Airtable's API lives at https://api.airtable.com/v0. Records are addressed by base id and table name (or table id): /v0/<base>/<table>.
Create a personal access token at airtable.com/create/tokens with the scopes (data.records:read, data.records:write, schema.bases:read) and bases you need. Send it as Authorization: Bearer <token>. In the examples it's written {{AIRTABLE_TOKEN}}. The base id (app…) is in the base's URL.
Full reference: https://airtable.com/developers/web/api/introduction
Up to 100 per page; pass offset from the response to get the next page. URL-encode table names with spaces.
curl "https://api.airtable.com/v0/{{BASE_ID}}/{{TABLE_NAME}}?maxRecords=10" \
-H "Authorization: Bearer {{AIRTABLE_TOKEN}}"
Up to 10 records per request. Field names must match the table exactly.
curl -X POST https://api.airtable.com/v0/{{BASE_ID}}/{{TABLE_NAME}} \
-H "Authorization: Bearer {{AIRTABLE_TOKEN}}" \
-H "Content-Type: application/json" \
-d '{"records": [{"fields": {"Name": "Created from PostTaco"}}]}'
PATCH changes only the fields you send; PUT clears the rest.
curl -X PATCH https://api.airtable.com/v0/{{BASE_ID}}/{{TABLE_NAME}}/{{RECORD_ID}} \
-H "Authorization: Bearer {{AIRTABLE_TOKEN}}" \
-H "Content-Type: application/json" \
-d '{"fields": {"Name": "Updated from PostTaco"}}'
Every base the token can reach, with ids and your permission level.
curl https://api.airtable.com/v0/meta/bases \
-H "Authorization: Bearer {{AIRTABLE_TOKEN}}"