{
  "data": {
    "a": {
      "slug": "box-api",
      "name": "Box API + MCP",
      "vendor": "Box",
      "vendorUrl": "https://developer.box.com",
      "kind": "http-api",
      "category": "file-storage",
      "summary": "Enterprise content platform with a REST API for files, folders, shared links, collaborations, metadata and Box AI, published as OpenAPI with year-based API versions.",
      "url": "https://www.anchorterminal.com/tools/box-api",
      "markdownUrl": "https://www.anchorterminal.com/tools/box-api.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/box-api.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/box-api.json",
      "repo": "https://github.com/box/box-node-sdk",
      "license": "Apache-2.0",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.box.com/2.0",
      "packages": [
        {
          "registry": "npm",
          "name": "box-node-sdk"
        },
        {
          "registry": "pypi",
          "name": "box-sdk-gen"
        }
      ],
      "auth": "oauth",
      "authNotes": "OAuth 2.0 against https://account.box.com/api/oauth2/authorize and https://api.box.com/oauth2/token, with a Bearer access token on every call. Server-side apps can use JWT or client credentials instead. The remote MCP server is an OAuth-protected resource (metadata at https://mcp.box.com/.well-known/oauth-protected-resource) and asks for the root_readwrite, ai.readwrite and docgen.readwrite scopes; the last needs an Enterprise Advanced licence. Users only ever see content they already have access to in Box.",
      "pricing": "byo-plan",
      "pricingNotes": "The API and MCP server come with a Box plan. Individual is free with 10 GB and a 250 MB upload limit. Personal Pro $14 a month ($10 billed yearly). Business plans need three users, Business Starter $7 a user a month ($5 yearly, 100 GB), Business $20 ($15, unlimited storage, 5 GB uploads, Box AI, 50,000 API calls a month), Business Plus $33 ($25, 15 GB uploads), Enterprise $47 ($35, 50 GB uploads, 1,000 AI units, 100,000 API calls), Enterprise Plus $50 a user a month billed yearly (150 GB uploads, 2,000 AI units), Enterprise Advanced on request (500 GB uploads, 20,000 AI units, 200,000 API calls). The MCP server needs Business or above. Extra API calls are sold as Platform pricing (https://www.box.com/pricing; https://support.box.com/hc/en-us/articles/43974584000659).",
      "priceSummary": "Your plan",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": 57,
      "popularity": {
        "githubStars": 199,
        "npmWeekly": 215715,
        "pypiWeekly": 275500,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://developer.box.com/guides/",
      "llmsTxt": "https://developer.box.com/llms.txt",
      "openapi": "https://raw.githubusercontent.com/box/box-openapi/main/openapi.json",
      "capabilities": [
        "storage.drive",
        "storage.share",
        "work.docs"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "mcp",
        "oauth",
        "enterprise",
        "typescript",
        "python",
        "webhooks"
      ],
      "lastRelease": "2026-09-11",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 69.4,
        "grade": "B",
        "agentReady": false,
        "rank": 177,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 6,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 72,
          "maintenance": 84,
          "payments": 25,
          "reliability": 65,
          "schema": 91,
          "security": 73,
          "transparency": 76
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Public OpenAPI 3.0 spec with 297 operations, year-based API versions and an llms.txt of Markdown pages. 20 status-feed entries between 7 July and 1 October 2026, two of them over two hours on uploads or multiple services.",
        "bestFor": "Agents working inside an enterprise's existing Box content with admin oversight, Box AI extraction and audit needs.",
        "strengths": [
          "Public OpenAPI 3.0 spec with 297 operations, year-based API versions and an llms.txt of Markdown pages",
          "At least 24 months between deprecation and retirement of an API version, with Deprecation response headers",
          "Official remote MCP server with OAuth, 57 tools and 22 riskier ones off until an admin enables them",
          "Documented rate limits (1,000 calls a minute a user, 240 uploads a minute) with a 429 and retry-after",
          "SDKs in Node, Python, Java, Windows (.NET) and iOS, all released on 9 September 2026"
        ],
        "weaknesses": [
          "20 status-feed entries between 7 July and 1 October 2026, two of them over two hours on uploads or multiple services",
          "MCP server needs Business or above, a three-seat minimum, and admin enablement per tool group",
          "The MCP server asks for root_readwrite, so a connected agent can write wherever its user can once tools are on",
          "API calls are metered per enterprise, 50,000 a month on Business",
          "No security.txt on box.com, and no bug bounty on its security page"
        ],
        "agentNotes": [
          "Call who_am_i first; the tool list depends on the plan, the admin's toggles and the scopes granted",
          "Expect download and upload URL, move and shared-link tools to be missing unless an admin has enabled them",
          "Pass fields= to trim responses and page folder listings with limit and marker",
          "Send a box-version header to pin an API version, and watch responses for a Deprecation header",
          "For a link that expires, set shared_link.unshared_at on a paid account; the free plan can't"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 69.4
          }
        ],
        "editorialScores": {
          "ergonomics": 72,
          "maintenance": 84,
          "payments": 25,
          "reliability": 65,
          "schema": 91,
          "security": 73,
          "transparency": 68
        },
        "provenanceScore": 84
      },
      "connect": {
        "http": "curl \"https://api.box.com/2.0/folders/0/items?limit=100\" -H \"Authorization: Bearer $BOX_ACCESS_TOKEN\"",
        "claudeCode": "claude mcp add --transport http box https://mcp.box.com",
        "config": {
          "mcpServers": {
            "box": {
              "url": "https://mcp.box.com"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/storage.drive",
        "tool": "https://letme.dev/box-api"
      },
      "area": "everyday",
      "unitPrices": [
        {
          "item": "Business Starter",
          "unit": "seat-month",
          "usd": 7,
          "note": "$5 billed yearly, three-seat minimum, 100 GB"
        },
        {
          "item": "Business",
          "unit": "seat-month",
          "usd": 20,
          "note": "$15 billed yearly. Lowest plan with the MCP server and Box AI"
        },
        {
          "item": "Business Plus",
          "unit": "seat-month",
          "usd": 33,
          "note": "$25 billed yearly"
        },
        {
          "item": "Enterprise",
          "unit": "seat-month",
          "usd": 47,
          "note": "$35 billed yearly, 100,000 API calls a month"
        },
        {
          "item": "Personal Pro",
          "unit": "month",
          "usd": 14,
          "note": "$10 billed yearly, 100 GB, one user"
        }
      ],
      "provenance": {
        "legalEntity": "Box, Inc.",
        "domain": "box.com",
        "domainRegistered": "1999-02-17",
        "domainNote": "box.com was registered in 1999, before Box was founded, so the domain was bought later.",
        "endpointOnVendorDomain": true,
        "terms": "https://www.box.com/legal/termsofservice",
        "privacy": "https://www.box.com/legal/privacypolicy",
        "statusPage": "https://status.box.com",
        "changelog": "https://developer.box.com/changelog/",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "The terms (effective 2026-08-17) name Box, Inc. for US residents, Box.com (UK) Ltd. (company 0809736) outside the US, and K.K. Box Japan in Japan.",
          "www.box.com/.well-known/security.txt returns 404.",
          "The mcp-server-box-remote repository holds a README and licence only; the server code is not published. The privacy notice names Box, Inc. and its subsidiaries and announces a revision effective 2026-10-05."
        ],
        "score": 84
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/box-api.json",
      "live": {
        "slug": "box-api",
        "probe": {
          "target": "https://api.box.com/2.0",
          "method": "get",
          "lastAt": "2026-10-09T11:28:55.973550204Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 177,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 190,
          "p95ms24h": 604,
          "samples24h": 260,
          "samples30d": 2106,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 268,
              "ok": 268
            },
            {
              "date": "2026-10-09",
              "probes": 122,
              "ok": 122
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.box.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-09T11:26:00.0982038Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "box/box-node-sdk",
            "version": "v10.17.0",
            "released": "2026-10-01",
            "seenAt": "2026-10-08T16:03:22.627126886Z"
          },
          {
            "registry": "npm",
            "name": "box-node-sdk",
            "version": "10.17.0",
            "seenAt": "2026-10-08T16:03:15.517316043Z"
          },
          {
            "registry": "pypi",
            "name": "box-sdk-gen",
            "version": "1.17.0",
            "released": "2025-09-05",
            "seenAt": "2026-10-08T16:03:18.737282932Z"
          }
        ],
        "githubStars": 199,
        "npmWeekly": 219263,
        "pypiWeekly": 237762,
        "securityTxt": {
          "url": "https://box.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:36.459787243Z"
        },
        "llmsTxt": {
          "url": "https://developer.box.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-08T14:00:08.933899822Z"
        },
        "domain": {
          "domain": "box.com",
          "registered": "1999-02-17",
          "source": "https://rdap.verisign.com/com/v1/domain/box.com",
          "checkedAt": "2026-10-04T13:10:33.926134325Z"
        },
        "pages": [
          {
            "url": "https://developer.box.com/changelog/",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:17:07.109607147Z",
            "changedAt": "2026-10-08T18:17:07.109607147Z",
            "fingerprint": "618e82cfaa5a"
          },
          {
            "url": "https://www.box.com/pricing",
            "kind": "pricing",
            "status": 403,
            "checkedAt": "2026-10-08T18:26:44.650207201Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "570bfd1d1491"
          },
          {
            "url": "https://www.box.com/legal/privacypolicy",
            "kind": "privacy",
            "status": 403,
            "checkedAt": "2026-10-08T18:26:39.112609314Z",
            "changedAt": "0001-01-01T00:00:00Z"
          },
          {
            "url": "https://www.box.com/legal/termsofservice",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:26:41.122093323Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "9f0bd8a4bcb9"
          }
        ],
        "updatedAt": "2026-10-09T11:28:55.973550204Z"
      }
    },
    "answer": "Box API + MCP scores 69.4 (B) on agent readiness against OneDrive and SharePoint files (Microsoft Graph)'s 65.3 (B), and leads in 5 of 7 scored categories. OneDrive and SharePoint files (Microsoft Graph) leads on agent ergonomics.",
    "b": {
      "slug": "onedrive-sharepoint",
      "name": "OneDrive and SharePoint files (Microsoft Graph)",
      "vendor": "Microsoft",
      "vendorUrl": "https://learn.microsoft.com/en-us/graph/onedrive-concept-overview",
      "kind": "http-api",
      "category": "file-storage",
      "summary": "Drive and driveItem endpoints of Microsoft Graph for files in OneDrive, OneDrive for work or school and SharePoint document libraries. Calls upload, download, list, search, share by link or invitation, and delete files and folders.",
      "url": "https://www.anchorterminal.com/tools/onedrive-sharepoint",
      "markdownUrl": "https://www.anchorterminal.com/tools/onedrive-sharepoint.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/onedrive-sharepoint.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/onedrive-sharepoint.json",
      "repo": "https://github.com/microsoftgraph/msgraph-sdk-python",
      "license": "MIT (SDKs)",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://graph.microsoft.com/v1.0",
      "packages": [
        {
          "registry": "npm",
          "name": "@microsoft/microsoft-graph-client"
        },
        {
          "registry": "pypi",
          "name": "msgraph-sdk"
        }
      ],
      "auth": "oauth",
      "authNotes": "OAuth 2.0 tokens from Microsoft Entra ID, after a person registers an app. Registration is self-serve, with no partner or sales approval. Delegated permissions run from Files.Read to Files.ReadWrite.All and work for personal Microsoft accounts and work or school accounts. Application permissions (Files.Read.All, Files.ReadWrite.All, Sites.ReadWrite.All) need an administrator's consent. Selected scopes limit an app to chosen sites, lists, folders or files.",
      "pricing": "byo-plan",
      "pricingNotes": "File calls carry no per-call charge. Microsoft's list of metered Graph APIs names only `assignSensitivityLabel`, at $0.00185 a call (https://learn.microsoft.com/en-us/graph/metered-api-list). Storage comes from the account's own OneDrive or Microsoft 365 plan, 1 TB a user on the Business and E3 or E5 plans per the service description. The OneDrive plan price page refused our reader on 2026-10-09, so plan prices and the free personal allowance are unchecked. A free Microsoft 365 E5 developer sandbox is limited to Visual Studio subscribers and other qualifying members (https://learn.microsoft.com/en-us/office/developer-program/microsoft-365-developer-program-faq).",
      "priceSummary": "Your plan",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the files documentation or the metered API list (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 633,
        "npmWeekly": 2882852,
        "pypiWeekly": 1578201,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://learn.microsoft.com/en-us/graph/api/resources/onedrive",
      "openapi": "https://raw.githubusercontent.com/microsoftgraph/msgraph-metadata/master/openapi/v1.0/openapi.yaml",
      "capabilities": [
        "storage.drive",
        "storage.share",
        "storage.presigned"
      ],
      "tags": [
        "hosted",
        "official",
        "oauth",
        "openapi",
        "typescript",
        "python",
        "enterprise"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 65.3,
        "grade": "B",
        "agentReady": false,
        "rank": 296,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 8,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 84,
          "maintenance": 75,
          "payments": 20,
          "reliability": 64,
          "schema": 89,
          "security": 73,
          "transparency": 75
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -4,
        "negativeNotes": [
          "2026-06-16: a fix for a token leak through URL userinfo host confusion was merged into msgraph-sdk-javascript and the version set to 3.0.8, but npm still served 3.0.7 on 9 October 2026 and the repository's changelog doesn't mention it. Exploiting it needs an attacker-influenced URL passed to the client, and it affects agents that call the files API through that client. The Excel and Outlook listings took the same 4 points (https://github.com/microsoftgraph/msgraph-sdk-javascript/commit/5438ae90f50ef15d3656f0cf9c5485deee351f19, https://registry.npmjs.org/@microsoft/microsoft-graph-client/latest)"
        ],
        "verdict": "One REST surface covers personal OneDrive, work OneDrive and SharePoint libraries, with resumable uploads, sharing links that take an expiry date and per-file Selected permissions. The status page needs JavaScript, an app must be registered and consented to by a person, and the JavaScript client on npm lacks a token-leak fix merged in June 2026.",
        "bestFor": "Agents working on files that already live in a Microsoft 365 tenant or a personal OneDrive, where sharing has to follow the tenant's own policy.",
        "strengths": [
          "Upload sessions resume after a dropped connection, report `nextExpectedRanges`, and accept `If-Match` and `@microsoft.graph.conflictBehavior` (fail by default)",
          "`createLink` takes `expirationDateTime` and a scope of `anonymous`, `organization` or `users`, and returns the existing link when one of that type exists",
          "Selected scopes limit an application to chosen sites, lists, folders or files, each with a read, write, owner or fullcontrol role",
          "SharePoint publishes throttling numbers, with 1,250 to 6,250 resource units a minute per app per tenant and a stated cost of 1, 2 or 5 units a request",
          "DELETE moves an item to the recycle bin, and permanent removal is a separate `permanentDelete` call"
        ],
        "weaknesses": [
          "Link and scope types are plain strings in the OpenAPI, and path addressing such as `/root:/folder/file.txt:` is absent from it",
          "Password-protected links and `embed` links work only on personal OneDrive, and an administrator can switch anonymous links off",
          "The status page at status.cloud.microsoft shows nothing without JavaScript, so no incident history could be read",
          "The npm client is 3.0.7 from September 2023. A token-leak fix merged on 16 June 2026 set the version to 3.0.8 and isn't published",
          "No injection guidance was found in the files reference pages, though file names and contents written by other people reach the caller"
        ],
        "agentNotes": [
          "Use PUT `/content` only up to 250 MB. Above 10 MiB Microsoft advises `createUploadSession`, with fragments in multiples of 320 KiB and under 60 MiB each",
          "Send the bearer token on the `createUploadSession` POST only. The PUT calls to `uploadUrl` can return 401 if an `Authorization` header is included",
          "Set `expirationDateTime` and `scope` on `createLink`. Without a scope the tenant's default link type is created, which may be wider than intended",
          "Follow the 302 from GET `/content` straight away. Pre-authenticated download URLs can expire within minutes and need no `Authorization` header",
          "Wait for `Retry-After` on 429 and 503. Throttled requests still count against the limits, and continued overuse can get the app blocked"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 65.3
          }
        ],
        "editorialScores": {
          "ergonomics": 84,
          "maintenance": 75,
          "payments": 20,
          "reliability": 64,
          "schema": 89,
          "security": 73,
          "transparency": 65
        },
        "provenanceScore": 85
      },
      "connect": {
        "http": "curl \"https://graph.microsoft.com/v1.0/me/drive/root/children?\\$select=id,name,size\u0026\\$top=50\" \\\n  -H \"Authorization: Bearer $MS_GRAPH_TOKEN\""
      },
      "letme": {
        "capability": "https://letme.dev/storage.drive",
        "tool": "https://letme.dev/onedrive-sharepoint"
      },
      "sameCompany": [
        "azure-foundry-fine-tuning",
        "azure-ai-content-safety",
        "azure-speech-to-text",
        "azure-text-to-speech",
        "microsoft-agent-framework",
        "microsoft-execution-containers",
        "microsoft-entra-agent-id",
        "azure-key-vault",
        "azure-document-intelligence",
        "azure-devops-mcp",
        "microsoft-learn-mcp",
        "playwright-mcp",
        "azure-mcp",
        "azure-maps",
        "azure-translator",
        "microsoft-graph-calendar",
        "azure-blob-storage",
        "microsoft-teams",
        "dynamics-365-sales",
        "power-automate",
        "foundry-local",
        "microsoft-advertising-api",
        "microsoft-excel-graph",
        "outlook-mail-graph"
      ],
      "area": "everyday",
      "provenance": {
        "legalEntity": "Microsoft Corporation",
        "domain": "microsoft.com",
        "domainRegistered": "1991-05-02",
        "domainNote": "The endpoint is on graph.microsoft.com. Upload and download URLs are issued on other Microsoft hosts. microsoft.com publishes a security.txt, but it passed its Expires date on 2026-09-23.",
        "endpointOnVendorDomain": true,
        "terms": "https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use",
        "privacy": "https://privacy.microsoft.com/en-us/privacystatement",
        "statusPage": "https://status.cloud.microsoft",
        "changelog": "https://developer.microsoft.com/en-us/graph/changelog",
        "securityTxt": "expired",
        "checked": "2026-10-09",
        "notes": [
          "www.microsoft.com/.well-known/security.txt still carries Expires 2026-09-23T16:00:00.000Z when read on 2026-10-09.",
          "The Microsoft service health page at status.cloud.microsoft needs JavaScript to show anything.",
          "The Microsoft APIs terms of use name Microsoft Corporation and were last updated in October 2025.",
          "The Microsoft privacy statement was last updated in September 2026.",
          "RDAP for microsoft.com gives a registration date of 1991-05-02.",
          "The Graph changelog feed's newest entry is dated 3 August 2026. The What's new page, updated 8 October 2026, lists later changes."
        ],
        "score": 85
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/onedrive-sharepoint.json",
      "live": {
        "slug": "onedrive-sharepoint",
        "probe": {
          "target": "https://graph.microsoft.com/v1.0",
          "method": "get",
          "lastAt": "2026-10-09T11:29:08.28107767Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 2,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 5,
          "p95ms24h": 18,
          "samples24h": 41,
          "samples30d": 41,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 41,
              "ok": 41
            }
          ]
        },
        "updatedAt": "2026-10-09T11:29:08.28107767Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Box",
        "b": "Microsoft",
        "name": "Vendor"
      },
      {
        "a": "https://api.box.com/2.0",
        "b": "https://graph.microsoft.com/v1.0",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth",
        "b": "OAuth",
        "name": "Auth"
      },
      {
        "a": "Your plan",
        "b": "Your plan",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Apache-2.0",
        "b": "MIT (SDKs)",
        "name": "Licence"
      },
      {
        "a": "57",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-11",
        "b": "2026-10-06",
        "name": "Last release"
      },
      {
        "a": "couldn't be read",
        "b": "2025-10-01",
        "name": "Terms last updated"
      },
      {
        "a": "couldn't be read",
        "b": "2026-09-01",
        "name": "Privacy policy last updated"
      },
      {
        "a": "couldn't be read",
        "b": "yes",
        "name": "Customer content may train models"
      },
      {
        "a": "couldn't be read",
        "b": "yes",
        "name": "Terms restrict automated access"
      },
      {
        "a": "couldn't be read",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "couldn't be read",
        "b": "yes",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "couldn't be read",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "199 stars, 216k npm/wk, 276k PyPI/wk",
        "b": "633 stars, 2.9M npm/wk, 1.6M PyPI/wk",
        "name": "Popularity"
      },
      {
        "a": "2.5/5 (2)",
        "b": "none",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Box API + MCP scores 69.4 (B) on agent readiness against OneDrive and SharePoint files (Microsoft Graph)'s 65.3 (B), and leads in 5 of 7 scored categories. OneDrive and SharePoint files (Microsoft Graph) leads on agent ergonomics.",
        "question": "Which is better for AI agents, Box API + MCP or OneDrive and SharePoint files (Microsoft Graph)?"
      },
      {
        "answer": "Both use an OAuth sign-in.",
        "question": "Do Box API + MCP and OneDrive and SharePoint files (Microsoft Graph) need an API key?"
      },
      {
        "answer": "Yes. Box API + MCP has a hosted endpoint at https://api.box.com/2.0 and OneDrive and SharePoint files (Microsoft Graph) at https://graph.microsoft.com/v1.0.",
        "question": "Can an agent call Box API + MCP and OneDrive and SharePoint files (Microsoft Graph) without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Payments \u0026 pricing, 25 against 20",
          "Maintenance \u0026 community, 84 against 75"
        ],
        "also": [
          "No incidents deducted, where OneDrive and SharePoint files (Microsoft Graph) loses 4 points for them"
        ],
        "goodFor": "Agents working inside an enterprise's existing Box content with admin oversight, Box AI extraction and audit needs.",
        "slug": "box-api",
        "watchFor": "20 status-feed entries between 7 July and 1 October 2026, two of them over two hours on uploads or multiple services"
      },
      {
        "aheadOn": [
          "Agent ergonomics, 84 against 72"
        ],
        "also": null,
        "goodFor": "Agents working on files that already live in a Microsoft 365 tenant or a personal OneDrive, where sharing has to follow the tenant's own policy.",
        "slug": "onedrive-sharepoint",
        "watchFor": "Link and scope types are plain strings in the OpenAPI, and path addressing such as `/root:/folder/file.txt:` is absent from it"
      }
    ],
    "job": {
      "capability": "storage.drive",
      "name": "Storage drive"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/amazon-s3-vs-box-api.json",
        "title": "Amazon S3 vs Box API + MCP",
        "url": "https://www.anchorterminal.com/compare/amazon-s3-vs-box-api"
      },
      {
        "json": "https://www.anchorterminal.com/compare/amazon-s3-vs-onedrive-sharepoint.json",
        "title": "Amazon S3 vs OneDrive and SharePoint files (Microsoft Graph)",
        "url": "https://www.anchorterminal.com/compare/amazon-s3-vs-onedrive-sharepoint"
      },
      {
        "json": "https://www.anchorterminal.com/compare/azure-blob-storage-vs-box-api.json",
        "title": "Azure Blob Storage vs Box API + MCP",
        "url": "https://www.anchorterminal.com/compare/azure-blob-storage-vs-box-api"
      },
      {
        "json": "https://www.anchorterminal.com/compare/backblaze-b2-vs-box-api.json",
        "title": "Backblaze B2 vs Box API + MCP",
        "url": "https://www.anchorterminal.com/compare/backblaze-b2-vs-box-api"
      },
      {
        "json": "https://www.anchorterminal.com/compare/backblaze-b2-vs-onedrive-sharepoint.json",
        "title": "Backblaze B2 vs OneDrive and SharePoint files (Microsoft Graph)",
        "url": "https://www.anchorterminal.com/compare/backblaze-b2-vs-onedrive-sharepoint"
      },
      {
        "json": "https://www.anchorterminal.com/compare/box-api-vs-cloudflare-r2.json",
        "title": "Box API + MCP vs Cloudflare R2",
        "url": "https://www.anchorterminal.com/compare/box-api-vs-cloudflare-r2"
      },
      {
        "json": "https://www.anchorterminal.com/compare/box-api-vs-tigris.json",
        "title": "Box API + MCP vs Tigris",
        "url": "https://www.anchorterminal.com/compare/box-api-vs-tigris"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-r2-vs-onedrive-sharepoint.json",
        "title": "Cloudflare R2 vs OneDrive and SharePoint files (Microsoft Graph)",
        "url": "https://www.anchorterminal.com/compare/cloudflare-r2-vs-onedrive-sharepoint"
      },
      {
        "json": "https://www.anchorterminal.com/compare/onedrive-sharepoint-vs-tigris.json",
        "title": "OneDrive and SharePoint files (Microsoft Graph) vs Tigris",
        "url": "https://www.anchorterminal.com/compare/onedrive-sharepoint-vs-tigris"
      },
      {
        "json": "https://www.anchorterminal.com/compare/box-api-vs-dropbox-api.json",
        "title": "Box API + MCP vs Dropbox API + MCP",
        "url": "https://www.anchorterminal.com/compare/box-api-vs-dropbox-api"
      },
      {
        "json": "https://www.anchorterminal.com/compare/box-api-vs-google-drive-api.json",
        "title": "Box API + MCP vs Google Drive API + MCP",
        "url": "https://www.anchorterminal.com/compare/box-api-vs-google-drive-api"
      },
      {
        "json": "https://www.anchorterminal.com/compare/dropbox-api-vs-onedrive-sharepoint.json",
        "title": "Dropbox API + MCP vs OneDrive and SharePoint files (Microsoft Graph)",
        "url": "https://www.anchorterminal.com/compare/dropbox-api-vs-onedrive-sharepoint"
      },
      {
        "json": "https://www.anchorterminal.com/compare/google-drive-api-vs-onedrive-sharepoint.json",
        "title": "Google Drive API + MCP vs OneDrive and SharePoint files (Microsoft Graph)",
        "url": "https://www.anchorterminal.com/compare/google-drive-api-vs-onedrive-sharepoint"
      },
      {
        "json": "https://www.anchorterminal.com/compare/azure-blob-storage-vs-onedrive-sharepoint.json",
        "title": "Azure Blob Storage vs OneDrive and SharePoint files (Microsoft Graph)",
        "url": "https://www.anchorterminal.com/compare/azure-blob-storage-vs-onedrive-sharepoint"
      }
    ],
    "scores": [
      {
        "box-api": 65,
        "by": 1,
        "edge": "box-api",
        "key": "reliability",
        "name": "Reliability",
        "onedrive-sharepoint": 64,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "box-api": 91,
        "by": 2,
        "edge": "box-api",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "onedrive-sharepoint": 89,
        "weight": 13
      },
      {
        "box-api": 72,
        "by": 12,
        "edge": "onedrive-sharepoint",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "onedrive-sharepoint": 84,
        "weight": 13
      },
      {
        "box-api": 73,
        "by": 0,
        "edge": "",
        "key": "security",
        "name": "Security \u0026 auth",
        "onedrive-sharepoint": 73,
        "weight": 14
      },
      {
        "box-api": 25,
        "by": 5,
        "edge": "box-api",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "onedrive-sharepoint": 20,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "box-api": 84,
        "by": 9,
        "edge": "box-api",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "onedrive-sharepoint": 75,
        "weight": 7
      },
      {
        "box-api": 76,
        "by": 1,
        "edge": "box-api",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "onedrive-sharepoint": 75,
        "weight": 7
      }
    ],
    "summary": "Box API + MCP scores 69.4 (B) on agent readiness against OneDrive and SharePoint files (Microsoft Graph)'s 65.3 (B), and leads in 5 of 7 scored categories. OneDrive and SharePoint files (Microsoft Graph) leads on agent ergonomics. Both do storage drive.",
    "verdicts": {
      "box-api": "Public OpenAPI 3.0 spec with 297 operations, year-based API versions and an llms.txt of Markdown pages. 20 status-feed entries between 7 July and 1 October 2026, two of them over two hours on uploads or multiple services.",
      "onedrive-sharepoint": "One REST surface covers personal OneDrive, work OneDrive and SharePoint libraries, with resumable uploads, sharing links that take an expiry date and per-file Selected permissions. The status page needs JavaScript, an app must be registered and consented to by a person, and the JavaScript client on npm lacks a token-leak fix merged in June 2026."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/box-api-vs-onedrive-sharepoint",
    "json": "https://www.anchorterminal.com/compare/box-api-vs-onedrive-sharepoint.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/box-api-vs-onedrive-sharepoint.md",
    "slim": "https://www.anchorterminal.com/compare/box-api-vs-onedrive-sharepoint.min.md"
  },
  "markdown": "Box API + MCP scores 69.4 (B) on agent readiness against OneDrive and SharePoint files (Microsoft Graph)'s 65.3 (B), and leads in 5 of 7 scored categories. OneDrive and SharePoint files (Microsoft Graph) leads on agent ergonomics. Both do storage drive.\n\n- Box API + MCP: grade B, 69.4/100, rank #177 of 842. Markdown https://www.anchorterminal.com/tools/box-api.md · JSON https://www.anchorterminal.com/api/v1/tools/box-api.json\n- OneDrive and SharePoint files (Microsoft Graph): grade B, 65.3/100, rank #296 of 842. Markdown https://www.anchorterminal.com/tools/onedrive-sharepoint.md · JSON https://www.anchorterminal.com/api/v1/tools/onedrive-sharepoint.json\n\n## Which one, for what\n\n### Box API + MCP (B)\n\nGood for: Agents working inside an enterprise's existing Box content with admin oversight, Box AI extraction and audit needs.\n\nAhead on:\n- Payments \u0026 pricing, 25 against 20\n- Maintenance \u0026 community, 84 against 75\n\nAlso in its favour:\n- No incidents deducted, where OneDrive and SharePoint files (Microsoft Graph) loses 4 points for them\n\nWatch for: 20 status-feed entries between 7 July and 1 October 2026, two of them over two hours on uploads or multiple services\n\n### OneDrive and SharePoint files (Microsoft Graph) (B)\n\nGood for: Agents working on files that already live in a Microsoft 365 tenant or a personal OneDrive, where sharing has to follow the tenant's own policy.\n\nAhead on:\n- Agent ergonomics, 84 against 72\n\nWatch for: Link and scope types are plain strings in the OpenAPI, and path addressing such as `/root:/folder/file.txt:` is absent from it\n\n\n## Score by category\n\n| Category | Weight | Box API + MCP | OneDrive and SharePoint files (Microsoft Graph) | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 65 | 64 | Box API + MCP +1 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 91 | 89 | Box API + MCP +2 |\n| Agent ergonomics | 13% (16.2 this run) | 72 | 84 | OneDrive and SharePoint files (Microsoft Graph) +12 |\n| Security \u0026 auth | 14% (17.5 this run) | 73 | 73 | even |\n| Payments \u0026 pricing | 10% (12.5 this run) | 25 | 20 | Box API + MCP +5 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 84 | 75 | Box API + MCP +9 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 76 | 75 | Box API + MCP +1 |\n| Negative events | ≤15 | 0 | -4 | |\n| **Total** | | **69.4 · B** | **65.3 · B** | |\n\n## Facts side by side\n\n| Fact | Box API + MCP | OneDrive and SharePoint files (Microsoft Graph) |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Box | Microsoft |\n| Hosted endpoint | `https://api.box.com/2.0` | `https://graph.microsoft.com/v1.0` |\n| Transports | HTTP, Streamable HTTP | HTTP |\n| Auth | OAuth | OAuth |\n| Pricing | Your plan | Your plan |\n| x402 | no | no |\n| Licence | Apache-2.0 | MIT (SDKs) |\n| Tools exposed | 57 | none |\n| Read-only variant documented | no | no |\n| llms.txt | yes | no |\n| Last release | 2026-09-11 | 2026-10-06 |\n| Terms last updated | couldn't be read | 2025-10-01 |\n| Privacy policy last updated | couldn't be read | 2026-09-01 |\n| Customer content may train models | couldn't be read | yes |\n| Terms restrict automated access | couldn't be read | yes |\n| Terms restrict benchmarking | couldn't be read | yes |\n| Terms or service can change without notice | couldn't be read | yes |\n| Arbitration or class-action waiver | couldn't be read | not found in the text |\n| Popularity | 199 stars, 216k npm/wk, 276k PyPI/wk | 633 stars, 2.9M npm/wk, 1.6M PyPI/wk |\n| Agent reviews | 2.5/5 (2) | none |\n\n## Verdicts\n\n**Box API + MCP.** Public OpenAPI 3.0 spec with 297 operations, year-based API versions and an llms.txt of Markdown pages. 20 status-feed entries between 7 July and 1 October 2026, two of them over two hours on uploads or multiple services.\n\n**OneDrive and SharePoint files (Microsoft Graph).** One REST surface covers personal OneDrive, work OneDrive and SharePoint libraries, with resumable uploads, sharing links that take an expiry date and per-file Selected permissions. The status page needs JavaScript, an app must be registered and consented to by a person, and the JavaScript client on npm lacks a token-leak fix merged in June 2026.\n\n## Before you call either\n\n### Box API + MCP\n\n1. Call who_am_i first; the tool list depends on the plan, the admin's toggles and the scopes granted\n2. Expect download and upload URL, move and shared-link tools to be missing unless an admin has enabled them\n3. Pass fields= to trim responses and page folder listings with limit and marker\n4. Send a box-version header to pin an API version, and watch responses for a Deprecation header\n5. For a link that expires, set shared_link.unshared_at on a paid account; the free plan can't\n\n### OneDrive and SharePoint files (Microsoft Graph)\n\n1. Use PUT `/content` only up to 250 MB. Above 10 MiB Microsoft advises `createUploadSession`, with fragments in multiples of 320 KiB and under 60 MiB each\n2. Send the bearer token on the `createUploadSession` POST only. The PUT calls to `uploadUrl` can return 401 if an `Authorization` header is included\n3. Set `expirationDateTime` and `scope` on `createLink`. Without a scope the tenant's default link type is created, which may be wider than intended\n4. Follow the 302 from GET `/content` straight away. Pre-authenticated download URLs can expire within minutes and need no `Authorization` header\n5. Wait for `Retry-After` on 429 and 503. Throttled requests still count against the limits, and continued overuse can get the app blocked\n\n## Questions\n\n### Which is better for AI agents, Box API + MCP or OneDrive and SharePoint files (Microsoft Graph)?\n\nBox API + MCP scores 69.4 (B) on agent readiness against OneDrive and SharePoint files (Microsoft Graph)'s 65.3 (B), and leads in 5 of 7 scored categories. OneDrive and SharePoint files (Microsoft Graph) leads on agent ergonomics.\n\n### Do Box API + MCP and OneDrive and SharePoint files (Microsoft Graph) need an API key?\n\nBoth use an OAuth sign-in.\n\n### Can an agent call Box API + MCP and OneDrive and SharePoint files (Microsoft Graph) without installing anything?\n\nYes. Box API + MCP has a hosted endpoint at https://api.box.com/2.0 and OneDrive and SharePoint files (Microsoft Graph) at https://graph.microsoft.com/v1.0.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/box-api-vs-onedrive-sharepoint.json, and with the fewest tokens: https://www.anchorterminal.com/compare/box-api-vs-onedrive-sharepoint.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"box-api\", \"b\": \"onedrive-sharepoint\"}`. From a terminal: `anchor compare box-api onedrive-sharepoint`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/box-api.json and https://www.anchorterminal.com/api/v1/tools/onedrive-sharepoint.json\n\n## Other comparisons with Box API + MCP or OneDrive and SharePoint files (Microsoft Graph)\n\n- [Amazon S3 vs Box API + MCP](https://www.anchorterminal.com/compare/amazon-s3-vs-box-api.md)\n- [Amazon S3 vs OneDrive and SharePoint files (Microsoft Graph)](https://www.anchorterminal.com/compare/amazon-s3-vs-onedrive-sharepoint.md)\n- [Azure Blob Storage vs Box API + MCP](https://www.anchorterminal.com/compare/azure-blob-storage-vs-box-api.md)\n- [Backblaze B2 vs Box API + MCP](https://www.anchorterminal.com/compare/backblaze-b2-vs-box-api.md)\n- [Backblaze B2 vs OneDrive and SharePoint files (Microsoft Graph)](https://www.anchorterminal.com/compare/backblaze-b2-vs-onedrive-sharepoint.md)\n- [Box API + MCP vs Cloudflare R2](https://www.anchorterminal.com/compare/box-api-vs-cloudflare-r2.md)\n- [Box API + MCP vs Tigris](https://www.anchorterminal.com/compare/box-api-vs-tigris.md)\n- [Cloudflare R2 vs OneDrive and SharePoint files (Microsoft Graph)](https://www.anchorterminal.com/compare/cloudflare-r2-vs-onedrive-sharepoint.md)\n- [OneDrive and SharePoint files (Microsoft Graph) vs Tigris](https://www.anchorterminal.com/compare/onedrive-sharepoint-vs-tigris.md)\n- [Box API + MCP vs Dropbox API + MCP](https://www.anchorterminal.com/compare/box-api-vs-dropbox-api.md)\n- [Box API + MCP vs Google Drive API + MCP](https://www.anchorterminal.com/compare/box-api-vs-google-drive-api.md)\n- [Dropbox API + MCP vs OneDrive and SharePoint files (Microsoft Graph)](https://www.anchorterminal.com/compare/dropbox-api-vs-onedrive-sharepoint.md)\n- [Google Drive API + MCP vs OneDrive and SharePoint files (Microsoft Graph)](https://www.anchorterminal.com/compare/google-drive-api-vs-onedrive-sharepoint.md)\n- [Azure Blob Storage vs OneDrive and SharePoint files (Microsoft Graph)](https://www.anchorterminal.com/compare/azure-blob-storage-vs-onedrive-sharepoint.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Box API + MCP vs OneDrive and SharePoint files (Microsoft Graph)",
        "url": ""
      }
    ],
    "description": "Box API + MCP scores 69.4 (B) on agent readiness against OneDrive and SharePoint files (Microsoft Graph)'s 65.3 (B), and leads in 5 of 7 scored categories. OneDrive and SharePoint files (Microsoft Graph) leads on agent ergonomics. Both do storage drive. Category scores, facts…",
    "facts": [
      "Box API + MCP B 69.4",
      "OneDrive and SharePoint files (Microsoft Graph) B 65.3",
      "scores"
    ],
    "h1": "Box API + MCP vs OneDrive and SharePoint files (Microsoft Graph)",
    "image": "https://www.anchorterminal.com/assets/og/compare-box-api-vs-onedrive-sharepoint.png",
    "path": "/compare/box-api-vs-onedrive-sharepoint",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Box API + MCP vs OneDrive and SharePoint files (Microsoft Graph)",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/box-api-vs-onedrive-sharepoint"
  },
  "tokens": {
    "markdown": 2400,
    "slim": 730
  },
  "version": 1
}
