Box
Box Enterprise.
Access mode: Read-only (typically)
Required information
| Field | Details |
|---|---|
| Enterprise ID | Box enterprise identifier. |
| Folder ID(s) | Target folders, or “all content” with appropriate scoping. |
| Box App | Custom App created in Box Developer Console with Server Authentication (Client Credentials Grant). |
| Scopes | Read-only: base_explorer, item_download. App must be authorized by Box admin. |
Network considerations
Fully managed SaaS. HTTPS to api.box.com. No VPN needed.
Box Shield: If enabled, external app access may be restricted. Admin must approve the custom app.
Credential and auth management
Preferred: Server Authentication (Client Credentials Grant). App authenticates as a service account. No user interaction needed. Admin authorization required.
Alternative: Server Authentication with JWT. App uses JWT assertion to obtain access token. Requires RSA keypair config.
Access scoping: Use Application Scopes and User Access Level to restrict what the service account can see.
Token expiry: 60 minutes. Flume handles refresh.
Validation checks
| Check | Method | Expected result |
|---|---|---|
| Authentication | GET https://api.box.com/2.0/users/me | Returns service account info |
| Folder access | GET https://api.box.com/2.0/folders/<id>/items | Lists folder contents |
| File download | GET https://api.box.com/2.0/files/<id>/content | Downloads file |
| Search | GET https://api.box.com/2.0/search?query=<term> | Returns results |
Every connection starts from the pre-engagement checklist and goes through the universal validation protocol before production sign-off.