Skip to content
Get startedRequest a demo
Document repositories

Box

Box Enterprise.

Access mode: Read-only (typically)

Required information

FieldDetails
Enterprise IDBox enterprise identifier.
Folder ID(s)Target folders, or “all content” with appropriate scoping.
Box AppCustom App created in Box Developer Console with Server Authentication (Client Credentials Grant).
ScopesRead-only: base_explorer, item_download. App must be authorized by Box admin.

Network considerations

Fully managed SaaS. HTTPS to api.box.com. No VPN needed.

Box Shield: If enabled, external app access may be restricted. Admin must approve the custom app.

Credential and auth management

Preferred: Server Authentication (Client Credentials Grant). App authenticates as a service account. No user interaction needed. Admin authorization required.

Alternative: Server Authentication with JWT. App uses JWT assertion to obtain access token. Requires RSA keypair config.

Access scoping: Use Application Scopes and User Access Level to restrict what the service account can see.

Token expiry: 60 minutes. Flume handles refresh.

Validation checks

CheckMethodExpected result
AuthenticationGET https://api.box.com/2.0/users/meReturns service account info
Folder accessGET https://api.box.com/2.0/folders/<id>/itemsLists folder contents
File downloadGET https://api.box.com/2.0/files/<id>/contentDownloads file
SearchGET https://api.box.com/2.0/search?query=<term>Returns results

Every connection starts from the pre-engagement checklist and goes through the universal validation protocol before production sign-off.