Skip to main content

At a glance

  • Availability: Experimental (how to enable).
  • Authentication: OAuth 2.0.
  • Connection: A user authorizes the connection in the provider’s consent screen.
  • Scopes: root_readwrite.
  • Provider documentation: Authentication reference.

Credentials

Set these per environment. See Connect an integration. These variables are required only when you supply your own OAuth app. If a managed app is available, you can connect without setting them. Provider permissions and consent still apply.

Setup

  1. Create a Box app: Sign in at https://app.box.com/developers/console (a free Individual Box account works) and create a Custom App with ‘User Authentication (OAuth 2.0)’.
  2. Configure the redirect URI and scopes: In the app’s Configuration tab, add your redirect URI ending in /api/auth/box/callback and enable the ‘Read and write all files and folders’ application scope.
  3. Copy credentials: Copy the Client ID and Client Secret from the Configuration tab into BOX_CLIENT_ID and BOX_CLIENT_SECRET.
  4. Verify access: Connect your Box account and run the List Folder Items tool against folder 0.

Provider notes

  • Authorization codes are only valid for 30 seconds; the client is authenticated with client_id/client_secret in the token request body
  • Refresh tokens are issued; access tokens are short-lived and refreshed automatically
  • Uploads go to upload.box.com as multipart/form-data: the ‘attributes’ part must come before the ‘file’ part, and files over 50 MB require Box’s chunked upload API (not covered by these tools)
Provider API reference.

Tools

Verify the connection

Call a read tool such as box__list_folder_items with arguments for your account. Confirm that the result comes from the intended account or workspace before enabling write tools.