

* A token can never do more than its creator. NocoDB checks the access of the creator on every call, so when their team loses an action, the token loses it too.
* Each call with a token counts as an action run. See [Availability](/docs/apps#availability).
* The app MCP server is separate from the [NocoDB MCP server](/docs/apis-and-mcp/mcp), which works with the whole workspace.

## Availability

The app API and MCP server are available on the **Plus** plan and above.

## Related

* [Members and teams](/docs/apps/members-and-teams)
* [NocoDB MCP server](/docs/apis-and-mcp/mcp)
* [Secure vibe coding](/docs/apps/security)

---

## Related pages

- [Apps](https://nocodb.com/docs/apps.md): NocoDB Apps is an AI app builder for creating enterprise-grade work apps: describe the app, and NocoAI builds it on the data you already have, with teams, permissions, an API and an MCP server.
- [Vibe Coding with NocoDB Apps](https://nocodb.com/docs/apps/vibe-coding.md): Vibe coding is making software by describing it to AI. NocoDB Apps bring vibe coding to enterprise-grade work apps, on your own data, with teams, permissions and safe deploys.
- [Create an App](https://nocodb.com/docs/apps/create-app.md): Create a NocoDB app with AI: describe the app, and NocoAI builds it on your data. Start from the App tile in a base, with Build with AI, or in the NocoAI chat.
- [AI App Builder](https://nocodb.com/docs/apps/app-builder.md): Build and change enterprise-grade work apps in NocoDB's AI app builder: describe a change to NocoAI in the chat, and test it in the live preview.
- [Data for Apps](https://nocodb.com/docs/apps/data.md): Build NocoDB apps on the data you already have: NocoDB tables, your own PostgreSQL or MySQL database, and data that syncs from tools such as GitHub and HubSpot, with no record limit.
- [Secure Vibe Coding](https://nocodb.com/docs/apps/security.md): How NocoDB Apps keep AI-built work apps safe: teams and action grants, record rules, reviewed public pages, secrets in connections, scoped API tokens, environments and version restore.
- [Members and Teams](https://nocodb.com/docs/apps/members-and-teams.md): Control who can use a NocoDB app and what they can do in it with app teams, members and action grants.
- [Public Access](https://nocodb.com/docs/apps/public-access.md): Make pages of a NocoDB app public, and choose which actions visitors can run without signing in.
