Box for AI agents

Box is a cloud content management platform that businesses use to store, share, and govern files, with controls like classifications, retention policies, and legal holds. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

Files and storageOAuth 2.0MCP + RESTbox.com
AUDIT LOG · BOXPOLICY: acme-support
09:41:07 · claude · u_8f2read
box.list_hubs
List Box Hubs✓ allowed · 212ms
09:41:08 · claude · u_8f2read
box.get_task
Get task✓ allowed · 164ms
09:41:09 · claude · u_8f2write
box.create_task
Create task✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
box.delete_file
Delete file✕ blocked · policy: deny
EVERY BOX CALL, ON THE RECORD
01 · USE CASES

What agents do in Box.

01

Look up a file's details

Read-only lookup of a file's classification, comments, or shared link before making any changes to it.

02

Share a file with a collaborator

Add a shared link or collaboration invite to a file or folder after the user approves who gets access.

03

Require approval before a legal hold

Treat assigning a legal hold or retention policy as needing confirmation since it restricts how a file can be deleted.

02 · ACTIONS

286 Box actions, graded by risk.

Every Box action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

128

Look things up. Allowed by default.

  • box.get_task
    Get task
  • box.get_user
    Get user
  • box.get_group
    Get group
  • box.list_hubs
    List Box Hubs
  • box.get_folder
    Get folder information
  • box.get_comment
    Get comment
  • box.get_webhook
    Get webhook
  • box.list_events
    List user and enterprise events
  • box.get_ai_agent
    Get AI Agent by ID
  • box.get_web_link
    Get web link
  • box.list_webhooks
    List all webhooks
  • box.get_collection
    Get collection by id
  • box.get_device_pin
    Get device pin
  • box.list_ai_agents
    List ai agents
  • box.list_workflows
    List workflows
  • box.get_user_avatar
    Get user avatar
+ 112 MORE

write

107

Create and change things. Allow, or ask the user first.

  • box.create_task
    Create task
  • box.create_user
    Create user
  • box.update_file
    Update file
  • box.update_task
    Update task
  • box.update_user
    Update user
  • box.create_group
    Create group
  • box.update_group
    Update group
  • box.create_folder
    Create folder
  • box.update_folder
    Update folder
  • box.create_comment
    Create comment
  • box.create_webhook
    Create webhook
  • box.update_comment
    Update comment
  • box.update_webhook
    Update webhook
  • box.create_ai_agent
    Create AI Agent
  • box.create_web_link
    Create web link
  • box.update_ai_agent
    Update AI Agent
+ 91 MORE

destructive

51

Delete, cancel or archive. Ask first, or deny outright.

  • box.delete_file
    Delete file
  • box.delete_task
    Remove task
  • box.delete_user
    Delete user
  • box.delete_group
    Remove group
  • box.delete_folder
    Delete folder
  • box.delete_comment
    Remove comment
  • box.delete_webhook
    Remove webhook
  • box.delete_ai_agent
    Delete AI Agent
  • box.delete_web_link
    Remove web link
  • box.delete_device_pin
    Remove device pin
  • box.delete_email_alias
    Remove email alias
  • box.delete_folder_lock
    Delete folder lock
  • box.delete_user_avatar
    Delete user avatar
  • box.delete_file_request
    Delete file request
  • box.delete_file_version
    Remove file version
  • box.delete_collaboration
    Remove collaboration
+ 35 MORE
03 · HOW IT WORKS

Box in three steps.

  1. 01Your users connect BoxThey sign in to Box on Arc0 Connect, under your brand, and approve the access you ask for.
  2. 02You set the rulesReads run, writes like “create task” can wait for the user, and “delete file” can be denied outright.
  3. 03Any agent can actYour agent calls Box through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('box', {
  read: 'allow',
  write: 'ask',        // create_task
  destructive: 'deny',  // delete_file
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How Box connects.

Users sign in to Box on Arc0 Connect and approve the scopes you request. Build with Arc0’s Box OAuth app, or bring your own so the Box consent screen names you. Tokens refresh automatically, and you can export them whenever you want.

The same Box connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
OAuth 2.0
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use Box from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

Box and Arc0, answered.

Q01

Can I use Box with Claude, ChatGPT or Cursor?

Yes. Connect Box to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Box actions you allow.

Q02

How do users connect Box?

Users sign in to Box on Arc0 Connect and approve the scopes you request. Build with Arc0’s Box OAuth app, or bring your own so the Box consent screen names you. Tokens refresh automatically, and you can export them whenever you want.

Q03

Which Box actions can my agent take?

286 in total: 128 read, 107 write and 51 destructive, such as “create task”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in Box?

Yes. Actions like “delete file” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call Box too?

Yes. The same Box connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug Box into your agent.

Your users connect Box once, under your brand. Your agent gets 286 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan