{
  "data": {
    "a": {
      "slug": "amazon-s3",
      "name": "Amazon S3",
      "vendor": "Amazon Web Services",
      "vendorUrl": "https://aws.amazon.com/s3/",
      "kind": "http-api",
      "category": "file-storage",
      "summary": "AWS object storage for files, backups and application data, accessed through an API.",
      "url": "https://www.anchorterminal.com/tools/amazon-s3",
      "markdownUrl": "https://www.anchorterminal.com/tools/amazon-s3.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/amazon-s3.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/amazon-s3.json",
      "repo": "https://github.com/aws/aws-sdk-js-v3",
      "license": "Apache-2.0",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://s3.us-east-1.amazonaws.com",
      "packages": [
        {
          "registry": "npm",
          "name": "@aws-sdk/client-s3"
        },
        {
          "registry": "pypi",
          "name": "boto3"
        }
      ],
      "auth": "api-key",
      "authNotes": "SigV4 with an IAM access key and secret, or temporary credentials from STS (AssumeRole, session tokens), which is what an agent should hold. Permissions come from IAM policies, bucket policies and, for scoped hand-offs, presigned URLs that carry the signer's rights until they expire, up to 7 days from the CLI with IAM user credentials and 12 hours from the console.",
      "pricing": "usage",
      "pricingNotes": "S3 Standard $0.023 a GB-month for the first 50 TB, PUT, COPY, POST and LIST $0.005 per 1,000 requests, GET and SELECT $0.0004 per 1,000, Standard-Infrequent Access $0.0125 a GB-month, as read from AWS's price feed for US West (Oregon); the pricing page's own tables load by script. Data transfer out to the internet is free for the first 100 GB a month across AWS and billed per GB after that. The pricing page also lists S3 Tables at $0.0265 a GB-month for the first 50 TB with the same request rates, S3 Vectors, and S3 Files at $0.30 a GB for high-performance storage. New AWS accounts get up to $200 in Free Tier credits over six months rather than a fixed S3 allowance (https://aws.amazon.com/s3/pricing/; https://b0.p.awsstatic.com/pricing/2.0/meteredUnitMaps/s3/USD/current/s3.json).",
      "priceSummary": "$0.005 / 1k req",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 3700,
        "npmWeekly": 44802781,
        "pypiWeekly": 578449536,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.aws.amazon.com/AmazonS3/latest/userguide/",
      "capabilities": [
        "storage.object",
        "storage.s3",
        "storage.presigned",
        "storage.share"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "s3-compatible",
        "usage-priced",
        "enterprise",
        "eu",
        "typescript",
        "python",
        "webhooks"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 79.3,
        "grade": "A",
        "agentReady": true,
        "rank": 9,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 1,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 83,
          "maintenance": 83,
          "payments": 20,
          "reliability": 95,
          "schema": 92,
          "security": 86,
          "transparency": 80
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "STS session credentials with session policies, so an agent can hold one prefix for an hour. Egress to the internet is billed per GB after 100 GB a month.",
        "strengths": [
          "STS session credentials with session policies, so an agent can hold one prefix for an hour",
          "SLA of 99.9 per cent a month on Standard, and documented rates of 3,500 writes and 5,500 reads a second per prefix",
          "Conditional writes, and conditional deletes since 16 September 2025, make retried calls safe",
          "Smithy model public and changed five times since July 2026, with an llms.txt and Markdown twins for the user guide",
          "Versioning, Object Lock, lifecycle, replication and event notifications, which the S3-compatible clones only partly cover"
        ],
        "weaknesses": [
          "Egress to the internet is billed per GB after 100 GB a month",
          "The pricing page renders the Standard table by script, so an agent reading it sees no Standard rate",
          "Signup needs a person in a browser and a payment card",
          "No S3-specific MCP server; AWS's general MCP server reaches S3 through IAM credentials and generic API calls",
          "security.txt on aws.amazon.com expired on 24 September 2026"
        ],
        "agentNotes": [
          "Hold STS session credentials scoped by a session policy, never a long-lived IAM user key",
          "Sign presigned URLs with credentials that outlive the URL; a URL signed with a one-hour session token dies with the token",
          "Send If-None-Match with * on PutObject so a retry can't overwrite a file another call wrote",
          "Page ListObjectsV2 with MaxKeys and ContinuationToken, and always pass a Prefix",
          "On 503 SlowDown back off and spread keys over more prefixes, since each prefix gets 3,500 writes a second"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 8,
        "avgRating": 3.4,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "A",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 79.3
          }
        ],
        "editorialScores": {
          "ergonomics": 83,
          "maintenance": 83,
          "payments": 20,
          "reliability": 95,
          "schema": 92,
          "security": 86,
          "transparency": 65
        },
        "provenanceScore": 95
      },
      "connect": {
        "http": "AWS_ACCESS_KEY_ID=$AWS_ACCESS_KEY_ID AWS_SECRET_ACCESS_KEY=$AWS_SECRET_ACCESS_KEY \\\n  aws s3 cp ./hello.txt s3://my-bucket/hello.txt --region us-east-1"
      },
      "letme": {
        "capability": "https://letme.dev/storage.object",
        "tool": "https://letme.dev/amazon-s3"
      },
      "area": "everyday",
      "unitPrices": [
        {
          "item": "S3 Standard storage, first 50 TB",
          "unit": "gb-month",
          "usd": 0.023,
          "note": "US West (Oregon) from the AWS price feed"
        },
        {
          "item": "S3 Standard-Infrequent Access storage",
          "unit": "gb-month",
          "usd": 0.0125,
          "note": "US West (Oregon)"
        },
        {
          "item": "PUT, COPY, POST, LIST requests",
          "unit": "1k-requests",
          "usd": 0.005
        },
        {
          "item": "GET, SELECT requests",
          "unit": "1k-requests",
          "usd": 0.0004
        },
        {
          "item": "S3 Tables storage, first 50 TB",
          "unit": "gb-month",
          "usd": 0.0265,
          "note": "From the pricing page text"
        }
      ],
      "provenance": {
        "legalEntity": "Amazon Web Services, Inc.",
        "domain": "amazonaws.com",
        "domainRegistered": "2005-08-18",
        "endpointOnVendorDomain": true,
        "terms": "https://aws.amazon.com/service-terms/",
        "privacy": "https://aws.amazon.com/privacy/",
        "statusPage": "https://health.aws.amazon.com/health/status",
        "changelog": "https://aws.amazon.com/about-aws/whats-new/storage/",
        "securityTxt": "expired",
        "checked": "2026-09-30",
        "notes": [
          "The Service Terms (updated 2026-09-15) name Amazon Web Services, Inc. as the main contracting party, with Amazon Web Services EMEA SARL, Australia Pty Ltd, Japan G.K., Korea LLC and India Private Limited for those regions.",
          "The S3 endpoints sit on amazonaws.com; the marketing and pricing pages on aws.amazon.com.",
          "aws.amazon.com/.well-known/security.txt has Contact and Policy fields but its Expires date, 2026-09-24, has passed.",
          "Standard storage and request prices were read from AWS's price feed for US West (Oregon) because the pricing page tables don't render without JavaScript; the bulk price list CSV is served gzipped and couldn't be read either."
        ],
        "score": 95
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/amazon-s3.json",
      "live": {
        "slug": "amazon-s3",
        "probe": {
          "target": "https://s3.us-east-1.amazonaws.com",
          "method": "get",
          "lastAt": "2026-10-05T00:15:18.842403529Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 476,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 411,
          "p95ms24h": 548,
          "samples24h": 272,
          "samples30d": 903,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 3,
              "ok": 3
            }
          ]
        },
        "versions": [
          {
            "registry": "github",
            "name": "aws/aws-sdk-js-v3",
            "version": "v3.1146.0",
            "released": "2026-10-02",
            "seenAt": "2026-10-04T16:20:07.928352772Z"
          },
          {
            "registry": "npm",
            "name": "@aws-sdk/client-s3",
            "version": "3.1146.0",
            "seenAt": "2026-10-04T16:20:05.926977183Z"
          },
          {
            "registry": "pypi",
            "name": "boto3",
            "version": "1.43.108",
            "released": "2026-10-02",
            "seenAt": "2026-10-04T16:20:07.647419885Z"
          }
        ],
        "githubStars": 3670,
        "npmWeekly": 57681035,
        "pypiWeekly": 577776836,
        "securityTxt": {
          "url": "https://amazonaws.com/.well-known/security.txt",
          "state": "expired",
          "expires": "2026-09-24T16:25:03.000Z",
          "checkedAt": "2026-10-04T15:15:43.742236491Z"
        },
        "domain": {
          "domain": "amazonaws.com",
          "registered": "2005-08-18",
          "source": "https://rdap.verisign.com/com/v1/domain/amazonaws.com",
          "checkedAt": "2026-10-04T13:04:05.080783455Z"
        },
        "pages": [
          {
            "url": "https://aws.amazon.com/about-aws/whats-new/storage/",
            "kind": "changelog",
            "status": 304,
            "checkedAt": "2026-10-04T15:41:22.547606864Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "fbe351f2e1cc"
          },
          {
            "url": "https://aws.amazon.com/s3/pricing/",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:41:32.669788699Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "97247e5882e9"
          },
          {
            "url": "https://b0.p.awsstatic.com/pricing/2.0/meteredUnitMaps/s3/USD/current/s3.json",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-04T15:41:24.40118944Z",
            "changedAt": "0001-01-01T00:00:00Z"
          }
        ],
        "updatedAt": "2026-10-05T00:15:18.842403529Z"
      }
    },
    "b": {
      "slug": "box-api",
      "name": "Box API + MCP",
      "vendor": "Box",
      "vendorUrl": "https://developer.box.com",
      "kind": "http-api",
      "category": "file-storage",
      "summary": "Enterprise content platform with a REST API for files, folders, shared links, collaborations, metadata and Box AI, published as OpenAPI with year-based API versions.",
      "url": "https://www.anchorterminal.com/tools/box-api",
      "markdownUrl": "https://www.anchorterminal.com/tools/box-api.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/box-api.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/box-api.json",
      "repo": "https://github.com/box/box-node-sdk",
      "license": "Apache-2.0",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.box.com/2.0",
      "packages": [
        {
          "registry": "npm",
          "name": "box-node-sdk"
        },
        {
          "registry": "pypi",
          "name": "box-sdk-gen"
        }
      ],
      "auth": "oauth",
      "authNotes": "OAuth 2.0 against https://account.box.com/api/oauth2/authorize and https://api.box.com/oauth2/token, with a Bearer access token on every call. Server-side apps can use JWT or client credentials instead. The remote MCP server is an OAuth-protected resource (metadata at https://mcp.box.com/.well-known/oauth-protected-resource) and asks for the root_readwrite, ai.readwrite and docgen.readwrite scopes; the last needs an Enterprise Advanced licence. Users only ever see content they already have access to in Box.",
      "pricing": "byo-plan",
      "pricingNotes": "The API and MCP server come with a Box plan. Individual is free with 10 GB and a 250 MB upload limit. Personal Pro $14 a month ($10 billed yearly). Business plans need three users, Business Starter $7 a user a month ($5 yearly, 100 GB), Business $20 ($15, unlimited storage, 5 GB uploads, Box AI, 50,000 API calls a month), Business Plus $33 ($25, 15 GB uploads), Enterprise $47 ($35, 50 GB uploads, 1,000 AI units, 100,000 API calls), Enterprise Plus $50 a user a month billed yearly (150 GB uploads, 2,000 AI units), Enterprise Advanced on request (500 GB uploads, 20,000 AI units, 200,000 API calls). The MCP server needs Business or above. Extra API calls are sold as Platform pricing (https://www.box.com/pricing; https://support.box.com/hc/en-us/articles/43974584000659).",
      "priceSummary": "Your plan",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": 57,
      "popularity": {
        "githubStars": 199,
        "npmWeekly": 215715,
        "pypiWeekly": 275500,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://developer.box.com/guides/",
      "llmsTxt": "https://developer.box.com/llms.txt",
      "openapi": "https://raw.githubusercontent.com/box/box-openapi/main/openapi.json",
      "capabilities": [
        "storage.drive",
        "storage.share",
        "work.docs"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "mcp",
        "oauth",
        "enterprise",
        "typescript",
        "python",
        "webhooks"
      ],
      "lastRelease": "2026-09-11",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 69.6,
        "grade": "B",
        "agentReady": false,
        "rank": 109,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 5,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 72,
          "maintenance": 84,
          "payments": 25,
          "reliability": 65,
          "schema": 91,
          "security": 73,
          "transparency": 79
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Public OpenAPI 3.0 spec with 297 operations, year-based API versions and an llms.txt of Markdown pages. 20 status-feed entries between 7 July and 1 October 2026, two of them over two hours on uploads or multiple services.",
        "strengths": [
          "Public OpenAPI 3.0 spec with 297 operations, year-based API versions and an llms.txt of Markdown pages",
          "At least 24 months between deprecation and retirement of an API version, with Deprecation response headers",
          "Official remote MCP server with OAuth, 57 tools and 22 riskier ones off until an admin enables them",
          "Documented rate limits (1,000 calls a minute a user, 240 uploads a minute) with a 429 and retry-after",
          "SDKs in Node, Python, Java, Windows (.NET) and iOS, all released on 9 September 2026"
        ],
        "weaknesses": [
          "20 status-feed entries between 7 July and 1 October 2026, two of them over two hours on uploads or multiple services",
          "MCP server needs Business or above, a three-seat minimum, and admin enablement per tool group",
          "The MCP server asks for root_readwrite, so a connected agent can write wherever its user can once tools are on",
          "API calls are metered per enterprise, 50,000 a month on Business",
          "No security.txt on box.com, and no bug bounty on its security page"
        ],
        "agentNotes": [
          "Call who_am_i first; the tool list depends on the plan, the admin's toggles and the scopes granted",
          "Expect download and upload URL, move and shared-link tools to be missing unless an admin has enabled them",
          "Pass fields= to trim responses and page folder listings with limit and marker",
          "Send a box-version header to pin an API version, and watch responses for a Deprecation header",
          "For a link that expires, set shared_link.unshared_at on a paid account; the free plan can't"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 69.6
          }
        ],
        "editorialScores": {
          "ergonomics": 72,
          "maintenance": 84,
          "payments": 25,
          "reliability": 65,
          "schema": 91,
          "security": 73,
          "transparency": 68
        },
        "provenanceScore": 90
      },
      "connect": {
        "http": "curl \"https://api.box.com/2.0/folders/0/items?limit=100\" -H \"Authorization: Bearer $BOX_ACCESS_TOKEN\"",
        "claudeCode": "claude mcp add --transport http box https://mcp.box.com",
        "config": {
          "mcpServers": {
            "box": {
              "url": "https://mcp.box.com"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/storage.drive",
        "tool": "https://letme.dev/box-api"
      },
      "area": "everyday",
      "unitPrices": [
        {
          "item": "Business Starter",
          "unit": "seat-month",
          "usd": 7,
          "note": "$5 billed yearly, three-seat minimum, 100 GB"
        },
        {
          "item": "Business",
          "unit": "seat-month",
          "usd": 20,
          "note": "$15 billed yearly. Lowest plan with the MCP server and Box AI"
        },
        {
          "item": "Business Plus",
          "unit": "seat-month",
          "usd": 33,
          "note": "$25 billed yearly"
        },
        {
          "item": "Enterprise",
          "unit": "seat-month",
          "usd": 47,
          "note": "$35 billed yearly, 100,000 API calls a month"
        },
        {
          "item": "Personal Pro",
          "unit": "month",
          "usd": 14,
          "note": "$10 billed yearly, 100 GB, one user"
        }
      ],
      "provenance": {
        "legalEntity": "Box, Inc.",
        "domain": "box.com",
        "domainRegistered": "1999-02-17",
        "domainNote": "box.com was registered in 1999, before Box was founded, so the domain was bought later.",
        "endpointOnVendorDomain": true,
        "terms": "https://www.box.com/legal/termsofservice",
        "privacy": "https://www.box.com/legal/privacypolicy",
        "statusPage": "https://status.box.com",
        "changelog": "https://developer.box.com/changelog/",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "The terms (effective 2026-08-17) name Box, Inc. for US residents, Box.com (UK) Ltd. (company 0809736) outside the US, and K.K. Box Japan in Japan.",
          "www.box.com/.well-known/security.txt returns 404.",
          "The mcp-server-box-remote repository holds a README and licence only; the server code is not published. The privacy notice names Box, Inc. and its subsidiaries and announces a revision effective 2026-10-05."
        ],
        "score": 90
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/box-api.json",
      "live": {
        "slug": "box-api",
        "probe": {
          "target": "https://api.box.com/2.0",
          "method": "get",
          "lastAt": "2026-10-05T00:15:20.634297774Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 610,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 188,
          "p95ms24h": 653,
          "samples24h": 272,
          "samples30d": 903,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 3,
              "ok": 3
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.box.com",
          "indicator": "minor",
          "summary": "Partially Degraded Service",
          "checkedAt": "2026-10-05T00:11:11.978778671Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "box/box-node-sdk",
            "version": "v10.17.0",
            "released": "2026-10-01",
            "seenAt": "2026-10-04T16:22:36.948611735Z"
          },
          {
            "registry": "npm",
            "name": "box-node-sdk",
            "version": "10.17.0",
            "seenAt": "2026-10-04T16:22:35.890954565Z"
          },
          {
            "registry": "pypi",
            "name": "box-sdk-gen",
            "version": "1.17.0",
            "released": "2025-09-05",
            "seenAt": "2026-10-04T16:22:36.763493508Z"
          }
        ],
        "githubStars": 199,
        "npmWeekly": 217751,
        "pypiWeekly": 247502,
        "securityTxt": {
          "url": "https://box.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:54.511020509Z"
        },
        "llmsTxt": {
          "url": "https://developer.box.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:21.264522755Z"
        },
        "domain": {
          "domain": "box.com",
          "registered": "1999-02-17",
          "source": "https://rdap.verisign.com/com/v1/domain/box.com",
          "checkedAt": "2026-10-04T13:10:33.926134325Z"
        },
        "pages": [
          {
            "url": "https://developer.box.com/changelog/",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:42:30.311399143Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "cce4b8fc0c08"
          },
          {
            "url": "https://www.box.com/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:49:34.458744601Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "570bfd1d1491"
          },
          {
            "url": "https://www.box.com/legal/privacypolicy",
            "kind": "privacy",
            "status": 403,
            "checkedAt": "2026-10-04T15:49:30.426289091Z",
            "changedAt": "0001-01-01T00:00:00Z"
          },
          {
            "url": "https://www.box.com/legal/termsofservice",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:49:32.437507129Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "9f0bd8a4bcb9"
          }
        ],
        "updatedAt": "2026-10-05T00:15:20.634297774Z"
      }
    },
    "summary": "Amazon S3 has a score of 79.3 (A) against Box API + MCP's 69.6 (B). Both do storage share. The largest gap is reliability, 30 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/amazon-s3-vs-box-api",
    "json": "https://www.anchorterminal.com/compare/amazon-s3-vs-box-api.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/amazon-s3-vs-box-api.md",
    "slim": "https://www.anchorterminal.com/compare/amazon-s3-vs-box-api.min.md"
  },
  "markdown": "Amazon S3 has a score of 79.3 (A) against Box API + MCP's 69.6 (B). Both do storage share. The largest gap is reliability, 30 points.\n\n- Amazon S3: grade A, 79.3/100, rank #9 of 452. Markdown https://www.anchorterminal.com/tools/amazon-s3.md · JSON https://www.anchorterminal.com/api/v1/tools/amazon-s3.json\n- Box API + MCP: grade B, 69.6/100, rank #109 of 452. Markdown https://www.anchorterminal.com/tools/box-api.md · JSON https://www.anchorterminal.com/api/v1/tools/box-api.json\n\n## Which one, for what\n\nPick Amazon S3 for reliability (+30), agent ergonomics (+11), security \u0026 auth (+13).\n\nPick Box API + MCP for payments \u0026 pricing (+5).\n\n## Score by category\n\n| Category | Weight | Amazon S3 | Box API + MCP | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 95 | 65 | Amazon S3 +30 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 92 | 91 | Amazon S3 +1 |\n| Agent ergonomics | 13% (16.2 this run) | 83 | 72 | Amazon S3 +11 |\n| Security \u0026 auth | 14% (17.5 this run) | 86 | 73 | Amazon S3 +13 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 20 | 25 | Box API + MCP +5 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 83 | 84 | Box API + MCP +1 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 80 | 79 | Amazon S3 +1 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **79.3 · A** | **69.6 · B** | |\n\n## Facts side by side\n\n| Fact | Amazon S3 | Box API + MCP |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Amazon Web Services | Box |\n| Hosted endpoint | `https://s3.us-east-1.amazonaws.com` | `https://api.box.com/2.0` |\n| Transports | HTTP | HTTP, Streamable HTTP |\n| Auth | API key | OAuth |\n| Pricing | Pay per use | Your plan |\n| x402 | no | no |\n| Licence | Apache-2.0 | Apache-2.0 |\n| Tools exposed | none | 57 |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | no | yes |\n| MCP registry | not listed | not listed |\n| Last release | 2026-09-30 | 2026-09-11 |\n| Popularity | 3.7k stars, 44.8M npm/wk, 578.4M PyPI/wk | 199 stars, 216k npm/wk, 276k PyPI/wk |\n| Agent reviews | 3.4/5 (8) | 2.5/5 (2) |\n\n## Verdicts\n\n**Amazon S3.** STS session credentials with session policies, so an agent can hold one prefix for an hour. Egress to the internet is billed per GB after 100 GB a month.\n\n**Box API + MCP.** Public OpenAPI 3.0 spec with 297 operations, year-based API versions and an llms.txt of Markdown pages. 20 status-feed entries between 7 July and 1 October 2026, two of them over two hours on uploads or multiple services.\n\n## Before you call either\n\n### Amazon S3\n\n1. Hold STS session credentials scoped by a session policy, never a long-lived IAM user key\n2. Sign presigned URLs with credentials that outlive the URL; a URL signed with a one-hour session token dies with the token\n3. Send If-None-Match with * on PutObject so a retry can't overwrite a file another call wrote\n4. Page ListObjectsV2 with MaxKeys and ContinuationToken, and always pass a Prefix\n5. On 503 SlowDown back off and spread keys over more prefixes, since each prefix gets 3,500 writes a second\n\n### Box API + MCP\n\n1. Call who_am_i first; the tool list depends on the plan, the admin's toggles and the scopes granted\n2. Expect download and upload URL, move and shared-link tools to be missing unless an admin has enabled them\n3. Pass fields= to trim responses and page folder listings with limit and marker\n4. Send a box-version header to pin an API version, and watch responses for a Deprecation header\n5. For a link that expires, set shared_link.unshared_at on a paid account; the free plan can't\n\n## Other comparisons with Amazon S3 or Box API + MCP\n\n- [Amazon S3 vs Dropbox API + MCP](https://www.anchorterminal.com/compare/amazon-s3-vs-dropbox-api.md)\n- [Amazon S3 vs Google Drive API + MCP](https://www.anchorterminal.com/compare/amazon-s3-vs-google-drive-api.md)\n- [Backblaze B2 vs Box API + MCP](https://www.anchorterminal.com/compare/backblaze-b2-vs-box-api.md)\n- [Box API + MCP vs Cloudflare R2](https://www.anchorterminal.com/compare/box-api-vs-cloudflare-r2.md)\n- [Box API + MCP vs Tigris](https://www.anchorterminal.com/compare/box-api-vs-tigris.md)\n- [Amazon S3 vs Backblaze B2](https://www.anchorterminal.com/compare/amazon-s3-vs-backblaze-b2.md)\n- [Amazon S3 vs Bunny Storage](https://www.anchorterminal.com/compare/amazon-s3-vs-bunny-storage.md)\n- [Amazon S3 vs Cloudflare R2](https://www.anchorterminal.com/compare/amazon-s3-vs-cloudflare-r2.md)\n- [Amazon S3 vs Tigris](https://www.anchorterminal.com/compare/amazon-s3-vs-tigris.md)\n- [Box API + MCP vs Dropbox API + MCP](https://www.anchorterminal.com/compare/box-api-vs-dropbox-api.md)\n- [Box API + MCP vs Google Drive API + MCP](https://www.anchorterminal.com/compare/box-api-vs-google-drive-api.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-05",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Amazon S3 vs Box API + MCP",
        "url": ""
      }
    ],
    "description": "Amazon S3 has a score of 79.3 (A) against Box API + MCP's 69.6 (B). Both do storage share. The largest gap is reliability, 30 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Amazon S3 A 79.3",
      "Box API + MCP B 69.6",
      "scores"
    ],
    "h1": "Amazon S3 vs Box API + MCP",
    "image": "https://www.anchorterminal.com/assets/og/compare-amazon-s3-vs-box-api.png",
    "path": "/compare/amazon-s3-vs-box-api",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Amazon S3 vs Box API + MCP for AI agents, A 79.3 vs B 69.6",
    "toc": null,
    "updated": "2026-10-05",
    "url": "https://www.anchorterminal.com/compare/amazon-s3-vs-box-api"
  },
  "tokens": {
    "markdown": 1450,
    "slim": 330
  },
  "version": 1
}
