Need help with your APIs? I offer API discovery, governance & evangelism services. Explore services →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC
Box website screenshot

Box

Box is a cloud content management and file sharing service for businesses. Box provides a secure platform for storing, managing, and sharing files and content, with features for collaboration, workflow automation, and integration with other business applications.

agent ready

Solid contracts, transparent operations, and an easy start — typically complete on four or five facets with one clear soft spot.

Kin Score

API Evangelist profiles Box the way a machine reads it — 319 machine-readable artifacts across 81 APIs, pulled from the provider's own public surface and indexed so a developer, an analyst, or an AI agent can evaluate it against every other provider on the network.

Every provider in the network is reduced to the same set of machine-readable artifacts — OpenAPI contracts, event specifications, GraphQL schemas, runnable collections, pricing and rate-limit signals, security posture, OAuth scopes, and the agent surfaces (MCP servers and skills) that let software drive the API on its own. We profile them because the interface is the part of a company you can actually inspect: it is a truer signal of what a provider does than any marketing page. From those artifacts we compute the Kin Score — Box scores 66.7/100 (strong), with a separate agent-readiness read of 60/100 (agent ready). The full breakdown is below, followed by every artifact we hold — each card links through to its machine-readable definition on apis.io.

Kin Score

This is the API Evangelist rating — a single, repeatable read computed from the artifacts on this page. Green fill is points earned; the red track is points possible, so every bar shows earned-versus-possible at a glance.

Kin Score Kin Score How this is scored →
scored 2026-07-27 · rubric v0.5
Composite quality — 66.7/100 · strong
Contract Quality 12.5 / 25
Developer Ergonomics 10.4 / 20
Commercial Clarity 16.8 / 20
Operational Transparency 8.9 / 13
Governance 8.8 / 12
Discoverability 9.3 / 10
Agent readiness — 60/100 · agent ready
Machine-Readable Contract 18 / 18
Agentic Access Contract 15 / 15
MCP Server 12 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3

How we profile Box

Each block below is one kind of artifact we hold for Box. For each we say what it is and why it earns a place in the profile, then list every one we've indexed — capped at two rows, scroll within the panel for the rest.

APIs 81

Each API is captured as its own OpenAPI definition — every operation, parameter, and response. This is the single most useful machine-readable description of what an API does, and it's what lets us score, lint, mock, and generate against it without asking the provider for anything.

Individual APIs this provider publishes, each with its own machine-readable definition.

Box Authorization API

A set of endpoints used to manage user authorization process.

Box Authorize API

The Authorize API from Box — 1 operation(s) for authorize.

Box Classifications API

Classification labels are used for content that is sensitive or under security restrictions.

Box Classifications on Files API

Classification labels are used for files that are sensitive or under security restrictions.

Box Classifications on Folders API

Classification labels are used for folders that are sensitive or under security restrictions.

Box Collaboration Whitelist Entries API

The Collaboration Whitelist Entries API from Box — 2 operation(s) for collaboration whitelist entries.

Box Collaboration Whitelist Exempt Targets API

The Collaboration Whitelist Exempt Targets API from Box — 2 operation(s) for collaboration whitelist exempt targets.

Box Collaborations API

Collaborations define access permissions for users and groups to files and folders, similar to access control lists.

Box Collaborations (List) API

A set of endpoints used to retrieve file, folder, pending, and group collaborations.

Box Collections API

Collections are a way to group files, folders, and web links without putting them all into a folder.

Box Comments API

Comments are messages generated users on files, allowing users to collaborate on a file, discussing any feedback they might have on the content.

Box Device Pinners API

Device pinners allow enterprises to control what devices can use native Box applications.

Box Domain Restrictions for Collaborations API

A set of endpoints that manage domains for which users can collaborate with files and folders in an enterprise.

Box Domain Restrictions (User Exemptions) API

A set of endpoints that allow exempting users from restrictions imposed by the list of allowed collaboration domains for a specific enterprise.

Box Downloads API

Downloads allow saving files to the application's server, or directly by the end user in a browser.

Box Email Aliases API

Email aliases provide a list of emails additional to the user's primary login email.

Box Enterprises API

The Enterprises API from Box — 1 operation(s) for enterprises.

Box Events API

Events provide a way for an application to subscribe to any actions performed by any user, users, or service in an enterprise.

Box File Requests API

File Requests provide a fast and secure way to request files and associated metadata from anyone. Users can create new file requests based on an existing file request, update fi...

Box File Version Legal Holds API

A legal hold is a process that an enterprise can use to preserve all forms of potentially relevant information when litigation is pending or reasonably anticipated. A File Versi...

Box File Version Retentions API

A retention policy blocks permanent deletion of content for a specified amount of time. A file version retention is a record for a retained file.

Box File Versions API

A set of endpoints used to manage specific versions of a file.

Box Files API

Files, together with Folders, are at the core of the Box API. Files can be uploaded and downloaded, as well as hold important metadata information about the content.

Box Folder Locks API

Folder locks define access restrictions placed by folder owners to prevent specific folders from being moved or deleted.

Box Folders API

Folders, together with Files, are at the core of the Box API. Folders can be uploaded and downloaded, as well as hold important metadata information about the content.

Box Group Memberships API

Group memberships signify that a user is a part of the group.

Box Groups API

Groups created in an enterprise.

Box Integration Mappings API

Integration Mappings allow the users to manage where content from partner apps is stored in Box.

Box Invites API

Invites are used to invite the user to an enterprise.

Box Legal Hold Policies API

A legal hold is a process that an enterprise can use to preserve all forms of potentially relevant information when litigation is pending or reasonably anticipated.

Box Legal Hold Policy Assignments API

A Legal Hold Policy Assignment is a relation between a policy and custodian. In this case, as custodian can be a user, folder, file, or file version.

Box Metadata Cascade Policies API

A metadata cascade policy describes how metadata instances applied to a folder should be applied to any item within that folder.

Box Metadata Instances (Files) API

A metadata instance describes the relation between a template and a file, including the values that are assigned for every field.

Box Metadata Instances (Folders) API

A metadata instance describes the relation between a template and a folder, including the values that are assigned for every field.

Box Metadata Queries API

The Metadata Queries API from Box — 1 operation(s) for metadata queries.

Box Metadata Templates API

A metadata template describes a reusable set of key/value pairs that can be assigned to a file.

Box Oauth2 API

The Oauth2 API from Box — 3 operation(s) for oauth2.

Box Recent Items API

Recent items represent items such as files or folders that the user accessed recently.

Box Retention Policies API

A retention policy blocks permanent deletion of content for a specified amount of time. Admins can create retention policies and then assign them to specific folders or their en...

Box Retention Policy Assignments API

A Retention Policy Assignment is a relation between a policy and folder or enterprise. Creating an assignment puts a retention on all the file versions that belong to that folde...

Box Search API

The Box API provides a way to find content in Box using full-text search queries.

Box Session Termination API

Session termination API is used to validate the roles and permissions of the group, and creates asynchronous jobs to terminate the group's sessions.

Box Shared Items API

The Shared Items API from Box — 1 operation(s) for shared items.

Box Shared Items#folders API

The Shared Items#folders API from Box — 1 operation(s) for shared items#folders.

Box Shared Items#web Links API

The Shared Items#web Links API from Box — 1 operation(s) for shared items#web links.

Box Shared Links (Files) API

Files shared links are URLs that are generated for files stored in Box, which provide direct, read-only access to the resource.

Box Shared Links (Folders) API

Folders shared links are URLs that are generated for folders stored in Box, which provide direct, read-only access to the resource.

Box Shared Links (Web Links) API

Web links for files are URLs that are generated for web links in Box, which provide direct, read-only access to the resource.

Box Shield Information Barrier Reports API

Shield information barrier reports contain information on what existing collaborations will be removed permanently when the information barrier is enabled.

Box Shield Information Barrier Segment Members API

Shield information barrier segment member represents a user that is assigned to a specific segment.

Box Shield Information Barrier Segment Restrictions API

Shield information barrier segment restriction is an access restriction based on the content (file or folder) owner.

Box Shield Information Barrier Segments API

Shield information barrier segment represents a defined group of users. A user can be a member of only one segment, which makes segments different from groups.

Box Shield Information Barriers API

Shield information barrier in Box defines an ethical wall. An ethical wall is a mechanism that prevents exchanges or communication that could lead to conflicts of interest and t...

Box Sign Requests API

Sign requests are used to submit a file for signature.

Box Sign Templates API

Sign templates allow you to use a predefined Box Sign template when creating a sign request. The template includes placeholders that are automatically populated with data when c...

Box Skill Invocations API

The Skill Invocations API from Box — 1 operation(s) for skill invocations.

Box Skills API

Box Skills are designed to allow custom processing of files uploaded to Box, with the intent of enhancing the underlying metadata of the file.

Box Standard and Zones Storage Policies API

Storage policy assignment represents the storage zone for items in a given enterprise.

Box Standard and Zones Storage Policy Assignments API

Storage policy assignment represents the relation between storage zone and the assigned item (for example a file stored in a specific zone).

Box Storage Policies API

The Storage Policies API from Box — 2 operation(s) for storage policies.

Box Storage Policy Assignments API

The Storage Policy Assignments API from Box — 2 operation(s) for storage policy assignments.

Box Task Assignments API

A task assignment defines which task is assigned to which user to complete.

Box Tasks API

Tasks allow users to request collaborators on a file to review a file or complete a piece of work. Tasks can be used by developers to create file-centric workflows.

Box Terms of Service API

A set of endpoints used to manage terms of service agreements.

Box Terms of Service User Statuses API

A set of endpoints used to manage the status of terms of service for a particular user.

Box Terms of Services API

The Terms of Services API from Box — 2 operation(s) for terms of services.

Box Transfer Folders API

API designed to move all of the items (files, folders and workflows) owned by a user into another user's account.

Box Trashed Files API

Files that were deleted and are in trash.

Box Trashed Folders API

Folders that were deleted and are in trash.

Box Trashed Items API

Items that were deleted and are in trash.

Box Trashed Web Links API

Web links that were deleted and are in trash.

Box Uploads API

The direct file upload API supports files up to 50MB in size and sends all the binary data to the Box API in 1 API request.

Box Uploads (Chunked) API

The chunked upload endpoints support files from 20MB in size and allow an application to upload the file in parts, allowing for more control to catch any errors and retry parts ...

Box User Avatars API

User avatars are JPG or PNG files uploaded to Box to represent the user image. They are then displayed in the user account.

Box Users API

Box API supports a variety of users, ranging from real employees logging in with their Managed User account, to applications using App Users to drive powerful automation workflows.

Box Watermarks (Files) API

A watermark is a semi-transparent overlay on an embedded file preview that displays a viewer's email address or user ID and the time of access over the file.

Box Watermarks (Folders) API

A watermark is a semi-transparent overlay on an embedded folder preview that displays a viewer's email address or user ID and the time of access over the folder content.

Box Web Links API

Web links are objects that point to URLs. These objects are also known as bookmarks within the Box web application.

Box Webhooks API

Webhooks allow you to monitor Box content for events, and receive notifications to a URL of your choice when they occur. For example, a workflow may include waiting for a file t...

Box Workflows API

Box Relay Workflows are objects that represent a named collection of flows.

Box Zip Downloads API

Zip downloads represent a successful request to create a ZIP archive with files and folders.

Scroll within the panel for all 81 ·

MCP Servers 1

Model Context Protocol servers expose these APIs directly to AI agents. We profile them because agent-native access is the fastest-growing way this provider's capabilities actually get used.

Model Context Protocol servers that expose these APIs to AI agents.

MCP Server

MCP SERVER

GraphQL 1

Where a provider ships GraphQL, the schema is the contract. We profile it alongside the REST surface so the whole interface is legible in one place.

GraphQL schemas published by this provider.

Box GraphQL Schema

This directory contains a conceptual GraphQL schema for the Box cloud content management platform. Box exposes a REST API (v2) at `https://api.box.com/2.0`. The schema in `box-s...

GRAPHQL

Pricing Plans 1

Pricing is part of the interface. Machine-readable plans tell you what a tier costs and includes before you commit — one of the six things the Kin Score reads for commercial clarity.

Published pricing tiers and plan structures.

Box Plans Pricing

8 plans

PLANS

Rate Limits 1

Rate limits are the difference between a demo that works and a production integration that doesn't fall over. Publishing them is an operational-transparency signal — and a hard requirement for any agent that plans its own throughput.

Documented rate limits and quota policies.

Box Rate Limits

5 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals let a buyer model the financial operations of an API before it's live. We profile them for the same reason we profile pricing: the money is part of the contract.

Cost, billing, and metering signals for API financial operations.

Box Finops

FINOPS

Features 16

The notable capabilities this provider advertises, captured as structured features so they can be searched and compared instead of read one landing page at a time.

Notable capabilities this provider offers.

Individual Free with 10 GB and 5 Box Sign requests/mo
Business at unlimited storage, 50K API calls/mo, integrated Box AI
Business Plus with unlimited external collaborators
Enterprise with 1K AI Units/mo, 100K API calls, FedRAMP/HIPAA
Enterprise Plus with 2K AI Units, 24-hr enhanced support
Enterprise Advanced (35-user min) with 20K AI Units, 200K API calls, Box Agent
REST API for files, folders, users, collaborations, metadata
Box Sign API for e-signatures
Box AI API for content Q&A and generation
Per-user 1,000 req/min cap
100 concurrent upload sessions
Webhooks v2 for content events
OAuth 2.0, JWT app auth, CCG (Client Credentials Grant)
Box Skills for AI-powered metadata extraction
Box Relay for workflow automation
1,500+ integrations on Business+

Scroll within the panel for all 16 ·

Spectral Rules 2

Governance rulesets we run against this provider's specs — the automated checks behind parts of the score. Profiling them makes the quality bar explicit and re-runnable, not a matter of opinion.

Box API Rules

5 rules · 4 warnings

SPECTRAL

Box API Rules

10 rules · 1 errors · 9 warnings

SPECTRAL

JSON Schema 197

Standalone JSON Schema definitions describe the data models behind the API. We profile them so the shapes are validatable on their own — useful long after a single request is forgotten.

Standalone JSON Schema definitions for this provider's data models.

Access token

6 properties

JSON SCHEMA

Classification

8 properties

JSON SCHEMA

Classification Template

8 properties

JSON SCHEMA

Client error

7 properties

JSON SCHEMA

Collaboration

14 properties

JSON SCHEMA

Allowed collaboration domains

0 properties

JSON SCHEMA

Allowed collaboration domain

6 properties

JSON SCHEMA

Collaborations

0 properties

JSON SCHEMA

Collection

4 properties

JSON SCHEMA

Collections

0 properties

JSON SCHEMA

Comment (Base)

2 properties

JSON SCHEMA

Comment (Full)

0 properties

JSON SCHEMA

Comment

0 properties

JSON SCHEMA

Comments

0 properties

JSON SCHEMA

Conflict error

0 properties

JSON SCHEMA

Device pinner

4 properties

JSON SCHEMA

Device pinners

4 properties

JSON SCHEMA

Email alias

4 properties

JSON SCHEMA

Email aliases

2 properties

JSON SCHEMA

Enterprise (Base)

2 properties

JSON SCHEMA

Event

9 properties

JSON SCHEMA

Events

3 properties

JSON SCHEMA

Event source

6 properties

JSON SCHEMA

File (Base)

3 properties

JSON SCHEMA

File (Full)

0 properties

JSON SCHEMA

File (Mini)

0 properties

JSON SCHEMA

File

0 properties

JSON SCHEMA

File (Conflict)

0 properties

JSON SCHEMA

File or folder scope

2 properties

JSON SCHEMA

File Request

15 properties

JSON SCHEMA

File Request (Copy)

0 properties

JSON SCHEMA

File Request (Update)

6 properties

JSON SCHEMA

Files

2 properties

JSON SCHEMA

Files under retention

0 properties

JSON SCHEMA

File version (Base)

2 properties

JSON SCHEMA

File version (Full)

0 properties

JSON SCHEMA

File version (Mini)

0 properties

JSON SCHEMA

File version

0 properties

JSON SCHEMA

File version legal hold

6 properties

JSON SCHEMA

File version legal holds

0 properties

JSON SCHEMA

File version retention

7 properties

JSON SCHEMA

File version retentions

0 properties

JSON SCHEMA

File versions

0 properties

JSON SCHEMA

Folder (Base)

3 properties

JSON SCHEMA

Folder (Full)

0 properties

JSON SCHEMA

Folder (Mini)

0 properties

JSON SCHEMA

Folder

0 properties

JSON SCHEMA

Folder Lock

7 properties

JSON SCHEMA

Folder Locks

3 properties

JSON SCHEMA

Generic source

0 properties

JSON SCHEMA

Group (Base)

2 properties

JSON SCHEMA

Group (Full)

0 properties

JSON SCHEMA

Group (Mini)

0 properties

JSON SCHEMA

Group

0 properties

JSON SCHEMA

Group membership

7 properties

JSON SCHEMA

Group memberships

0 properties

JSON SCHEMA

Groups

0 properties

JSON SCHEMA

Integration mapping (Base)

2 properties

JSON SCHEMA

Integration mapping (Mini)

0 properties

JSON SCHEMA

Integration mapping

0 properties

JSON SCHEMA

Integration mappings

0 properties

JSON SCHEMA

Create integration mapping request

3 properties

JSON SCHEMA

Invite

8 properties

JSON SCHEMA

Items

0 properties

JSON SCHEMA

Keyword Skill Card

7 properties

JSON SCHEMA

Legal hold policies

0 properties

JSON SCHEMA

Legal hold policy (Mini)

2 properties

JSON SCHEMA

Legal hold policy

0 properties

JSON SCHEMA

Legal hold policy assignment (Base)

2 properties

JSON SCHEMA

Legal hold policy assignment

0 properties

JSON SCHEMA

Legal hold policy assignments

0 properties

JSON SCHEMA

Metadata instance (Base)

4 properties

JSON SCHEMA

Metadata instance (Full)

0 properties

JSON SCHEMA

Metadata instance

0 properties

JSON SCHEMA

Metadata cascade policies

0 properties

JSON SCHEMA

Metadata cascade policy

6 properties

JSON SCHEMA

Metadata field filter (date range)

0 properties

JSON SCHEMA

Metadata field filter (float)

0 properties

JSON SCHEMA

Metadata field filter (float range)

0 properties

JSON SCHEMA

Metadata field filter (multi-select)

0 properties

JSON SCHEMA

Metadata field filter (string)

0 properties

JSON SCHEMA

Metadata filter

3 properties

JSON SCHEMA

Metadata query search request

8 properties

JSON SCHEMA

Metadata query index

4 properties

JSON SCHEMA

Metadata query search results

3 properties

JSON SCHEMA

Metadata instances

2 properties

JSON SCHEMA

Metadata template

8 properties

JSON SCHEMA

Metadata templates

0 properties

JSON SCHEMA

OAuth 2.0 error

2 properties

JSON SCHEMA

Token revocation request

3 properties

JSON SCHEMA

Refresh access token

4 properties

JSON SCHEMA

Token request

15 properties

JSON SCHEMA

Real-time server

5 properties

JSON SCHEMA

Real-time servers

2 properties

JSON SCHEMA

Recent item

5 properties

JSON SCHEMA

Recent items

0 properties

JSON SCHEMA

Retention policies

0 properties

JSON SCHEMA

Retention policy (Base)

2 properties

JSON SCHEMA

Retention policy (Mini)

0 properties

JSON SCHEMA

Retention policy

0 properties

JSON SCHEMA

Retention policy assignment (Base)

2 properties

JSON SCHEMA

Retention policy assignment

8 properties

JSON SCHEMA

Retention policy assignments

0 properties

JSON SCHEMA

Search Results

0 properties

JSON SCHEMA

Search Result (including Shared Link)

3 properties

JSON SCHEMA

Session termination message

1 properties

JSON SCHEMA

Shield information barrier (Base)

2 properties

JSON SCHEMA

Shield information barrier

10 properties

JSON SCHEMA

Shield information barrier reference

1 properties

JSON SCHEMA

Shield information barrier report

0 properties

JSON SCHEMA

List of Shield Information Barriers

0 properties

JSON SCHEMA

Shield information barrier segment

9 properties

JSON SCHEMA

Sign Request (Base)

13 properties

JSON SCHEMA

Sign Request

0 properties

JSON SCHEMA

Create a sign request

0 properties

JSON SCHEMA

Signer fields for Create Sign Request

11 properties

JSON SCHEMA

Sign Request Prefill Tag

4 properties

JSON SCHEMA

Box Sign

0 properties

JSON SCHEMA

Sign Request Signer Input

0 properties

JSON SCHEMA

Box Sign template

0 properties

JSON SCHEMA

Box Sign templates

0 properties

JSON SCHEMA

Skills metadata instance

9 properties

JSON SCHEMA

Skill webhook payload

10 properties

JSON SCHEMA

Status Skill Card

7 properties

JSON SCHEMA

Storage policies

0 properties

JSON SCHEMA

Storage policy (Mini)

2 properties

JSON SCHEMA

Storage policy

0 properties

JSON SCHEMA

Storage policy assignment

4 properties

JSON SCHEMA

Storage policy assignments

0 properties

JSON SCHEMA

Task

11 properties

JSON SCHEMA

Task assignment

10 properties

JSON SCHEMA

Task assignments

2 properties

JSON SCHEMA

Tasks

2 properties

JSON SCHEMA

Signer fields for Templates

0 properties

JSON SCHEMA

Template Signer Input

0 properties

JSON SCHEMA

Terms of service (Base)

2 properties

JSON SCHEMA

Terms of service

0 properties

JSON SCHEMA

Terms of services

2 properties

JSON SCHEMA

Terms of service user status

7 properties

JSON SCHEMA

Terms of service user statuses

2 properties

JSON SCHEMA

Timeline Skill Card

8 properties

JSON SCHEMA

Tracking code

3 properties

JSON SCHEMA

Transcript Skill Card

8 properties

JSON SCHEMA

Trashed File

22 properties

JSON SCHEMA

Trashed File (Restored)

22 properties

JSON SCHEMA

Trashed Folder

21 properties

JSON SCHEMA

Trashed Folder (Restored)

21 properties

JSON SCHEMA

Trashed Web Link

18 properties

JSON SCHEMA

Trashed Web Link (Restored)

18 properties

JSON SCHEMA

Uploaded part

1 properties

JSON SCHEMA

Upload part (Mini)

3 properties

JSON SCHEMA

Upload part

0 properties

JSON SCHEMA

Upload parts

0 properties

JSON SCHEMA

Upload session

7 properties

JSON SCHEMA

Upload URL

2 properties

JSON SCHEMA

User (Base)

2 properties

JSON SCHEMA

User (Collaborations)

0 properties

JSON SCHEMA

User (Full)

0 properties

JSON SCHEMA

User (Mini)

0 properties

JSON SCHEMA

User

0 properties

JSON SCHEMA

User avatar

1 properties

JSON SCHEMA

User (Integration Mappings)

0 properties

JSON SCHEMA

Users

0 properties

JSON SCHEMA

Watermark

1 properties

JSON SCHEMA

Webhook (Mini)

3 properties

JSON SCHEMA

Webhook

0 properties

JSON SCHEMA

Webhook (V2) payload

7 properties

JSON SCHEMA

Webhooks

0 properties

JSON SCHEMA

Web link (Base)

3 properties

JSON SCHEMA

Web link (Mini)

0 properties

JSON SCHEMA

Web link

0 properties

JSON SCHEMA

Workflow (Full)

0 properties

JSON SCHEMA

Workflow (Mini)

5 properties

JSON SCHEMA

Workflow

0 properties

JSON SCHEMA

Workflows

0 properties

JSON SCHEMA

Zip download

4 properties

JSON SCHEMA

Create a `zip` archive

2 properties

JSON SCHEMA

Zip download status

5 properties

JSON SCHEMA

Scroll within the panel for all 197 ·

JSON Structure 1

JSON Structure captures the data shapes in a form built for tooling — a complement to JSON Schema that keeps the model machine-legible.

JSON Structure definitions describing this provider's data shapes.

Box Structure

0 properties

JSON STRUCTURE

Examples 13

Real request and response payloads are what turn a spec from abstract into obvious — and they're one of the twelve things an agent needs to call an API correctly on the first try.

Example request and response payloads for these APIs.

Scroll within the panel for all 13 ·

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals — the evidence that a provider takes security seriously enough to document it. We profile it because you can't govern what you can't see.

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Box Authentication

oauth2 · 1 scheme

SECURITY

Box Domain Security

TLSv1.3 · HSTS · DNSSEC · DMARC

SECURITY

Scopes 1

OAuth scopes are the vocabulary of least-privilege access. Profiling them shows exactly what an integration — or an agent acting on a user's behalf — is allowed to do.

OAuth scopes governing access to this provider's APIs.

Box Scopes

9 scopes · authorizationCode

9 scopes

SCOPES

Agentic Access 1

An x-agentic-access contract marks which operations are safe for an agent to run on its own and which need a human in the loop. It is the difference between an API an agent can use and one it can use safely.

Recommended x-agentic-access execution contracts for AI agents.

Box Agentic Access

537 operations · 291 acting · 14 human-in-the-loop

537 operations · 291 acting

AGENTIC

Resources

Every other property we hold for Box — documentation, portals, status pages, policies, and corporate surface — grouped by the job it does, following the integrator's arc from getting started to running in production.

Get Started 3

Portal, sign-up, and the first successful call

Agent Surfaces 3

MCP servers, agent skills, and machine-readable catalogs

Access & Security 3

Authentication, authorization, and security posture

Commercial 3

Pricing, plans, and the legal terms of use

Other 1

Properties that don't map to a standard resource type

← All providers · Data indexed from github.com/api-evangelist/box · machine-readable index on apis.io