Box for AI agents
Box is a cloud content management platform that businesses use to store, share, and govern files, with controls like classifications, retention policies, and legal holds. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.
What agents do in Box.
Look up a file's details
Read-only lookup of a file's classification, comments, or shared link before making any changes to it.
Share a file with a collaborator
Add a shared link or collaboration invite to a file or folder after the user approves who gets access.
Require approval before a legal hold
Treat assigning a legal hold or retention policy as needing confirmation since it restricts how a file can be deleted.
286 Box actions, graded by risk.
Every Box action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.
read
128Look things up. Allowed by default.
- box.get_taskGet task
- box.get_userGet user
- box.get_groupGet group
- box.list_hubsList Box Hubs
- box.get_folderGet folder information
- box.get_commentGet comment
- box.get_webhookGet webhook
- box.list_eventsList user and enterprise events
- box.get_ai_agentGet AI Agent by ID
- box.get_web_linkGet web link
- box.list_webhooksList all webhooks
- box.get_collectionGet collection by id
- box.get_device_pinGet device pin
- box.list_ai_agentsList ai agents
- box.list_workflowsList workflows
- box.get_user_avatarGet user avatar
write
107Create and change things. Allow, or ask the user first.
- box.create_taskCreate task
- box.create_userCreate user
- box.update_fileUpdate file
- box.update_taskUpdate task
- box.update_userUpdate user
- box.create_groupCreate group
- box.update_groupUpdate group
- box.create_folderCreate folder
- box.update_folderUpdate folder
- box.create_commentCreate comment
- box.create_webhookCreate webhook
- box.update_commentUpdate comment
- box.update_webhookUpdate webhook
- box.create_ai_agentCreate AI Agent
- box.create_web_linkCreate web link
- box.update_ai_agentUpdate AI Agent
destructive
51Delete, cancel or archive. Ask first, or deny outright.
- box.delete_fileDelete file
- box.delete_taskRemove task
- box.delete_userDelete user
- box.delete_groupRemove group
- box.delete_folderDelete folder
- box.delete_commentRemove comment
- box.delete_webhookRemove webhook
- box.delete_ai_agentDelete AI Agent
- box.delete_web_linkRemove web link
- box.delete_device_pinRemove device pin
- box.delete_email_aliasRemove email alias
- box.delete_folder_lockDelete folder lock
- box.delete_user_avatarDelete user avatar
- box.delete_file_requestDelete file request
- box.delete_file_versionRemove file version
- box.delete_collaborationRemove collaboration
Box in three steps.
- 01Your users connect BoxThey sign in to Box on Arc0 Connect, under your brand, and approve the access you ask for.
- 02You set the rulesReads run, writes like “create task” can wait for the user, and “delete file” can be denied outright.
- 03Any agent can actYour agent calls Box through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
await arc0.policies.set('box', { read: 'allow', write: 'ask', // create_task destructive: 'deny', // delete_file }) # Claude Code: the same connection, one URL $ claude mcp add --transport http arc0 \ https://mcp.arc0.ai/u/u_8f2
How Box connects.
Users sign in to Box on Arc0 Connect and approve the scopes you request. Build with Arc0’s Box OAuth app, or bring your own so the Box consent screen names you. Tokens refresh automatically, and you can export them whenever you want.
The same Box connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →
- AUTH
- OAuth 2.0
- CREDENTIALS
- Per-tenant encrypted vault
- MODEL SEES
- Results only, never credentials
- AUDIT LOG
- Every call, on every plan
Use Box from any agent.
Box and Arc0, answered.
Can I use Box with Claude, ChatGPT or Cursor?
Yes. Connect Box to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Box actions you allow.
How do users connect Box?
Users sign in to Box on Arc0 Connect and approve the scopes you request. Build with Arc0’s Box OAuth app, or bring your own so the Box consent screen names you. Tokens refresh automatically, and you can export them whenever you want.
Which Box actions can my agent take?
286 in total: 128 read, 107 write and 51 destructive, such as “create task”. Your policies decide which of them each agent may call.
Can I stop my agent from deleting things in Box?
Yes. Actions like “delete file” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.
Can my own backend call Box too?
Yes. The same Box connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.
Plug Box into your agent.
Your users connect Box once, under your brand. Your agent gets 286 actions behind your policies, with every call on the record.
Free to build · MCP + REST · Audit log on every plan