{
 "categories": [
  "documents",
  "collaboration",
  "enterprise"
 ],
 "deployment": "saas",
 "evidence": [
  {
   "date": "2026-08-21",
   "fact": "homepage",
   "note": "Box presents itself as an intelligent content-management platform for collaboration, Box AI, security, and e-signature.",
   "source": "https://www.box.com",
   "tier": "declared"
  },
  {
   "date": "2026-08-21",
   "fact": "license",
   "note": "Box markets enterprise content, security, and compliance capabilities as a commercial cloud platform.",
   "source": "https://www.box.com",
   "tier": "declared"
  },
  {
   "date": "2026-08-21",
   "fact": "modalities.api.exists",
   "note": "Box documents that every API endpoint requires a valid access token and shows calls to https://api.box.com/2.0/.",
   "source": "https://developer.box.com/guides/authentication/index",
   "tier": "declared"
  },
  {
   "date": "2026-08-21",
   "fact": "modalities.api.kinds[0]",
   "note": "The documented public interface is HTTP to api.box.com with Bearer access tokens, which is Box's REST Platform API.",
   "source": "https://developer.box.com/guides/authentication/index",
   "tier": "declared"
  },
  {
   "date": "2026-08-21",
   "fact": "modalities.api.auth[0]",
   "note": "Box documents OAuth 2.0 login for user-facing applications, including the official CLI box login flow.",
   "source": "https://developer.box.com/guides/cli/index",
   "tier": "declared"
  },
  {
   "date": "2026-08-21",
   "fact": "modalities.api.auth[1]",
   "note": "Box documents JWT as a server-authentication method for the CLI and Platform apps.",
   "source": "https://developer.box.com/guides/cli/index",
   "tier": "declared"
  },
  {
   "date": "2026-08-21",
   "fact": "modalities.api.auth[2]",
   "note": "Box documents Client Credentials Grant (CCG) as a server-authentication method using client ID, client secret, and enterprise ID.",
   "source": "https://developer.box.com/guides/cli/index",
   "tier": "declared"
  },
  {
   "date": "2026-08-21",
   "fact": "modalities.api.coverage",
   "note": "Maintained official SDKs are documented as having full API parity for Java, iOS, .NET, Python, and Node. Product surfaces such as Sign and Hubs are additional APIs rather than a single complete CRUD surface.",
   "source": "https://developer.box.com/guides/tooling/sdks/index",
   "tier": "declared"
  },
  {
   "date": "2026-08-21",
   "fact": "modalities.sdk.exists",
   "note": "Box publishes official SDKs and states the Java, iOS, .NET, Python, and Node projects are maintained.",
   "source": "https://developer.box.com/guides/tooling/sdks/index",
   "tier": "declared"
  },
  {
   "date": "2026-08-21",
   "fact": "modalities.sdk.languages[0]",
   "note": "Box lists a maintained Java SDK with full API parity.",
   "source": "https://developer.box.com/guides/tooling/sdks/index",
   "tier": "declared"
  },
  {
   "date": "2026-08-21",
   "fact": "modalities.sdk.languages[1]",
   "note": "Box lists a maintained .NET SDK with full API parity.",
   "source": "https://developer.box.com/guides/tooling/sdks/index",
   "tier": "declared"
  },
  {
   "date": "2026-08-21",
   "fact": "modalities.sdk.languages[2]",
   "note": "Box lists a maintained Python SDK with full API parity.",
   "source": "https://developer.box.com/guides/tooling/sdks/index",
   "tier": "declared"
  },
  {
   "date": "2026-08-21",
   "fact": "modalities.sdk.languages[3]",
   "note": "Box lists a maintained Node SDK with full API parity.",
   "source": "https://developer.box.com/guides/tooling/sdks/index",
   "tier": "declared"
  },
  {
   "date": "2026-08-21",
   "fact": "modalities.mcp.first_party",
   "note": "Box documents a vendor-hosted MCP server at https://mcp.box.com. Admins enable it in the Admin Console; users authorize with OAuth.",
   "source": "https://developer.box.com/guides/box-mcp",
   "tier": "declared"
  },
  {
   "date": "2026-08-21",
   "fact": "modalities.integrations.zapier",
   "note": "Zapier documents a Box app with file, folder, comment, and event triggers plus upload, share, AI, metadata, and user actions.",
   "source": "https://zapier.com/apps/box/integrations",
   "tier": "scraped"
  },
  {
   "date": "2026-08-21",
   "fact": "modalities.integrations.make",
   "note": "Make documents a verified, Make-maintained Box app with file, folder, metadata, comment, and Sign-request modules.",
   "source": "https://www.make.com/en/integrations/box",
   "tier": "scraped"
  },
  {
   "date": "2026-08-21",
   "fact": "modalities.integrations.power_automate",
   "note": "Microsoft publishes a Standard Box connector for Power Automate, Logic Apps, Power Apps, and Copilot Studio with file create, update, get, and delete actions.",
   "source": "https://learn.microsoft.com/en-us/connectors/box/",
   "tier": "scraped"
  },
  {
   "date": "2026-08-21",
   "fact": "modalities.integrations.n8n",
   "note": "n8n documents a built-in Box node for file copy, delete, download, upload, search, and share, plus folder create, get, delete, and update.",
   "source": "https://docs.n8n.io/integrations/builtin/app-nodes/n8n-nodes-base.box/",
   "tier": "scraped"
  },
  {
   "date": "2026-08-21",
   "fact": "modalities.cli.exists",
   "note": "Box documents an official CLI installed via the box or @box/cli npm packages, with JSON output and OAuth, JWT, and CCG authentication.",
   "source": "https://developer.box.com/guides/cli/index",
   "tier": "declared"
  },
  {
   "date": "2026-08-21",
   "fact": "modalities.extensibility.webhooks",
   "note": "Box's developer llms.txt indexes Webhooks overview plus V1 and V2 create, list, update, delete, and signature-verification guides.",
   "source": "https://developer.box.com/llms.txt",
   "tier": "declared"
  },
  {
   "date": "2026-08-21",
   "fact": "modalities.data_access.export[0]",
   "note": "The official CLI and Platform API retrieve file content and metadata; the CLI quickstart returns structured user JSON via box users:get me.",
   "source": "https://developer.box.com/guides/cli/index",
   "tier": "declared"
  },
  {
   "date": "2026-08-21",
   "fact": "modalities.data_access.import[0]",
   "note": "Box documents CLI and API upload and file-management commands as the supported way to put content into Box.",
   "source": "https://developer.box.com/guides/cli/index",
   "tier": "declared"
  },
  {
   "date": "2026-08-21",
   "fact": "modalities.agent_docs.llms_txt",
   "note": "Box publishes a genuine developer llms.txt that indexes authentication, SDKs, CLI, webhooks, and MCP documentation.",
   "source": "https://developer.box.com/llms.txt",
   "tier": "declared"
  },
  {
   "date": "2026-08-21",
   "fact": "verdict.scores.api",
   "note": "The Platform API is documented, token-authenticated, and backed by maintained official SDKs with full parity. Custom-app API requests are chargeable and some product areas are separate APIs, which keeps the path below unusual completeness.",
   "source": "https://developer.box.com/guides/authentication/index",
   "tier": "declared"
  },
  {
   "date": "2026-08-21",
   "fact": "verdict.scores.mcp",
   "note": "The official hosted server has OAuth and useful search, AI, and folder tools, but an admin must enable it and some scopes need Enterprise Advanced. The self-hosted community server is deprecated.",
   "source": "https://developer.box.com/guides/box-mcp",
   "tier": "declared"
  },
  {
   "date": "2026-08-21",
   "fact": "verdict.scores.integrations",
   "note": "Zapier, Make, n8n, and Microsoft Power Automate all expose Box file and folder connectors. The Power Automate connector documents size, folder-count, and SSO limits.",
   "source": "https://learn.microsoft.com/en-us/connectors/box/",
   "tier": "scraped"
  },
  {
   "date": "2026-08-21",
   "fact": "verdict.scores.cli",
   "note": "The official CLI is documented for Linux, Windows, and macOS, supports JSON output and multiple auth methods, and Box says it works with agentic tools. Default user login is limited to files, folders, AI, and Sign unless a platform app adds scopes.",
   "source": "https://developer.box.com/guides/cli/index",
   "tier": "declared"
  },
  {
   "date": "2026-08-21",
   "fact": "freshness.watch[0].url",
   "note": "Opened and verified as Box's current first-party hosted MCP overview, including Admin Console enablement and deprecation of the self-hosted server.",
   "source": "https://developer.box.com/guides/box-mcp",
   "tier": "declared"
  },
  {
   "date": "2026-08-21",
   "fact": "freshness.watch[1].url",
   "note": "Opened and verified as Box's current authentication overview for the Platform API.",
   "source": "https://developer.box.com/guides/authentication/index",
   "tier": "declared"
  },
  {
   "date": "2026-08-21",
   "fact": "freshness.watch[2].url",
   "note": "Opened and verified as Box's current developer documentation index for agents.",
   "source": "https://developer.box.com/llms.txt",
   "tier": "declared"
  }
 ],
 "freshness": {
  "last_verified": "2026-08-21",
  "volatility": "high",
  "watch": [
   {
    "type": "mcp",
    "url": "https://developer.box.com/guides/box-mcp"
   },
   {
    "type": "docs",
    "url": "https://developer.box.com/guides/authentication/index"
   },
   {
    "type": "docs",
    "url": "https://developer.box.com/llms.txt"
   }
  ]
 },
 "homepage": "https://www.box.com",
 "id": "box",
 "license": "commercial",
 "modalities": {
  "agent_docs": {
   "llms_txt": true
  },
  "api": {
   "auth": [
    "oauth2",
    "jwt",
    "client-credentials"
   ],
   "coverage": "partial",
   "docs": "https://developer.box.com/guides/authentication/index",
   "exists": true,
   "kinds": [
    "rest"
   ]
  },
  "cli": {
   "exists": true
  },
  "computer_use": {
   "issues": [],
   "viability": "unknown"
  },
  "data_access": {
   "export": [
    "api-download"
   ],
   "import": [
    "api-upload"
   ]
  },
  "extensibility": {
   "scripting": [],
   "webhooks": true
  },
  "integrations": {
   "make": true,
   "n8n": true,
   "power_automate": true,
   "zapier": true
  },
  "mcp": {
   "first_party": true,
   "third_party": [],
   "verdict": "official"
  },
  "rpa": {
   "drivability": "unknown",
   "notes": "No repeatable UI probe was run. Box's Platform API, official SDKs, official CLI, hosted MCP server, webhooks, and documented iPaaS connectors cover practical automation without browser control.\n",
   "ui_stack": [
    "web-dom"
   ],
   "vendor_support": []
  },
  "sdk": {
   "exists": true,
   "languages": [
    "java",
    "dotnet",
    "python",
    "javascript"
   ],
   "official": true
  }
 },
 "name": "Box",
 "platforms": [
  "web"
 ],
 "related": {
  "alternatives": [
   "sharepoint"
  ],
  "our_products": []
 },
 "schema_version": 1,
 "score_version": 1,
 "status": "active",
 "vendor": "Box",
 "verdict": {
  "best_path": "api",
  "scores": {
   "api": 8,
   "cli": 7,
   "computer_use": null,
   "integrations": 7,
   "mcp": 7,
   "overall": 8,
   "rpa": null
  },
  "summary": "Box is automatable today through a mature Platform API and a first-party hosted MCP server. The REST API at api.box.com identifies callers with access tokens. Applications authenticate with OAuth 2.0 for user login, JWT or Client Credentials Grant for server-to-server automation, or short-lived developer tokens. Official Java, .NET, Python, and Node SDKs are maintained with full API parity; the Android Content SDK is no longer supported. The official Box CLI installs via the box or @box/cli npm packages, supports OAuth, JWT, and CCG, and can manage files, folders, users, Hubs, AI, and Sign from scripts. Box hosts MCP at mcp.box.com. An admin must enable the server in the Admin Console and, for custom clients, create Integration Credentials. Agents can call search, Box AI, folder, and related tools without handling raw file payloads in the client. Some scopes such as docgen.readwrite need an Enterprise Advanced license. The previously published self-hosted community MCP server is deprecated. Zapier, Make, n8n, and Microsoft Power Automate all have Box connectors. Computer-use viability is unassessed.\n"
 }
}