Box
Service ID: box
Box empowers your teams by making it easy to work with people inside and outside your organization, protect your valuable content, and connect all your apps.
At a Glance
- Difficulty
- ✅STRAIGHTFORWARDSelf-Service OAuth App — No Box Review, No Partnership, Free Account Sufficient
- Authentication
- OAuth 2.0Authorization Code flow.
- Webhooks
- No webhooks — Box changes are picked up by polling instead.
- Partnership Required
- No(Box reviews an app only if you choose to publish it to the Box marketplace, which is optional.)
- Partnership Application
- Box Developer console↗
- Apideck Credentials
- AvailableTemporary shared credentials for trying the connector, branded Apideck on the Box authorisation screen. Going live needs your own Box app.
- Costs
- Free to build. A free Box account includes full API access; paid plans bundle a monthly call allowance.
- Sandbox Availability
- Not available(Box developer sandboxes are provisioned by an enterprise administrator, so they cannot be obtained on a free account.)
- Account Type Required
- Any Box account, including a free individual one.
- Consumer Access Level
- Any Box user can authorise access to their own account.
- Rate Limits
- 1,000 API calls per minute per user, with tighter limits on uploads and search.
What are Apideck credentials?
For select connectors, Apideck has established partnerships allowing you to integrate immediately without your own partnership. When using Apideck credentials, “Apideck” appears as the requesting application during OAuth. Learn more about partnership categories →
Responsibility matrix
| Task | You (Customer) | Your Consumer | Apideck |
|---|---|---|---|
| Registering the Box app and choosing its scopes | ✓ | — | — |
| Authorising the Box account | — | ✓ | — |
| Enabling the app where an enterprise restricts unpublished apps | — | ✓ (their Box admin, if required) | — |
| Exchanging and refreshing tokens | — | — | ✓ |
Environments
- Single environment
- Box does not separate testing from production: one app's credentials work against any Box account, so whatever you do while testing happens in the live account you connected.
- Testing
- Connect a Box account you created for testing rather than one holding real files.
🚨Important to Know About Box
- Some Box enterprises switch on a setting that blocks unpublished applications. A user there cannot connect until their own Box administrator enables the app once, by its Client ID. There is nothing to submit to Box and no review, and most enterprises leave the setting off.
- Box scopes are account-wide: the connection reaches everything the connecting user can already see in Box, and cannot be confined to a single folder.
- Box expires a refresh token after 60 days, but Apideck renews it before that, so a connection does not lapse merely from sitting idle. It needs authorising again only if the authorisation is withdrawn in Box or a renewal fails.
⚠️
2 gotchas across 1 resource
Connector-specific behaviors and limitations to be aware of
📦
4 supported resources
View field mappings, supported operations, and schema details