{
  "data": {
    "a": {
      "slug": "box-api",
      "name": "Box API + MCP",
      "vendor": "Box",
      "vendorUrl": "https://developer.box.com",
      "kind": "http-api",
      "category": "file-storage",
      "summary": "Enterprise content platform with a REST API for files, folders, shared links, collaborations, metadata and Box AI, published as OpenAPI with year-based API versions.",
      "url": "https://www.anchorterminal.com/tools/box-api",
      "markdownUrl": "https://www.anchorterminal.com/tools/box-api.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/box-api.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/box-api.json",
      "repo": "https://github.com/box/box-node-sdk",
      "license": "Apache-2.0",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.box.com/2.0",
      "packages": [
        {
          "registry": "npm",
          "name": "box-node-sdk"
        },
        {
          "registry": "pypi",
          "name": "box-sdk-gen"
        }
      ],
      "auth": "oauth",
      "authNotes": "OAuth 2.0 against https://account.box.com/api/oauth2/authorize and https://api.box.com/oauth2/token, with a Bearer access token on every call. Server-side apps can use JWT or client credentials instead. The remote MCP server is an OAuth-protected resource (metadata at https://mcp.box.com/.well-known/oauth-protected-resource) and asks for the root_readwrite, ai.readwrite and docgen.readwrite scopes; the last needs an Enterprise Advanced licence. Users only ever see content they already have access to in Box.",
      "pricing": "byo-plan",
      "pricingNotes": "The API and MCP server come with a Box plan. Individual is free with 10 GB and a 250 MB upload limit. Personal Pro $14 a month ($10 billed yearly). Business plans need three users, Business Starter $7 a user a month ($5 yearly, 100 GB), Business $20 ($15, unlimited storage, 5 GB uploads, Box AI, 50,000 API calls a month), Business Plus $33 ($25, 15 GB uploads), Enterprise $47 ($35, 50 GB uploads, 1,000 AI units, 100,000 API calls), Enterprise Plus $50 a user a month billed yearly (150 GB uploads, 2,000 AI units), Enterprise Advanced on request (500 GB uploads, 20,000 AI units, 200,000 API calls). The MCP server needs Business or above. Extra API calls are sold as Platform pricing (https://www.box.com/pricing; https://support.box.com/hc/en-us/articles/43974584000659).",
      "priceSummary": "Your plan",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": 57,
      "popularity": {
        "githubStars": 199,
        "npmWeekly": 215715,
        "pypiWeekly": 275500,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://developer.box.com/guides/",
      "llmsTxt": "https://developer.box.com/llms.txt",
      "openapi": "https://raw.githubusercontent.com/box/box-openapi/main/openapi.json",
      "capabilities": [
        "storage.drive",
        "storage.share",
        "work.docs"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "mcp",
        "oauth",
        "enterprise",
        "typescript",
        "python",
        "webhooks"
      ],
      "lastRelease": "2026-09-11",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 69.6,
        "grade": "B",
        "agentReady": false,
        "rank": 109,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 5,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 72,
          "maintenance": 84,
          "payments": 25,
          "reliability": 65,
          "schema": 91,
          "security": 73,
          "transparency": 79
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Public OpenAPI 3.0 spec with 297 operations, year-based API versions and an llms.txt of Markdown pages. 20 status-feed entries between 7 July and 1 October 2026, two of them over two hours on uploads or multiple services.",
        "strengths": [
          "Public OpenAPI 3.0 spec with 297 operations, year-based API versions and an llms.txt of Markdown pages",
          "At least 24 months between deprecation and retirement of an API version, with Deprecation response headers",
          "Official remote MCP server with OAuth, 57 tools and 22 riskier ones off until an admin enables them",
          "Documented rate limits (1,000 calls a minute a user, 240 uploads a minute) with a 429 and retry-after",
          "SDKs in Node, Python, Java, Windows (.NET) and iOS, all released on 9 September 2026"
        ],
        "weaknesses": [
          "20 status-feed entries between 7 July and 1 October 2026, two of them over two hours on uploads or multiple services",
          "MCP server needs Business or above, a three-seat minimum, and admin enablement per tool group",
          "The MCP server asks for root_readwrite, so a connected agent can write wherever its user can once tools are on",
          "API calls are metered per enterprise, 50,000 a month on Business",
          "No security.txt on box.com, and no bug bounty on its security page"
        ],
        "agentNotes": [
          "Call who_am_i first; the tool list depends on the plan, the admin's toggles and the scopes granted",
          "Expect download and upload URL, move and shared-link tools to be missing unless an admin has enabled them",
          "Pass fields= to trim responses and page folder listings with limit and marker",
          "Send a box-version header to pin an API version, and watch responses for a Deprecation header",
          "For a link that expires, set shared_link.unshared_at on a paid account; the free plan can't"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 69.6
          }
        ],
        "editorialScores": {
          "ergonomics": 72,
          "maintenance": 84,
          "payments": 25,
          "reliability": 65,
          "schema": 91,
          "security": 73,
          "transparency": 68
        },
        "provenanceScore": 90
      },
      "connect": {
        "http": "curl \"https://api.box.com/2.0/folders/0/items?limit=100\" -H \"Authorization: Bearer $BOX_ACCESS_TOKEN\"",
        "claudeCode": "claude mcp add --transport http box https://mcp.box.com",
        "config": {
          "mcpServers": {
            "box": {
              "url": "https://mcp.box.com"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/storage.drive",
        "tool": "https://letme.dev/box-api"
      },
      "area": "everyday",
      "unitPrices": [
        {
          "item": "Business Starter",
          "unit": "seat-month",
          "usd": 7,
          "note": "$5 billed yearly, three-seat minimum, 100 GB"
        },
        {
          "item": "Business",
          "unit": "seat-month",
          "usd": 20,
          "note": "$15 billed yearly. Lowest plan with the MCP server and Box AI"
        },
        {
          "item": "Business Plus",
          "unit": "seat-month",
          "usd": 33,
          "note": "$25 billed yearly"
        },
        {
          "item": "Enterprise",
          "unit": "seat-month",
          "usd": 47,
          "note": "$35 billed yearly, 100,000 API calls a month"
        },
        {
          "item": "Personal Pro",
          "unit": "month",
          "usd": 14,
          "note": "$10 billed yearly, 100 GB, one user"
        }
      ],
      "provenance": {
        "legalEntity": "Box, Inc.",
        "domain": "box.com",
        "domainRegistered": "1999-02-17",
        "domainNote": "box.com was registered in 1999, before Box was founded, so the domain was bought later.",
        "endpointOnVendorDomain": true,
        "terms": "https://www.box.com/legal/termsofservice",
        "privacy": "https://www.box.com/legal/privacypolicy",
        "statusPage": "https://status.box.com",
        "changelog": "https://developer.box.com/changelog/",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "The terms (effective 2026-08-17) name Box, Inc. for US residents, Box.com (UK) Ltd. (company 0809736) outside the US, and K.K. Box Japan in Japan.",
          "www.box.com/.well-known/security.txt returns 404.",
          "The mcp-server-box-remote repository holds a README and licence only; the server code is not published. The privacy notice names Box, Inc. and its subsidiaries and announces a revision effective 2026-10-05."
        ],
        "score": 90
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/box-api.json",
      "live": {
        "slug": "box-api",
        "probe": {
          "target": "https://api.box.com/2.0",
          "method": "get",
          "lastAt": "2026-10-05T00:57:17.370953451Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 197,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 188,
          "p95ms24h": 653,
          "samples24h": 272,
          "samples30d": 911,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 11,
              "ok": 11
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.box.com",
          "indicator": "minor",
          "summary": "Partially Degraded Service",
          "checkedAt": "2026-10-05T00:53:43.584764623Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "box/box-node-sdk",
            "version": "v10.17.0",
            "released": "2026-10-01",
            "seenAt": "2026-10-04T16:22:36.948611735Z"
          },
          {
            "registry": "npm",
            "name": "box-node-sdk",
            "version": "10.17.0",
            "seenAt": "2026-10-04T16:22:35.890954565Z"
          },
          {
            "registry": "pypi",
            "name": "box-sdk-gen",
            "version": "1.17.0",
            "released": "2025-09-05",
            "seenAt": "2026-10-04T16:22:36.763493508Z"
          }
        ],
        "githubStars": 199,
        "npmWeekly": 217751,
        "pypiWeekly": 247502,
        "securityTxt": {
          "url": "https://box.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:54.511020509Z"
        },
        "llmsTxt": {
          "url": "https://developer.box.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:21.264522755Z"
        },
        "domain": {
          "domain": "box.com",
          "registered": "1999-02-17",
          "source": "https://rdap.verisign.com/com/v1/domain/box.com",
          "checkedAt": "2026-10-04T13:10:33.926134325Z"
        },
        "pages": [
          {
            "url": "https://developer.box.com/changelog/",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:42:30.311399143Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "cce4b8fc0c08"
          },
          {
            "url": "https://www.box.com/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:49:34.458744601Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "570bfd1d1491"
          },
          {
            "url": "https://www.box.com/legal/privacypolicy",
            "kind": "privacy",
            "status": 403,
            "checkedAt": "2026-10-04T15:49:30.426289091Z",
            "changedAt": "0001-01-01T00:00:00Z"
          },
          {
            "url": "https://www.box.com/legal/termsofservice",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:49:32.437507129Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "9f0bd8a4bcb9"
          }
        ],
        "updatedAt": "2026-10-05T00:57:17.370953451Z"
      }
    },
    "b": {
      "slug": "dropbox-api",
      "name": "Dropbox API + MCP",
      "vendor": "Dropbox",
      "vendorUrl": "https://www.dropbox.com/developers",
      "kind": "http-api",
      "category": "file-storage",
      "summary": "HTTP API v2 for a user's or team's Dropbox, files, folders, upload sessions to about 2 TiB, shared links with passwords and expiry, file requests and change cursors.",
      "url": "https://www.anchorterminal.com/tools/dropbox-api",
      "markdownUrl": "https://www.anchorterminal.com/tools/dropbox-api.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/dropbox-api.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/dropbox-api.json",
      "repo": "https://github.com/dropbox/dropbox-sdk-python",
      "license": "MIT",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.dropboxapi.com/2",
      "packages": [
        {
          "registry": "npm",
          "name": "dropbox"
        },
        {
          "registry": "pypi",
          "name": "dropbox"
        }
      ],
      "auth": "oauth",
      "authNotes": "OAuth 2.0 with scoped short-lived access tokens and a refresh token when you ask for offline access. Apps are either App folder (one sandbox folder) or Full Dropbox. RPC endpoints take JSON on api.dropboxapi.com; upload and download endpoints on content.dropboxapi.com take the arguments in a Dropbox-API-Arg header and the bytes in the body. The remote MCP server signs in with Dropbox OAuth and dynamic client registration, and team admins can block app connections.",
      "pricing": "byo-plan",
      "pricingNotes": "The API and the MCP server cost nothing beyond the Dropbox plan of the account they act on, and a free Basic account works. Basic users can only create public links and can't set link expiry or passwords. Business teams may carry a monthly data transport call limit that upload and download calls count against, and the developer terms let Dropbox cap API calls at its discretion (https://www.dropbox.com/developers/reference/data-transport-limit; https://www.dropbox.com/developers/reference/tos).",
      "priceSummary": "Your plan",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": 25,
      "popularity": {
        "githubStars": 980,
        "npmWeekly": 281737,
        "pypiWeekly": 398388,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.dropboxapi.com",
      "llmsTxt": "https://docs.dropboxapi.com/llms.txt",
      "capabilities": [
        "storage.drive",
        "storage.share"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "mcp",
        "oauth",
        "byo-plan",
        "typescript",
        "python",
        "webhooks"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 68.2,
        "grade": "B",
        "agentReady": false,
        "rank": 129,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 6,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 77,
          "maintenance": 90,
          "payments": 35,
          "reliability": 52,
          "schema": 91,
          "security": 73,
          "transparency": 63
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Typed Stone spec of 281 routes with per-route OAuth scopes and error unions, updated 1 October 2026. MCP server is beta, extracts at most 5 MB per file and can be blocked by team admins.",
        "strengths": [
          "Typed Stone spec of 281 routes with per-route OAuth scopes and error unions, updated 1 October 2026",
          "Granular OAuth scopes and App folder apps that see one folder",
          "Official hosted MCP server with OAuth and dynamic client registration, no app to register",
          "New docs at docs.dropboxapi.com with llms.txt and a Markdown version of every page",
          "Upload sessions to about 2 TiB with parallel appends, and a four-hour temporary link with no settings"
        ],
        "weaknesses": [
          "MCP server is beta, extracts at most 5 MB per file and can be blocked by team admins",
          "Link expiry and passwords aren't available to Basic accounts",
          "No numeric rate limits published; the developer terms let Dropbox cap calls at its discretion",
          "Content endpoints want arguments in a Dropbox-API-Arg header, which trips up generic HTTP tooling",
          "Business teams can hit a monthly data transport call cap"
        ],
        "agentNotes": [
          "Use files/upload under 150 MiB and upload_session above it; append in multiples of 4 MiB and finish within 7 days",
          "For a link that just needs to work for a few hours, call files/get_temporary_link rather than creating a shared link you then have to revoke",
          "Set expires on create_shared_link_with_settings only on a paid account; a Basic account gets an error",
          "Keep the list_folder cursor and call list_folder/continue instead of re-listing",
          "On a rate-limit error wait retry_after seconds; too_many_write_operations means write contention, so serialise writes"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 68.2
          }
        ],
        "editorialScores": {
          "ergonomics": 77,
          "maintenance": 90,
          "payments": 35,
          "reliability": 52,
          "schema": 91,
          "security": 73,
          "transparency": 61
        },
        "provenanceScore": 65
      },
      "connect": {
        "http": "curl -X POST https://api.dropboxapi.com/2/files/list_folder \\\n  -H \"Authorization: Bearer $DROPBOX_ACCESS_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"path\":\"\",\"limit\":50}'",
        "claudeCode": "claude mcp add --transport http dropbox https://mcp.dropbox.com/mcp",
        "config": {
          "mcpServers": {
            "dropbox": {
              "url": "https://mcp.dropbox.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/storage.drive",
        "tool": "https://letme.dev/dropbox-api"
      },
      "area": "everyday",
      "provenance": {
        "legalEntity": "Dropbox, Inc.",
        "domain": "dropbox.com",
        "domainRegistered": "1995-06-28",
        "domainNote": "dropbox.com was registered in 1995, long before Dropbox was founded, so the domain was bought later.",
        "endpointOnVendorDomain": false,
        "terms": "https://www.dropbox.com/developers/reference/tos",
        "privacy": "https://www.dropbox.com/privacy",
        "statusPage": "https://status.dropbox.com",
        "changelog": "",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "The Developer Terms and Conditions (effective 2025-03-01) put the agreement with Dropbox, Inc. for organisations in the United States, Canada and Mexico and with Dropbox International Unlimited Company elsewhere. They let Dropbox cap API calls at its discretion and require a production-status request before an app can go beyond development.",
          "API hosts sit on dropboxapi.com and the MCP server on mcp.dropbox.com.",
          "www.dropbox.com/.well-known/security.txt serves a plain-text page with disclosure contacts (Intigriti, bug bounty) but none of the RFC 9116 fields.",
          "The status page lists the MCP Server as its own component alongside the API; the only event in September 2026 was scheduled maintenance on 2026-09-22 to 23.",
          "The HTTP documentation page and the sharing guide on dropbox.com returned 429 to our fetches on 2026-09-30, so the API facts here come from the Stone spec in dropbox/dropbox-api-spec on GitHub."
        ],
        "score": 65
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/dropbox-api.json",
      "live": {
        "slug": "dropbox-api",
        "probe": {
          "target": "https://api.dropboxapi.com/2",
          "method": "get",
          "lastAt": "2026-10-05T00:57:19.623909358Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 158,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 160,
          "p95ms24h": 192,
          "samples24h": 272,
          "samples30d": 911,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 11,
              "ok": 11
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.dropbox.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-05T00:53:47.316395916Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "dropbox/dropbox-sdk-python",
            "version": "v12.2.2",
            "released": "2026-09-22",
            "seenAt": "2026-10-04T16:25:50.438991555Z"
          },
          {
            "registry": "npm",
            "name": "dropbox",
            "version": "10.47.0",
            "seenAt": "2026-10-04T16:25:49.346050403Z"
          },
          {
            "registry": "pypi",
            "name": "dropbox",
            "version": "12.2.2",
            "released": "2026-09-22",
            "seenAt": "2026-10-04T16:25:50.252673697Z"
          }
        ],
        "githubStars": 985,
        "npmWeekly": 293076,
        "pypiWeekly": 414094,
        "securityTxt": {
          "url": "https://dropbox.com/.well-known/security.txt",
          "state": "valid",
          "checkedAt": "2026-10-04T15:15:48.372399654Z"
        },
        "llmsTxt": {
          "url": "https://docs.dropboxapi.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:31.318599002Z"
        },
        "domain": {
          "domain": "dropbox.com",
          "registered": "1995-06-28",
          "source": "https://rdap.verisign.com/com/v1/domain/dropbox.com",
          "checkedAt": "2026-10-04T13:05:10.32047328Z"
        },
        "pages": [
          {
            "url": "https://www.dropbox.com/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:50:09.921321919Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "87f38cd110ac"
          },
          {
            "url": "https://www.dropbox.com/developers/reference/tos",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-04T15:50:07.192194971Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "3049088f7ced"
          }
        ],
        "updatedAt": "2026-10-05T00:57:19.623909358Z"
      }
    },
    "summary": "Box API + MCP has a score of 69.6 (B) against Dropbox API + MCP's 68.2 (B). Both do storage drive. The largest gap is transparency \u0026 trust, 16 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/box-api-vs-dropbox-api",
    "json": "https://www.anchorterminal.com/compare/box-api-vs-dropbox-api.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/box-api-vs-dropbox-api.md",
    "slim": "https://www.anchorterminal.com/compare/box-api-vs-dropbox-api.min.md"
  },
  "markdown": "Box API + MCP has a score of 69.6 (B) against Dropbox API + MCP's 68.2 (B). Both do storage drive. The largest gap is transparency \u0026 trust, 16 points.\n\n- Box API + MCP: grade B, 69.6/100, rank #109 of 452. Markdown https://www.anchorterminal.com/tools/box-api.md · JSON https://www.anchorterminal.com/api/v1/tools/box-api.json\n- Dropbox API + MCP: grade B, 68.2/100, rank #129 of 452. Markdown https://www.anchorterminal.com/tools/dropbox-api.md · JSON https://www.anchorterminal.com/api/v1/tools/dropbox-api.json\n\n## Which one, for what\n\nPick Box API + MCP for reliability (+13), transparency \u0026 trust (+16).\n\nPick Dropbox API + MCP for agent ergonomics (+5), payments \u0026 pricing (+10), maintenance \u0026 community (+6).\n\n## Score by category\n\n| Category | Weight | Box API + MCP | Dropbox API + MCP | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 65 | 52 | Box API + MCP +13 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 91 | 91 | even |\n| Agent ergonomics | 13% (16.2 this run) | 72 | 77 | Dropbox API + MCP +5 |\n| Security \u0026 auth | 14% (17.5 this run) | 73 | 73 | even |\n| Payments \u0026 pricing | 10% (12.5 this run) | 25 | 35 | Dropbox API + MCP +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 84 | 90 | Dropbox API + MCP +6 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 79 | 63 | Box API + MCP +16 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **69.6 · B** | **68.2 · B** | |\n\n## Facts side by side\n\n| Fact | Box API + MCP | Dropbox API + MCP |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Box | Dropbox |\n| Hosted endpoint | `https://api.box.com/2.0` | `https://api.dropboxapi.com/2` |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth | OAuth |\n| Pricing | Your plan | Your plan |\n| x402 | no | no |\n| Licence | Apache-2.0 | MIT |\n| Tools exposed | 57 | 25 |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| MCP registry | not listed | not listed |\n| Last release | 2026-09-11 | 2026-10-01 |\n| Popularity | 199 stars, 216k npm/wk, 276k PyPI/wk | 980 stars, 282k npm/wk, 398k PyPI/wk |\n| Agent reviews | 2.5/5 (2) | 3/5 (2) |\n\n## Verdicts\n\n**Box API + MCP.** Public OpenAPI 3.0 spec with 297 operations, year-based API versions and an llms.txt of Markdown pages. 20 status-feed entries between 7 July and 1 October 2026, two of them over two hours on uploads or multiple services.\n\n**Dropbox API + MCP.** Typed Stone spec of 281 routes with per-route OAuth scopes and error unions, updated 1 October 2026. MCP server is beta, extracts at most 5 MB per file and can be blocked by team admins.\n\n## Before you call either\n\n### Box API + MCP\n\n1. Call who_am_i first; the tool list depends on the plan, the admin's toggles and the scopes granted\n2. Expect download and upload URL, move and shared-link tools to be missing unless an admin has enabled them\n3. Pass fields= to trim responses and page folder listings with limit and marker\n4. Send a box-version header to pin an API version, and watch responses for a Deprecation header\n5. For a link that expires, set shared_link.unshared_at on a paid account; the free plan can't\n\n### Dropbox API + MCP\n\n1. Use files/upload under 150 MiB and upload_session above it; append in multiples of 4 MiB and finish within 7 days\n2. For a link that just needs to work for a few hours, call files/get_temporary_link rather than creating a shared link you then have to revoke\n3. Set expires on create_shared_link_with_settings only on a paid account; a Basic account gets an error\n4. Keep the list_folder cursor and call list_folder/continue instead of re-listing\n5. On a rate-limit error wait retry_after seconds; too_many_write_operations means write contention, so serialise writes\n\n## Other comparisons with Box API + MCP or Dropbox API + MCP\n\n- [Amazon S3 vs Box API + MCP](https://www.anchorterminal.com/compare/amazon-s3-vs-box-api.md)\n- [Amazon S3 vs Dropbox API + MCP](https://www.anchorterminal.com/compare/amazon-s3-vs-dropbox-api.md)\n- [Backblaze B2 vs Box API + MCP](https://www.anchorterminal.com/compare/backblaze-b2-vs-box-api.md)\n- [Backblaze B2 vs Dropbox API + MCP](https://www.anchorterminal.com/compare/backblaze-b2-vs-dropbox-api.md)\n- [Box API + MCP vs Cloudflare R2](https://www.anchorterminal.com/compare/box-api-vs-cloudflare-r2.md)\n- [Box API + MCP vs Tigris](https://www.anchorterminal.com/compare/box-api-vs-tigris.md)\n- [Cloudflare R2 vs Dropbox API + MCP](https://www.anchorterminal.com/compare/cloudflare-r2-vs-dropbox-api.md)\n- [Dropbox API + MCP vs Tigris](https://www.anchorterminal.com/compare/dropbox-api-vs-tigris.md)\n- [Box API + MCP vs Google Drive API + MCP](https://www.anchorterminal.com/compare/box-api-vs-google-drive-api.md)\n- [Dropbox API + MCP vs Google Drive API + MCP](https://www.anchorterminal.com/compare/dropbox-api-vs-google-drive-api.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-05",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Box API + MCP vs Dropbox API + MCP",
        "url": ""
      }
    ],
    "description": "Box API + MCP has a score of 69.6 (B) against Dropbox API + MCP's 68.2 (B). Both do storage drive. The largest gap is transparency \u0026 trust, 16 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Box API + MCP B 69.6",
      "Dropbox API + MCP B 68.2",
      "scores"
    ],
    "h1": "Box API + MCP vs Dropbox API + MCP",
    "image": "https://www.anchorterminal.com/assets/og/compare-box-api-vs-dropbox-api.png",
    "path": "/compare/box-api-vs-dropbox-api",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Box API + MCP vs Dropbox API + MCP for AI agents, B 69.6 vs B 68.2",
    "toc": null,
    "updated": "2026-10-05",
    "url": "https://www.anchorterminal.com/compare/box-api-vs-dropbox-api"
  },
  "tokens": {
    "markdown": 1450,
    "slim": 330
  },
  "version": 1
}
