The API Report CardAPI Index
Box

Box API

Document Management Systems · box.com

Box publishes a mature REST API with 150 plus endpoints spanning files, users, collaborations, metadata, Box Sign, and Box AI. Access is fully self-serve at developer.box.com with OAuth 2.0, JWT, and client credentials auth. Official SDKs cover six languages and rate limits are published.

Last verified: August 2026Software & Data ToolsMCP READY
API GRADE
A
VERIFIED AUG 2026

SCORECARD

ExistenceGOODPublic REST API with 150 plus endpoints across files, users, collaborations, metadata, Sign, and AI.
AccessGOODFully self-serve developer portal at developer.box.com; free developer tokens for testing.
CoverageGOODFiles, users, sharing, metadata, Sign, AI, events, and governance surfaces like retention and legal holds.
AuthGOODOAuth 2.0 three-legged, JWT server auth, and client credentials grant, plus developer tokens.
Docs & DXGOODPublic docs, an OpenAPI spec, SDKs in six languages plus a CLI and UI Elements, and v2 webhooks.
StabilityGOODRate limits are published per user and per enterprise; webhooks are versioned with v1 and v2 both documented.
MCPGOODBox operates an official hosted MCP server at mcp.box.com with a supporting repo under the Box GitHub org and setup guides in the Box developer docs. It connects AI agents to Box content, search, and Box AI features. developer.box.com VERIFIED 2026-08
Supergood turns hard-to-integrate enterprise software into clean REST APIs and MCP tools: stable endpoints, normalized JSON, managed auth.

Frequently asked questions

Box scores A on Supergood's API Report Card. Box publishes a mature REST API with 150 plus endpoints spanning files, users, collaborations, metadata, Box Sign, and Box AI. Access is fully self-serve at developer.box.com with OAuth 2.0, JWT, and client credentials auth. Official SDKs cover six languages and rate limits are published.

Tried to integrate with Box?