Box MCP Server (Official)

Official Box MCP server enabling AI agents to interact with Box's content management platform — reading, uploading, searching, and organizing files and folders; managing permissions; and accessing Box's AI features.

Evaluated Mar 06, 2026 (0d ago) vcurrent
Homepage ↗ Repo ↗ Other box cloud-storage documents mcp-server official enterprise collaboration file-management
⚙ Agent Friendliness
79
/ 100
Can an agent use this?
🔒 Security
89
/ 100
Is it safe for agents?
⚡ Reliability
84
/ 100
Does it work consistently?

Score Breakdown

⚙ Agent Friendliness

MCP Quality
80
Documentation
85
Error Messages
80
Auth Simplicity
65
Rate Limits
78

🔒 Security

TLS Enforcement
100
Auth Strength
88
Scope Granularity
85
Dep. Hygiene
85
Secret Handling
88

HTTPS enforced. JWT app authentication with scopes. FedRAMP, SOC 2, ISO 27001, HIPAA, PCI DSS. Enterprise content management security.

⚡ Reliability

Uptime/SLA
90
Version Stability
85
Breaking Changes
82
Error Recovery
80
AF Security Reliability

Best When

An agent needs to read, manage, or search enterprise documents stored in Box — particularly when using Box AI for document intelligence.

Avoid When

Your organization uses Google Drive or SharePoint — use those integrations instead.

Use Cases

  • Reading and analyzing documents stored in Box from knowledge agents
  • Searching Box content for relevant files using Box AI
  • Uploading agent-generated documents and reports to Box
  • Managing file permissions and sharing for collaboration agents
  • Using Box AI to extract insights from stored documents

Not For

  • Teams using Google Drive, Dropbox, or SharePoint for storage
  • Real-time collaborative document editing
  • Simple file hosting without enterprise governance needs

Interface

REST API
Yes
GraphQL
No
gRPC
No
MCP Server
Yes
SDK
Yes
Webhooks
Yes

Authentication

Methods: oauth2 jwt client_credentials
OAuth: Yes Scopes: Yes

Server-side authentication via JWT (app users) or Client Credentials Grant for agent use. OAuth 2.0 for user-delegated. Scopes control resource access.

Pricing

Model: per-seat
Free tier: Yes
Requires CC: No

Enterprise features require paid plans. Box AI requires Enterprise Plus or above. MCP server is open source.

Agent Metadata

Pagination
offset
Idempotent
Partial
Retry Guidance
Documented

Known Gotchas

  • JWT auth setup requires RSA key pair and Box app configuration — complex onboarding
  • App users vs actual users distinction — agents should use app users for automated workflows
  • File IDs are mandatory for all operations — must discover IDs before operating
  • Box AI requires Enterprise Plus license — verify plan before building AI features
  • Folder structure traversal requires recursive API calls
  • Webhook signatures for security — implement verification for inbound webhooks

Alternatives

Full Evaluation Report

Detailed scoring breakdown, competitive positioning, security analysis, and improvement recommendations for Box MCP Server (Official).

$99

Scores are editorial opinions as of 2026-03-06.

5178
Packages Evaluated
26151
Need Evaluation
173
Need Re-evaluation
Community Powered