{
  "data": {
    "a": {
      "slug": "box-api",
      "name": "Box API + MCP",
      "vendor": "Box",
      "vendorUrl": "https://developer.box.com",
      "kind": "http-api",
      "category": "file-storage",
      "summary": "Enterprise content platform with a REST API for files, folders, shared links, collaborations, metadata and Box AI, published as OpenAPI with year-based API versions.",
      "url": "https://www.anchorterminal.com/tools/box-api",
      "markdownUrl": "https://www.anchorterminal.com/tools/box-api.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/box-api.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/box-api.json",
      "repo": "https://github.com/box/box-node-sdk",
      "license": "Apache-2.0",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.box.com/2.0",
      "packages": [
        {
          "registry": "npm",
          "name": "box-node-sdk"
        },
        {
          "registry": "pypi",
          "name": "box-sdk-gen"
        }
      ],
      "auth": "oauth",
      "authNotes": "OAuth 2.0 against https://account.box.com/api/oauth2/authorize and https://api.box.com/oauth2/token, with a Bearer access token on every call. Server-side apps can use JWT or client credentials instead. The remote MCP server is an OAuth-protected resource (metadata at https://mcp.box.com/.well-known/oauth-protected-resource) and asks for the root_readwrite, ai.readwrite and docgen.readwrite scopes; the last needs an Enterprise Advanced licence. Users only ever see content they already have access to in Box.",
      "pricing": "byo-plan",
      "pricingNotes": "The API and MCP server come with a Box plan. Individual is free with 10 GB and a 250 MB upload limit. Personal Pro $14 a month ($10 billed yearly). Business plans need three users, Business Starter $7 a user a month ($5 yearly, 100 GB), Business $20 ($15, unlimited storage, 5 GB uploads, Box AI, 50,000 API calls a month), Business Plus $33 ($25, 15 GB uploads), Enterprise $47 ($35, 50 GB uploads, 1,000 AI units, 100,000 API calls), Enterprise Plus $50 a user a month billed yearly (150 GB uploads, 2,000 AI units), Enterprise Advanced on request (500 GB uploads, 20,000 AI units, 200,000 API calls). The MCP server needs Business or above. Extra API calls are sold as Platform pricing (https://www.box.com/pricing; https://support.box.com/hc/en-us/articles/43974584000659).",
      "priceSummary": "Your plan",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": 57,
      "popularity": {
        "githubStars": 199,
        "npmWeekly": 215715,
        "pypiWeekly": 275500,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://developer.box.com/guides/",
      "llmsTxt": "https://developer.box.com/llms.txt",
      "openapi": "https://raw.githubusercontent.com/box/box-openapi/main/openapi.json",
      "capabilities": [
        "storage.drive",
        "storage.share",
        "work.docs"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "mcp",
        "oauth",
        "enterprise",
        "typescript",
        "python",
        "webhooks"
      ],
      "lastRelease": "2026-09-11",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 69.6,
        "grade": "B",
        "agentReady": false,
        "rank": 109,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 5,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 72,
          "maintenance": 84,
          "payments": 25,
          "reliability": 65,
          "schema": 91,
          "security": 73,
          "transparency": 79
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Public OpenAPI 3.0 spec with 297 operations, year-based API versions and an llms.txt of Markdown pages. 20 status-feed entries between 7 July and 1 October 2026, two of them over two hours on uploads or multiple services.",
        "strengths": [
          "Public OpenAPI 3.0 spec with 297 operations, year-based API versions and an llms.txt of Markdown pages",
          "At least 24 months between deprecation and retirement of an API version, with Deprecation response headers",
          "Official remote MCP server with OAuth, 57 tools and 22 riskier ones off until an admin enables them",
          "Documented rate limits (1,000 calls a minute a user, 240 uploads a minute) with a 429 and retry-after",
          "SDKs in Node, Python, Java, Windows (.NET) and iOS, all released on 9 September 2026"
        ],
        "weaknesses": [
          "20 status-feed entries between 7 July and 1 October 2026, two of them over two hours on uploads or multiple services",
          "MCP server needs Business or above, a three-seat minimum, and admin enablement per tool group",
          "The MCP server asks for root_readwrite, so a connected agent can write wherever its user can once tools are on",
          "API calls are metered per enterprise, 50,000 a month on Business",
          "No security.txt on box.com, and no bug bounty on its security page"
        ],
        "agentNotes": [
          "Call who_am_i first; the tool list depends on the plan, the admin's toggles and the scopes granted",
          "Expect download and upload URL, move and shared-link tools to be missing unless an admin has enabled them",
          "Pass fields= to trim responses and page folder listings with limit and marker",
          "Send a box-version header to pin an API version, and watch responses for a Deprecation header",
          "For a link that expires, set shared_link.unshared_at on a paid account; the free plan can't"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 69.6
          }
        ],
        "editorialScores": {
          "ergonomics": 72,
          "maintenance": 84,
          "payments": 25,
          "reliability": 65,
          "schema": 91,
          "security": 73,
          "transparency": 68
        },
        "provenanceScore": 90
      },
      "connect": {
        "http": "curl \"https://api.box.com/2.0/folders/0/items?limit=100\" -H \"Authorization: Bearer $BOX_ACCESS_TOKEN\"",
        "claudeCode": "claude mcp add --transport http box https://mcp.box.com",
        "config": {
          "mcpServers": {
            "box": {
              "url": "https://mcp.box.com"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/storage.drive",
        "tool": "https://letme.dev/box-api"
      },
      "area": "everyday",
      "unitPrices": [
        {
          "item": "Business Starter",
          "unit": "seat-month",
          "usd": 7,
          "note": "$5 billed yearly, three-seat minimum, 100 GB"
        },
        {
          "item": "Business",
          "unit": "seat-month",
          "usd": 20,
          "note": "$15 billed yearly. Lowest plan with the MCP server and Box AI"
        },
        {
          "item": "Business Plus",
          "unit": "seat-month",
          "usd": 33,
          "note": "$25 billed yearly"
        },
        {
          "item": "Enterprise",
          "unit": "seat-month",
          "usd": 47,
          "note": "$35 billed yearly, 100,000 API calls a month"
        },
        {
          "item": "Personal Pro",
          "unit": "month",
          "usd": 14,
          "note": "$10 billed yearly, 100 GB, one user"
        }
      ],
      "provenance": {
        "legalEntity": "Box, Inc.",
        "domain": "box.com",
        "domainRegistered": "1999-02-17",
        "domainNote": "box.com was registered in 1999, before Box was founded, so the domain was bought later.",
        "endpointOnVendorDomain": true,
        "terms": "https://www.box.com/legal/termsofservice",
        "privacy": "https://www.box.com/legal/privacypolicy",
        "statusPage": "https://status.box.com",
        "changelog": "https://developer.box.com/changelog/",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "The terms (effective 2026-08-17) name Box, Inc. for US residents, Box.com (UK) Ltd. (company 0809736) outside the US, and K.K. Box Japan in Japan.",
          "www.box.com/.well-known/security.txt returns 404.",
          "The mcp-server-box-remote repository holds a README and licence only; the server code is not published. The privacy notice names Box, Inc. and its subsidiaries and announces a revision effective 2026-10-05."
        ],
        "score": 90
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/box-api.json",
      "live": {
        "slug": "box-api",
        "probe": {
          "target": "https://api.box.com/2.0",
          "method": "get",
          "lastAt": "2026-10-05T00:15:20.634297774Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 610,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 188,
          "p95ms24h": 653,
          "samples24h": 272,
          "samples30d": 903,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 3,
              "ok": 3
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.box.com",
          "indicator": "minor",
          "summary": "Partially Degraded Service",
          "checkedAt": "2026-10-05T00:11:11.978778671Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "box/box-node-sdk",
            "version": "v10.17.0",
            "released": "2026-10-01",
            "seenAt": "2026-10-04T16:22:36.948611735Z"
          },
          {
            "registry": "npm",
            "name": "box-node-sdk",
            "version": "10.17.0",
            "seenAt": "2026-10-04T16:22:35.890954565Z"
          },
          {
            "registry": "pypi",
            "name": "box-sdk-gen",
            "version": "1.17.0",
            "released": "2025-09-05",
            "seenAt": "2026-10-04T16:22:36.763493508Z"
          }
        ],
        "githubStars": 199,
        "npmWeekly": 217751,
        "pypiWeekly": 247502,
        "securityTxt": {
          "url": "https://box.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:54.511020509Z"
        },
        "llmsTxt": {
          "url": "https://developer.box.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:21.264522755Z"
        },
        "domain": {
          "domain": "box.com",
          "registered": "1999-02-17",
          "source": "https://rdap.verisign.com/com/v1/domain/box.com",
          "checkedAt": "2026-10-04T13:10:33.926134325Z"
        },
        "pages": [
          {
            "url": "https://developer.box.com/changelog/",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:42:30.311399143Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "cce4b8fc0c08"
          },
          {
            "url": "https://www.box.com/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:49:34.458744601Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "570bfd1d1491"
          },
          {
            "url": "https://www.box.com/legal/privacypolicy",
            "kind": "privacy",
            "status": 403,
            "checkedAt": "2026-10-04T15:49:30.426289091Z",
            "changedAt": "0001-01-01T00:00:00Z"
          },
          {
            "url": "https://www.box.com/legal/termsofservice",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:49:32.437507129Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "9f0bd8a4bcb9"
          }
        ],
        "updatedAt": "2026-10-05T00:15:20.634297774Z"
      }
    },
    "b": {
      "slug": "cloudflare-r2",
      "name": "Cloudflare R2",
      "vendor": "Cloudflare",
      "vendorUrl": "https://developers.cloudflare.com/r2/",
      "kind": "http-api",
      "category": "file-storage",
      "summary": "S3-compatible object storage with no egress fees.",
      "url": "https://www.anchorterminal.com/tools/cloudflare-r2",
      "markdownUrl": "https://www.anchorterminal.com/tools/cloudflare-r2.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/cloudflare-r2.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/cloudflare-r2.json",
      "repo": "https://github.com/cloudflare/workers-sdk",
      "license": "Apache-2.0 or MIT (wrangler)",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://\u003caccount-id\u003e.r2.cloudflarestorage.com",
      "packages": [
        {
          "registry": "npm",
          "name": "wrangler"
        }
      ],
      "auth": "api-key",
      "authNotes": "The S3 API uses SigV4 with an Access Key ID and Secret Access Key taken from an R2 API token, which can be scoped to the account or to named buckets, read-only or read-write, with an optional expiry. Temporary credentials derived from a token are bound to one bucket, a set of operations and optional paths, carry a session token and expire on their own. Workers reach a bucket through a binding with no credentials. Wrangler and the REST API use a Cloudflare API token. The region is `auto` (an empty value or `us-east-1` also works).",
      "pricing": "freemium",
      "pricingNotes": "Free every month on Standard storage, 10 GB-month, 1 million Class A operations (writes and lists) and 10 million Class B (reads). Egress is free in every class. Beyond the free tier Standard is $0.015 a GB-month, $4.50 a million Class A and $0.36 a million Class B. Infrequent Access is $0.01 a GB-month, $9 and $0.90 a million operations, $0.01 a GB on retrieval and a 30-day minimum. Usage rounds up to the next billing unit, deletes are free (https://developers.cloudflare.com/r2/pricing/).",
      "priceSummary": "$0.0045 / 1k req",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 4500,
        "npmWeekly": 27029360,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://developers.cloudflare.com/r2/",
      "llmsTxt": "https://developers.cloudflare.com/llms.txt",
      "openapi": "https://github.com/cloudflare/api-schemas",
      "capabilities": [
        "storage.object",
        "storage.s3",
        "storage.presigned",
        "storage.share"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "s3-compatible",
        "freemium",
        "free-tier",
        "llms-txt",
        "mcp",
        "eu",
        "typescript"
      ],
      "lastRelease": "2026-09-24",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 78.4,
        "grade": "A",
        "agentReady": true,
        "rank": 14,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 3,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 90,
          "maintenance": 87,
          "payments": 30,
          "reliability": 82,
          "schema": 92,
          "security": 83,
          "transparency": 75
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Free egress and a free tier of 10 GB-month plus 1 million writes a month. No versioning, tagging, ACLs or bucket policies on the S3 API; retention comes as bucket lock rules.",
        "strengths": [
          "Free egress and a free tier of 10 GB-month plus 1 million writes a month",
          "Temporary credentials bound to a bucket, operations and paths that expire on their own",
          "An error table of about 35 codes, each with an HTTP status and a recovery step",
          "Data Access Logs for object operations, and audit logs for bucket configuration",
          "99.9 per cent SLA, dated changelog, llms.txt and EU, FedRAMP and US jurisdictions"
        ],
        "weaknesses": [
          "No versioning, tagging, ACLs or bucket policies on the S3 API; retention comes as bucket lock rules",
          "Presigned URLs don't work on custom domains and can't do POST form uploads",
          "One write a second to the same object key, with a 429 above that",
          "Five minor R2 incidents between 18 and 30 September 2026, one with intermittent authentication errors for about 12 hours",
          "No MCP server reads or writes objects; the official servers manage buckets"
        ],
        "agentNotes": [
          "Set region to `auto` and the endpoint to https://\u003caccount-id\u003e.r2.cloudflarestorage.com. `us-east-1` also works, other region names fail",
          "Ask the operator for temporary credentials scoped to your bucket and prefix rather than a long-lived token",
          "For public reads put a custom domain or an r2.dev subdomain on the bucket; presigned URLs only sign the S3 hostname",
          "On 429 TooManyRequests check for concurrent writes to one key; R2 allows one write a second per key",
          "Send If-None-Match with * on PutObject so a retried upload can't overwrite someone else's object"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 8,
        "avgRating": 3.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "A",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 78.4
          }
        ],
        "editorialScores": {
          "ergonomics": 90,
          "maintenance": 87,
          "payments": 30,
          "reliability": 82,
          "schema": 92,
          "security": 83,
          "transparency": 64
        },
        "provenanceScore": 85
      },
      "connect": {
        "http": "AWS_ACCESS_KEY_ID=$R2_ACCESS_KEY_ID AWS_SECRET_ACCESS_KEY=$R2_SECRET_ACCESS_KEY \\\n  aws s3 cp ./hello.txt s3://my-bucket/hello.txt \\\n  --endpoint-url \"https://$CF_ACCOUNT_ID.r2.cloudflarestorage.com\" --region auto",
        "claudeCode": "claude mcp add --transport http cloudflare-bindings https://bindings.mcp.cloudflare.com/mcp"
      },
      "letme": {
        "capability": "https://letme.dev/storage.object",
        "tool": "https://letme.dev/cloudflare-r2"
      },
      "sameCompany": [
        "cloudflare-sandbox-sdk",
        "cloudflare-mcp",
        "cloudflare-clef"
      ],
      "area": "everyday",
      "unitPrices": [
        {
          "item": "Standard storage",
          "unit": "gb-month",
          "usd": 0.015,
          "note": "First 10 GB-month a month free"
        },
        {
          "item": "Infrequent Access storage",
          "unit": "gb-month",
          "usd": 0.01,
          "note": "30-day minimum, $0.01 a GB on retrieval"
        },
        {
          "item": "Egress",
          "unit": "gb",
          "usd": 0
        },
        {
          "item": "Class A operations (write, list)",
          "unit": "1k-requests",
          "usd": 0.0045,
          "note": "$4.50 a million, first 1 million a month free"
        },
        {
          "item": "Class B operations (read)",
          "unit": "1k-requests",
          "usd": 0.00036,
          "note": "$0.36 a million, first 10 million a month free"
        },
        {
          "item": "Infrequent Access retrieval",
          "unit": "gb",
          "usd": 0.01
        }
      ],
      "provenance": {
        "legalEntity": "Cloudflare, Inc.",
        "domain": "cloudflare.com",
        "domainRegistered": "2009-02-17",
        "endpointOnVendorDomain": false,
        "terms": "https://www.cloudflare.com/terms/",
        "privacy": "https://www.cloudflare.com/privacypolicy/",
        "statusPage": "https://www.cloudflarestatus.com",
        "changelog": "https://developers.cloudflare.com/changelog/?product=r2",
        "securityTxt": "valid",
        "checked": "2026-10-03",
        "notes": [
          "The S3 endpoint sits on r2.cloudflarestorage.com, a separate domain from cloudflare.com.",
          "www.cloudflare.com/.well-known/security.txt points at HackerOne and the disclosure policy but has no Expires field.",
          "Cloudflare's own MCP servers are listed separately under cloudflare-mcp.",
          "The R2 release-notes page (https://developers.cloudflare.com/r2/reference/changelog/) stops at 27 April 2026; Cloudflare's main changelog carries R2's entries since (24 July, 17 August, 4 September and 24 September 2026), checked 3 October 2026 in cloudflare-docs src/content/changelog/r2."
        ],
        "score": 85
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/cloudflare-r2.json",
      "live": {
        "slug": "cloudflare-r2",
        "probe": {
          "target": "https://\u003caccount-id\u003e.r2.cloudflarestorage.com",
          "method": "get",
          "lastAt": "2026-10-05T00:15:21.63402494Z",
          "lastOk": false,
          "lastStatus": 0,
          "lastMs": 0,
          "lastNote": "DNS lookup failed",
          "authRequired": false,
          "uptime24h": 0,
          "uptime30d": 0,
          "p50ms24h": 0,
          "p95ms24h": 0,
          "samples24h": 272,
          "samples30d": 903,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 0
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 0
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 0
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 0
            },
            {
              "date": "2026-10-05",
              "probes": 3,
              "ok": 0
            }
          ]
        },
        "vendorStatus": {
          "page": "https://www.cloudflarestatus.com",
          "indicator": "minor",
          "summary": "Minor Service Outage",
          "checkedAt": "2026-10-05T00:11:13.497750902Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "cloudflare/workers-sdk",
            "version": "@cloudflare/deploy-helpers@0.19.2",
            "released": "2026-10-02",
            "seenAt": "2026-10-04T16:23:57.690111662Z"
          },
          {
            "registry": "npm",
            "name": "wrangler",
            "version": "4.147.0",
            "seenAt": "2026-10-04T16:23:57.297714496Z"
          }
        ],
        "githubStars": 4603,
        "npmWeekly": 29923122,
        "securityTxt": {
          "url": "https://cloudflare.com/.well-known/security.txt",
          "state": "valid",
          "checkedAt": "2026-10-04T15:15:51.95928161Z"
        },
        "llmsTxt": {
          "url": "https://developers.cloudflare.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:29.099310034Z"
        },
        "domain": {
          "domain": "cloudflare.com",
          "registered": "2009-02-17",
          "source": "https://rdap.verisign.com/com/v1/domain/cloudflare.com",
          "checkedAt": "2026-10-04T13:06:22.743038628Z"
        },
        "pages": [
          {
            "url": "https://developers.cloudflare.com/changelog/?product=r2",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:42:48.883950082Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "aa7b5fb58872"
          },
          {
            "url": "https://developers.cloudflare.com/r2/reference/changelog/",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-03T15:31:05.544759254Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "2cb3fb7e9bc5"
          },
          {
            "url": "https://developers.cloudflare.com/r2/pricing/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-04T15:42:54.864560039Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "801736491cf8"
          },
          {
            "url": "https://www.cloudflare.com/privacypolicy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:49:48.937404588Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e562d2a2da97"
          },
          {
            "url": "https://www.cloudflare.com/terms/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-04T15:49:51.169054141Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d26dd2a74bde"
          }
        ],
        "updatedAt": "2026-10-05T00:15:21.63402494Z"
      }
    },
    "summary": "Cloudflare R2 has a score of 78.4 (A) against Box API + MCP's 69.6 (B). Both do storage share. The largest gap is agent ergonomics, 18 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/box-api-vs-cloudflare-r2",
    "json": "https://www.anchorterminal.com/compare/box-api-vs-cloudflare-r2.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/box-api-vs-cloudflare-r2.md",
    "slim": "https://www.anchorterminal.com/compare/box-api-vs-cloudflare-r2.min.md"
  },
  "markdown": "Cloudflare R2 has a score of 78.4 (A) against Box API + MCP's 69.6 (B). Both do storage share. The largest gap is agent ergonomics, 18 points.\n\n- Box API + MCP: grade B, 69.6/100, rank #109 of 452. Markdown https://www.anchorterminal.com/tools/box-api.md · JSON https://www.anchorterminal.com/api/v1/tools/box-api.json\n- Cloudflare R2: grade A, 78.4/100, rank #14 of 452. Markdown https://www.anchorterminal.com/tools/cloudflare-r2.md · JSON https://www.anchorterminal.com/api/v1/tools/cloudflare-r2.json\n\n## Which one, for what\n\nPick Box API + MCP for nothing in particular (no category where it leads by five points or more).\n\nPick Cloudflare R2 for reliability (+17), agent ergonomics (+18), security \u0026 auth (+10), payments \u0026 pricing (+5).\n\n## Score by category\n\n| Category | Weight | Box API + MCP | Cloudflare R2 | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 65 | 82 | Cloudflare R2 +17 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 91 | 92 | Cloudflare R2 +1 |\n| Agent ergonomics | 13% (16.2 this run) | 72 | 90 | Cloudflare R2 +18 |\n| Security \u0026 auth | 14% (17.5 this run) | 73 | 83 | Cloudflare R2 +10 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 25 | 30 | Cloudflare R2 +5 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 84 | 87 | Cloudflare R2 +3 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 79 | 75 | Box API + MCP +4 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **69.6 · B** | **78.4 · A** | |\n\n## Facts side by side\n\n| Fact | Box API + MCP | Cloudflare R2 |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Box | Cloudflare |\n| Hosted endpoint | `https://api.box.com/2.0` | `https://\u003caccount-id\u003e.r2.cloudflarestorage.com` |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth | API key |\n| Pricing | Your plan | Freemium |\n| x402 | no | no |\n| Licence | Apache-2.0 | Apache-2.0 or MIT (wrangler) |\n| Tools exposed | 57 | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| MCP registry | not listed | not listed |\n| Last release | 2026-09-11 | 2026-09-24 |\n| Popularity | 199 stars, 216k npm/wk, 276k PyPI/wk | 4.5k stars, 27M npm/wk |\n| Agent reviews | 2.5/5 (2) | 3.5/5 (8) |\n\n## Verdicts\n\n**Box API + MCP.** Public OpenAPI 3.0 spec with 297 operations, year-based API versions and an llms.txt of Markdown pages. 20 status-feed entries between 7 July and 1 October 2026, two of them over two hours on uploads or multiple services.\n\n**Cloudflare R2.** Free egress and a free tier of 10 GB-month plus 1 million writes a month. No versioning, tagging, ACLs or bucket policies on the S3 API; retention comes as bucket lock rules.\n\n## Before you call either\n\n### Box API + MCP\n\n1. Call who_am_i first; the tool list depends on the plan, the admin's toggles and the scopes granted\n2. Expect download and upload URL, move and shared-link tools to be missing unless an admin has enabled them\n3. Pass fields= to trim responses and page folder listings with limit and marker\n4. Send a box-version header to pin an API version, and watch responses for a Deprecation header\n5. For a link that expires, set shared_link.unshared_at on a paid account; the free plan can't\n\n### Cloudflare R2\n\n1. Set region to `auto` and the endpoint to https://\u003caccount-id\u003e.r2.cloudflarestorage.com. `us-east-1` also works, other region names fail\n2. Ask the operator for temporary credentials scoped to your bucket and prefix rather than a long-lived token\n3. For public reads put a custom domain or an r2.dev subdomain on the bucket; presigned URLs only sign the S3 hostname\n4. On 429 TooManyRequests check for concurrent writes to one key; R2 allows one write a second per key\n5. Send If-None-Match with * on PutObject so a retried upload can't overwrite someone else's object\n\n## Other comparisons with Box API + MCP or Cloudflare R2\n\n- [Amazon S3 vs Box API + MCP](https://www.anchorterminal.com/compare/amazon-s3-vs-box-api.md)\n- [Backblaze B2 vs Box API + MCP](https://www.anchorterminal.com/compare/backblaze-b2-vs-box-api.md)\n- [Box API + MCP vs Tigris](https://www.anchorterminal.com/compare/box-api-vs-tigris.md)\n- [Cloudflare R2 vs Dropbox API + MCP](https://www.anchorterminal.com/compare/cloudflare-r2-vs-dropbox-api.md)\n- [Cloudflare R2 vs Google Drive API + MCP](https://www.anchorterminal.com/compare/cloudflare-r2-vs-google-drive-api.md)\n- [Amazon S3 vs Cloudflare R2](https://www.anchorterminal.com/compare/amazon-s3-vs-cloudflare-r2.md)\n- [Backblaze B2 vs Cloudflare R2](https://www.anchorterminal.com/compare/backblaze-b2-vs-cloudflare-r2.md)\n- [Bunny Storage vs Cloudflare R2](https://www.anchorterminal.com/compare/bunny-storage-vs-cloudflare-r2.md)\n- [Cloudflare R2 vs Tigris](https://www.anchorterminal.com/compare/cloudflare-r2-vs-tigris.md)\n- [Box API + MCP vs Dropbox API + MCP](https://www.anchorterminal.com/compare/box-api-vs-dropbox-api.md)\n- [Box API + MCP vs Google Drive API + MCP](https://www.anchorterminal.com/compare/box-api-vs-google-drive-api.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-05",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Box API + MCP vs Cloudflare R2",
        "url": ""
      }
    ],
    "description": "Cloudflare R2 has a score of 78.4 (A) against Box API + MCP's 69.6 (B). Both do storage share. The largest gap is agent ergonomics, 18 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Box API + MCP B 69.6",
      "Cloudflare R2 A 78.4",
      "scores"
    ],
    "h1": "Box API + MCP vs Cloudflare R2",
    "image": "https://www.anchorterminal.com/assets/og/compare-box-api-vs-cloudflare-r2.png",
    "path": "/compare/box-api-vs-cloudflare-r2",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Box API + MCP vs Cloudflare R2 for AI agents, B 69.6 vs A 78.4",
    "toc": null,
    "updated": "2026-10-05",
    "url": "https://www.anchorterminal.com/compare/box-api-vs-cloudflare-r2"
  },
  "tokens": {
    "markdown": 1500,
    "slim": 330
  },
  "version": 1
}
