Box
Box is a cloud content management and file sharing service for businesses. Box provides a secure platform for storing, managing, and sharing files and content, with features for collaboration, workflow automation, and integration with other business applications.
Solid contracts, transparent operations, and an easy start — typically complete on four or five facets with one clear soft spot.
API Evangelist profiles Box the way a machine reads it — 319 machine-readable artifacts across 81 APIs, pulled from the provider's own public surface and indexed so a developer, an analyst, or an AI agent can evaluate it against every other provider on the network.
Every provider in the network is reduced to the same set of machine-readable artifacts — OpenAPI contracts, event specifications, GraphQL schemas, runnable collections, pricing and rate-limit signals, security posture, OAuth scopes, and the agent surfaces (MCP servers and skills) that let software drive the API on its own. We profile them because the interface is the part of a company you can actually inspect: it is a truer signal of what a provider does than any marketing page. From those artifacts we compute the Kin Score — Box scores 66.7/100 (strong), with a separate agent-readiness read of 60/100 (agent ready). The full breakdown is below, followed by every artifact we hold — each card links through to its machine-readable definition on apis.io.
Kin Score
This is the API Evangelist rating — a single, repeatable read computed from the artifacts on this page. Green fill is points earned; the red track is points possible, so every bar shows earned-versus-possible at a glance.
How we profile Box
Each block below is one kind of artifact we hold for Box. For each we say what it is and why it earns a place in the profile, then list every one we've indexed — capped at two rows, scroll within the panel for the rest.
APIs 81
Each API is captured as its own OpenAPI definition — every operation, parameter, and response. This is the single most useful machine-readable description of what an API does, and it's what lets us score, lint, mock, and generate against it without asking the provider for anything.
Individual APIs this provider publishes, each with its own machine-readable definition.
Box Authorization API
A set of endpoints used to manage user authorization process.
Box Authorize API
The Authorize API from Box — 1 operation(s) for authorize.
Box Classifications API
Classification labels are used for content that is sensitive or under security restrictions.
Box Classifications on Files API
Classification labels are used for files that are sensitive or under security restrictions.
Box Classifications on Folders API
Classification labels are used for folders that are sensitive or under security restrictions.
Box Collaboration Whitelist Entries API
The Collaboration Whitelist Entries API from Box — 2 operation(s) for collaboration whitelist entries.
Box Collaboration Whitelist Exempt Targets API
The Collaboration Whitelist Exempt Targets API from Box — 2 operation(s) for collaboration whitelist exempt targets.
Box Collaborations API
Collaborations define access permissions for users and groups to files and folders, similar to access control lists.
Box Collaborations (List) API
A set of endpoints used to retrieve file, folder, pending, and group collaborations.
Box Collections API
Collections are a way to group files, folders, and web links without putting them all into a folder.
Box Comments API
Comments are messages generated users on files, allowing users to collaborate on a file, discussing any feedback they might have on the content.
Box Device Pinners API
Device pinners allow enterprises to control what devices can use native Box applications.
Box Domain Restrictions for Collaborations API
A set of endpoints that manage domains for which users can collaborate with files and folders in an enterprise.
Box Domain Restrictions (User Exemptions) API
A set of endpoints that allow exempting users from restrictions imposed by the list of allowed collaboration domains for a specific enterprise.
Box Downloads API
Downloads allow saving files to the application's server, or directly by the end user in a browser.
Box Email Aliases API
Email aliases provide a list of emails additional to the user's primary login email.
Box Enterprises API
The Enterprises API from Box — 1 operation(s) for enterprises.
Box Events API
Events provide a way for an application to subscribe to any actions performed by any user, users, or service in an enterprise.
Box File Requests API
File Requests provide a fast and secure way to request files and associated metadata from anyone. Users can create new file requests based on an existing file request, update fi...
Box File Version Legal Holds API
A legal hold is a process that an enterprise can use to preserve all forms of potentially relevant information when litigation is pending or reasonably anticipated. A File Versi...
Box File Version Retentions API
A retention policy blocks permanent deletion of content for a specified amount of time. A file version retention is a record for a retained file.
Box File Versions API
A set of endpoints used to manage specific versions of a file.
Box Files API
Files, together with Folders, are at the core of the Box API. Files can be uploaded and downloaded, as well as hold important metadata information about the content.
Box Folder Locks API
Folder locks define access restrictions placed by folder owners to prevent specific folders from being moved or deleted.
Box Folders API
Folders, together with Files, are at the core of the Box API. Folders can be uploaded and downloaded, as well as hold important metadata information about the content.
Box Group Memberships API
Group memberships signify that a user is a part of the group.
Box Groups API
Groups created in an enterprise.
Box Integration Mappings API
Integration Mappings allow the users to manage where content from partner apps is stored in Box.
Box Invites API
Invites are used to invite the user to an enterprise.
Box Legal Hold Policies API
A legal hold is a process that an enterprise can use to preserve all forms of potentially relevant information when litigation is pending or reasonably anticipated.
Box Legal Hold Policy Assignments API
A Legal Hold Policy Assignment is a relation between a policy and custodian. In this case, as custodian can be a user, folder, file, or file version.
Box Metadata Cascade Policies API
A metadata cascade policy describes how metadata instances applied to a folder should be applied to any item within that folder.
Box Metadata Instances (Files) API
A metadata instance describes the relation between a template and a file, including the values that are assigned for every field.
Box Metadata Instances (Folders) API
A metadata instance describes the relation between a template and a folder, including the values that are assigned for every field.
Box Metadata Queries API
The Metadata Queries API from Box — 1 operation(s) for metadata queries.
Box Metadata Templates API
A metadata template describes a reusable set of key/value pairs that can be assigned to a file.
Box Oauth2 API
The Oauth2 API from Box — 3 operation(s) for oauth2.
Box Recent Items API
Recent items represent items such as files or folders that the user accessed recently.
Box Retention Policies API
A retention policy blocks permanent deletion of content for a specified amount of time. Admins can create retention policies and then assign them to specific folders or their en...
Box Retention Policy Assignments API
A Retention Policy Assignment is a relation between a policy and folder or enterprise. Creating an assignment puts a retention on all the file versions that belong to that folde...
Box Search API
The Box API provides a way to find content in Box using full-text search queries.
Box Session Termination API
Session termination API is used to validate the roles and permissions of the group, and creates asynchronous jobs to terminate the group's sessions.
Box Shared Items API
The Shared Items API from Box — 1 operation(s) for shared items.
Box Shared Items#folders API
The Shared Items#folders API from Box — 1 operation(s) for shared items#folders.
Box Shared Items#web Links API
The Shared Items#web Links API from Box — 1 operation(s) for shared items#web links.
Box Shared Links (Files) API
Files shared links are URLs that are generated for files stored in Box, which provide direct, read-only access to the resource.
Box Shared Links (Folders) API
Folders shared links are URLs that are generated for folders stored in Box, which provide direct, read-only access to the resource.
Box Shared Links (Web Links) API
Web links for files are URLs that are generated for web links in Box, which provide direct, read-only access to the resource.
Box Shield Information Barrier Reports API
Shield information barrier reports contain information on what existing collaborations will be removed permanently when the information barrier is enabled.
Box Shield Information Barrier Segment Members API
Shield information barrier segment member represents a user that is assigned to a specific segment.
Box Shield Information Barrier Segment Restrictions API
Shield information barrier segment restriction is an access restriction based on the content (file or folder) owner.
Box Shield Information Barrier Segments API
Shield information barrier segment represents a defined group of users. A user can be a member of only one segment, which makes segments different from groups.
Box Shield Information Barriers API
Shield information barrier in Box defines an ethical wall. An ethical wall is a mechanism that prevents exchanges or communication that could lead to conflicts of interest and t...
Box Sign Requests API
Sign requests are used to submit a file for signature.
Box Sign Templates API
Sign templates allow you to use a predefined Box Sign template when creating a sign request. The template includes placeholders that are automatically populated with data when c...
Box Skill Invocations API
The Skill Invocations API from Box — 1 operation(s) for skill invocations.
Box Skills API
Box Skills are designed to allow custom processing of files uploaded to Box, with the intent of enhancing the underlying metadata of the file.
Box Standard and Zones Storage Policies API
Storage policy assignment represents the storage zone for items in a given enterprise.
Box Standard and Zones Storage Policy Assignments API
Storage policy assignment represents the relation between storage zone and the assigned item (for example a file stored in a specific zone).
Box Storage Policies API
The Storage Policies API from Box — 2 operation(s) for storage policies.
Box Storage Policy Assignments API
The Storage Policy Assignments API from Box — 2 operation(s) for storage policy assignments.
Box Task Assignments API
A task assignment defines which task is assigned to which user to complete.
Box Tasks API
Tasks allow users to request collaborators on a file to review a file or complete a piece of work. Tasks can be used by developers to create file-centric workflows.
Box Terms of Service API
A set of endpoints used to manage terms of service agreements.
Box Terms of Service User Statuses API
A set of endpoints used to manage the status of terms of service for a particular user.
Box Terms of Services API
The Terms of Services API from Box — 2 operation(s) for terms of services.
Box Transfer Folders API
API designed to move all of the items (files, folders and workflows) owned by a user into another user's account.
Box Trashed Files API
Files that were deleted and are in trash.
Box Trashed Folders API
Folders that were deleted and are in trash.
Box Trashed Items API
Items that were deleted and are in trash.
Box Trashed Web Links API
Web links that were deleted and are in trash.
Box Uploads API
The direct file upload API supports files up to 50MB in size and sends all the binary data to the Box API in 1 API request.
Box Uploads (Chunked) API
The chunked upload endpoints support files from 20MB in size and allow an application to upload the file in parts, allowing for more control to catch any errors and retry parts ...
Box User Avatars API
User avatars are JPG or PNG files uploaded to Box to represent the user image. They are then displayed in the user account.
Box Users API
Box API supports a variety of users, ranging from real employees logging in with their Managed User account, to applications using App Users to drive powerful automation workflows.
Box Watermarks (Files) API
A watermark is a semi-transparent overlay on an embedded file preview that displays a viewer's email address or user ID and the time of access over the file.
Box Watermarks (Folders) API
A watermark is a semi-transparent overlay on an embedded folder preview that displays a viewer's email address or user ID and the time of access over the folder content.
Box Web Links API
Web links are objects that point to URLs. These objects are also known as bookmarks within the Box web application.
Box Webhooks API
Webhooks allow you to monitor Box content for events, and receive notifications to a URL of your choice when they occur. For example, a workflow may include waiting for a file t...
Box Workflows API
Box Relay Workflows are objects that represent a named collection of flows.
Box Zip Downloads API
Zip downloads represent a successful request to create a ZIP archive with files and folders.
Scroll within the panel for all 81 ·
MCP Servers 1
Model Context Protocol servers expose these APIs directly to AI agents. We profile them because agent-native access is the fastest-growing way this provider's capabilities actually get used.
Model Context Protocol servers that expose these APIs to AI agents.
MCP Server
MCP SERVERGraphQL 1
Where a provider ships GraphQL, the schema is the contract. We profile it alongside the REST surface so the whole interface is legible in one place.
GraphQL schemas published by this provider.
Box GraphQL Schema
This directory contains a conceptual GraphQL schema for the Box cloud content management platform. Box exposes a REST API (v2) at `https://api.box.com/2.0`. The schema in `box-s...
GRAPHQLPricing Plans 1
Pricing is part of the interface. Machine-readable plans tell you what a tier costs and includes before you commit — one of the six things the Kin Score reads for commercial clarity.
Published pricing tiers and plan structures.
Box Plans Pricing
PLANSRate Limits 1
Rate limits are the difference between a demo that works and a production integration that doesn't fall over. Publishing them is an operational-transparency signal — and a hard requirement for any agent that plans its own throughput.
Documented rate limits and quota policies.
Box Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals let a buyer model the financial operations of an API before it's live. We profile them for the same reason we profile pricing: the money is part of the contract.
Cost, billing, and metering signals for API financial operations.
Box Finops
FINOPSFeatures 16
The notable capabilities this provider advertises, captured as structured features so they can be searched and compared instead of read one landing page at a time.
Notable capabilities this provider offers.
Scroll within the panel for all 16 ·
Spectral Rules 2
Governance rulesets we run against this provider's specs — the automated checks behind parts of the score. Profiling them makes the quality bar explicit and re-runnable, not a matter of opinion.
Box API Rules
SPECTRALBox API Rules
SPECTRALJSON Schema 197
Standalone JSON Schema definitions describe the data models behind the API. We profile them so the shapes are validatable on their own — useful long after a single request is forgotten.
Standalone JSON Schema definitions for this provider's data models.
Access token
JSON SCHEMAClassification
JSON SCHEMAClassification Template
JSON SCHEMAClient error
JSON SCHEMACollaboration
JSON SCHEMAAllowed collaboration domains
JSON SCHEMAAllowed collaboration domain
JSON SCHEMAAllowed collaboration domains user exemption
JSON SCHEMACollaborations
JSON SCHEMACollection
JSON SCHEMACollections
JSON SCHEMAComment (Base)
JSON SCHEMAComment (Full)
JSON SCHEMAComment
JSON SCHEMAComments
JSON SCHEMAConflict error
JSON SCHEMADevice pinner
JSON SCHEMADevice pinners
JSON SCHEMAEmail alias
JSON SCHEMAEmail aliases
JSON SCHEMAEnterprise (Base)
JSON SCHEMAEvent
JSON SCHEMAEvents
JSON SCHEMAEvent source
JSON SCHEMAFile (Base)
JSON SCHEMAFile (Full)
JSON SCHEMAFile (Mini)
JSON SCHEMAFile
JSON SCHEMAFile (Conflict)
JSON SCHEMAFile or folder scope
JSON SCHEMAFile Request
JSON SCHEMAFile Request (Copy)
JSON SCHEMAFile Request (Update)
JSON SCHEMAFiles
JSON SCHEMAFiles under retention
JSON SCHEMAFile version (Base)
JSON SCHEMAFile version (Full)
JSON SCHEMAFile version (Mini)
JSON SCHEMAFile version
JSON SCHEMAFile version legal hold
JSON SCHEMAFile version legal holds
JSON SCHEMAFile version retention
JSON SCHEMAFile version retentions
JSON SCHEMAFile versions
JSON SCHEMAFolder (Base)
JSON SCHEMAFolder (Full)
JSON SCHEMAFolder (Mini)
JSON SCHEMAFolder
JSON SCHEMAFolder Lock
JSON SCHEMAFolder Locks
JSON SCHEMAGeneric source
JSON SCHEMAGroup (Base)
JSON SCHEMAGroup (Full)
JSON SCHEMAGroup (Mini)
JSON SCHEMAGroup
JSON SCHEMAGroup membership
JSON SCHEMAGroup memberships
JSON SCHEMAGroups
JSON SCHEMAIntegration mapping (Base)
JSON SCHEMAIntegration mapping (Mini)
JSON SCHEMAIntegration mapping
JSON SCHEMAIntegration mappings
JSON SCHEMACreate integration mapping request
JSON SCHEMAIntegration mapping options for type Slack
JSON SCHEMAInvite
JSON SCHEMAItems
JSON SCHEMAKeyword Skill Card
JSON SCHEMALegal hold policies
JSON SCHEMALegal hold policy (Mini)
JSON SCHEMALegal hold policy
JSON SCHEMALegal hold policy assignment (Base)
JSON SCHEMALegal hold policy assignment
JSON SCHEMALegal hold policy assignments
JSON SCHEMAMetadata instance (Base)
JSON SCHEMAMetadata instance (Full)
JSON SCHEMAMetadata instance
JSON SCHEMAMetadata cascade policies
JSON SCHEMAMetadata cascade policy
JSON SCHEMAMetadata field filter (date range)
JSON SCHEMAMetadata field filter (float)
JSON SCHEMAMetadata field filter (float range)
JSON SCHEMAMetadata field filter (multi-select)
JSON SCHEMAMetadata field filter (string)
JSON SCHEMAMetadata filter
JSON SCHEMAMetadata query search request
JSON SCHEMAMetadata query index
JSON SCHEMAMetadata query search results
JSON SCHEMAMetadata instances
JSON SCHEMAMetadata template
JSON SCHEMAMetadata templates
JSON SCHEMAOAuth 2.0 error
JSON SCHEMAToken revocation request
JSON SCHEMARefresh access token
JSON SCHEMAToken request
JSON SCHEMAReal-time server
JSON SCHEMAReal-time servers
JSON SCHEMARecent item
JSON SCHEMARecent items
JSON SCHEMARetention policies
JSON SCHEMARetention policy (Base)
JSON SCHEMARetention policy (Mini)
JSON SCHEMARetention policy
JSON SCHEMARetention policy assignment (Base)
JSON SCHEMARetention policy assignment
JSON SCHEMARetention policy assignments
JSON SCHEMASearch Results
JSON SCHEMASearch Results (including Shared Links)
JSON SCHEMASearch Result (including Shared Link)
JSON SCHEMASession termination message
JSON SCHEMAShield information barrier (Base)
JSON SCHEMAShield information barrier
JSON SCHEMAShield information barrier reference
JSON SCHEMAShield information barrier report (Base)
JSON SCHEMAShield information barrier report
JSON SCHEMAShield information barrier report details
JSON SCHEMAList of Shield Information Barrier Reports
JSON SCHEMAList of Shield Information Barriers
JSON SCHEMAShield information barrier segment
JSON SCHEMAShield information barrier segment member
JSON SCHEMAList of Shield Information Barrier Segments
JSON SCHEMASign Request (Base)
JSON SCHEMASign Request
JSON SCHEMACreate a sign request
JSON SCHEMASigner fields for Create Sign Request
JSON SCHEMASign Request Prefill Tag
JSON SCHEMABox Sign
JSON SCHEMASigner fields for GET Sign Request response
JSON SCHEMASign Request Signer Input
JSON SCHEMABox Sign template
JSON SCHEMABox Sign templates
JSON SCHEMASkills metadata instance
JSON SCHEMASkill webhook payload
JSON SCHEMAStatus Skill Card
JSON SCHEMAStorage policies
JSON SCHEMAStorage policy (Mini)
JSON SCHEMAStorage policy
JSON SCHEMAStorage policy assignment
JSON SCHEMAStorage policy assignments
JSON SCHEMATask
JSON SCHEMATask assignment
JSON SCHEMATask assignments
JSON SCHEMATasks
JSON SCHEMASigner fields for Templates
JSON SCHEMATemplate Signer Input
JSON SCHEMATerms of service (Base)
JSON SCHEMATerms of service
JSON SCHEMATerms of services
JSON SCHEMATerms of service user status
JSON SCHEMATerms of service user statuses
JSON SCHEMATimeline Skill Card
JSON SCHEMATracking code
JSON SCHEMATranscript Skill Card
JSON SCHEMATrashed File
JSON SCHEMATrashed File (Restored)
JSON SCHEMATrashed Folder
JSON SCHEMATrashed Folder (Restored)
JSON SCHEMATrashed Web Link
JSON SCHEMATrashed Web Link (Restored)
JSON SCHEMAUploaded part
JSON SCHEMAUpload part (Mini)
JSON SCHEMAUpload part
JSON SCHEMAUpload parts
JSON SCHEMAUpload session
JSON SCHEMAUpload URL
JSON SCHEMAUser (Base)
JSON SCHEMAUser (Collaborations)
JSON SCHEMAUser (Full)
JSON SCHEMAUser (Mini)
JSON SCHEMAUser
JSON SCHEMAUser avatar
JSON SCHEMAUser (Integration Mappings)
JSON SCHEMAUsers
JSON SCHEMAWatermark
JSON SCHEMAWebhook (Mini)
JSON SCHEMAWebhook
JSON SCHEMAWebhook (V2) payload
JSON SCHEMAWebhooks
JSON SCHEMAWeb link (Base)
JSON SCHEMAWeb link (Mini)
JSON SCHEMAWeb link
JSON SCHEMAWorkflow (Full)
JSON SCHEMAWorkflow (Mini)
JSON SCHEMAWorkflow
JSON SCHEMAWorkflows
JSON SCHEMAZip download
JSON SCHEMACreate a `zip` archive
JSON SCHEMAZip download status
JSON SCHEMAScroll within the panel for all 197 ·
JSON Structure 1
JSON Structure captures the data shapes in a form built for tooling — a complement to JSON Schema that keeps the model machine-legible.
JSON Structure definitions describing this provider's data shapes.
Box Structure
JSON STRUCTUREExamples 13
Real request and response payloads are what turn a spec from abstract into obvious — and they're one of the twelve things an agent needs to call an API correctly on the first try.
Example request and response payloads for these APIs.
Scroll within the panel for all 13 ·
Security Posture 2
Authentication, domain security, vulnerability disclosure, and trust-center signals — the evidence that a provider takes security seriously enough to document it. We profile it because you can't govern what you can't see.
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Scopes 1
OAuth scopes are the vocabulary of least-privilege access. Profiling them shows exactly what an integration — or an agent acting on a user's behalf — is allowed to do.
OAuth scopes governing access to this provider's APIs.
Agentic Access 1
An x-agentic-access contract marks which operations are safe for an agent to run on its own and which need a human in the loop. It is the difference between an API an agent can use and one it can use safely.
Recommended x-agentic-access execution contracts for AI agents.
Resources
Every other property we hold for Box — documentation, portals, status pages, policies, and corporate surface — grouped by the job it does, following the integrator's arc from getting started to running in production.
Get Started 3
Portal, sign-up, and the first successful call
Agent Surfaces 3
MCP servers, agent skills, and machine-readable catalogs
Build 9
SDKs, sample code, and the tooling you integrate with
Scroll within the panel for all 9 ·
Access & Security 3
Authentication, authorization, and security posture
Operate 5
Status, limits, changes, and where to get help
Commercial 3
Pricing, plans, and the legal terms of use
Company 4
The organization behind the API
Other 1
Properties that don't map to a standard resource type
← All providers · Data indexed from github.com/api-evangelist/box · machine-readable index on apis.io