{
  "data": {
    "a": {
      "slug": "box-api",
      "name": "Box API + MCP",
      "vendor": "Box",
      "vendorUrl": "https://developer.box.com",
      "kind": "http-api",
      "category": "file-storage",
      "summary": "Enterprise content platform with a REST API for files, folders, shared links, collaborations, metadata and Box AI, published as OpenAPI with year-based API versions.",
      "url": "https://www.anchorterminal.com/tools/box-api",
      "markdownUrl": "https://www.anchorterminal.com/tools/box-api.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/box-api.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/box-api.json",
      "repo": "https://github.com/box/box-node-sdk",
      "license": "Apache-2.0",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.box.com/2.0",
      "packages": [
        {
          "registry": "npm",
          "name": "box-node-sdk"
        },
        {
          "registry": "pypi",
          "name": "box-sdk-gen"
        }
      ],
      "auth": "oauth",
      "authNotes": "OAuth 2.0 against https://account.box.com/api/oauth2/authorize and https://api.box.com/oauth2/token, with a Bearer access token on every call. Server-side apps can use JWT or client credentials instead. The remote MCP server is an OAuth-protected resource (metadata at https://mcp.box.com/.well-known/oauth-protected-resource) and asks for the root_readwrite, ai.readwrite and docgen.readwrite scopes; the last needs an Enterprise Advanced licence. Users only ever see content they already have access to in Box.",
      "pricing": "byo-plan",
      "pricingNotes": "The API and MCP server come with a Box plan. Individual is free with 10 GB and a 250 MB upload limit. Personal Pro $14 a month ($10 billed yearly). Business plans need three users, Business Starter $7 a user a month ($5 yearly, 100 GB), Business $20 ($15, unlimited storage, 5 GB uploads, Box AI, 50,000 API calls a month), Business Plus $33 ($25, 15 GB uploads), Enterprise $47 ($35, 50 GB uploads, 1,000 AI units, 100,000 API calls), Enterprise Plus $50 a user a month billed yearly (150 GB uploads, 2,000 AI units), Enterprise Advanced on request (500 GB uploads, 20,000 AI units, 200,000 API calls). The MCP server needs Business or above. Extra API calls are sold as Platform pricing (https://www.box.com/pricing; https://support.box.com/hc/en-us/articles/43974584000659).",
      "priceSummary": "Your plan",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": 57,
      "popularity": {
        "githubStars": 199,
        "npmWeekly": 215715,
        "pypiWeekly": 275500,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://developer.box.com/guides/",
      "llmsTxt": "https://developer.box.com/llms.txt",
      "openapi": "https://raw.githubusercontent.com/box/box-openapi/main/openapi.json",
      "capabilities": [
        "storage.drive",
        "storage.share",
        "work.docs"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "mcp",
        "oauth",
        "enterprise",
        "typescript",
        "python",
        "webhooks"
      ],
      "lastRelease": "2026-09-11",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 69.6,
        "grade": "B",
        "agentReady": false,
        "rank": 109,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 5,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 72,
          "maintenance": 84,
          "payments": 25,
          "reliability": 65,
          "schema": 91,
          "security": 73,
          "transparency": 79
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Public OpenAPI 3.0 spec with 297 operations, year-based API versions and an llms.txt of Markdown pages. 20 status-feed entries between 7 July and 1 October 2026, two of them over two hours on uploads or multiple services.",
        "strengths": [
          "Public OpenAPI 3.0 spec with 297 operations, year-based API versions and an llms.txt of Markdown pages",
          "At least 24 months between deprecation and retirement of an API version, with Deprecation response headers",
          "Official remote MCP server with OAuth, 57 tools and 22 riskier ones off until an admin enables them",
          "Documented rate limits (1,000 calls a minute a user, 240 uploads a minute) with a 429 and retry-after",
          "SDKs in Node, Python, Java, Windows (.NET) and iOS, all released on 9 September 2026"
        ],
        "weaknesses": [
          "20 status-feed entries between 7 July and 1 October 2026, two of them over two hours on uploads or multiple services",
          "MCP server needs Business or above, a three-seat minimum, and admin enablement per tool group",
          "The MCP server asks for root_readwrite, so a connected agent can write wherever its user can once tools are on",
          "API calls are metered per enterprise, 50,000 a month on Business",
          "No security.txt on box.com, and no bug bounty on its security page"
        ],
        "agentNotes": [
          "Call who_am_i first; the tool list depends on the plan, the admin's toggles and the scopes granted",
          "Expect download and upload URL, move and shared-link tools to be missing unless an admin has enabled them",
          "Pass fields= to trim responses and page folder listings with limit and marker",
          "Send a box-version header to pin an API version, and watch responses for a Deprecation header",
          "For a link that expires, set shared_link.unshared_at on a paid account; the free plan can't"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 69.6
          }
        ],
        "editorialScores": {
          "ergonomics": 72,
          "maintenance": 84,
          "payments": 25,
          "reliability": 65,
          "schema": 91,
          "security": 73,
          "transparency": 68
        },
        "provenanceScore": 90
      },
      "connect": {
        "http": "curl \"https://api.box.com/2.0/folders/0/items?limit=100\" -H \"Authorization: Bearer $BOX_ACCESS_TOKEN\"",
        "claudeCode": "claude mcp add --transport http box https://mcp.box.com",
        "config": {
          "mcpServers": {
            "box": {
              "url": "https://mcp.box.com"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/storage.drive",
        "tool": "https://letme.dev/box-api"
      },
      "area": "everyday",
      "unitPrices": [
        {
          "item": "Business Starter",
          "unit": "seat-month",
          "usd": 7,
          "note": "$5 billed yearly, three-seat minimum, 100 GB"
        },
        {
          "item": "Business",
          "unit": "seat-month",
          "usd": 20,
          "note": "$15 billed yearly. Lowest plan with the MCP server and Box AI"
        },
        {
          "item": "Business Plus",
          "unit": "seat-month",
          "usd": 33,
          "note": "$25 billed yearly"
        },
        {
          "item": "Enterprise",
          "unit": "seat-month",
          "usd": 47,
          "note": "$35 billed yearly, 100,000 API calls a month"
        },
        {
          "item": "Personal Pro",
          "unit": "month",
          "usd": 14,
          "note": "$10 billed yearly, 100 GB, one user"
        }
      ],
      "provenance": {
        "legalEntity": "Box, Inc.",
        "domain": "box.com",
        "domainRegistered": "1999-02-17",
        "domainNote": "box.com was registered in 1999, before Box was founded, so the domain was bought later.",
        "endpointOnVendorDomain": true,
        "terms": "https://www.box.com/legal/termsofservice",
        "privacy": "https://www.box.com/legal/privacypolicy",
        "statusPage": "https://status.box.com",
        "changelog": "https://developer.box.com/changelog/",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "The terms (effective 2026-08-17) name Box, Inc. for US residents, Box.com (UK) Ltd. (company 0809736) outside the US, and K.K. Box Japan in Japan.",
          "www.box.com/.well-known/security.txt returns 404.",
          "The mcp-server-box-remote repository holds a README and licence only; the server code is not published. The privacy notice names Box, Inc. and its subsidiaries and announces a revision effective 2026-10-05."
        ],
        "score": 90
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/box-api.json",
      "live": {
        "slug": "box-api",
        "probe": {
          "target": "https://api.box.com/2.0",
          "method": "get",
          "lastAt": "2026-10-05T02:29:52.956919617Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 189,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 188,
          "p95ms24h": 653,
          "samples24h": 273,
          "samples30d": 929,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 29,
              "ok": 29
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.box.com",
          "indicator": "minor",
          "summary": "Partially Degraded Service",
          "checkedAt": "2026-10-05T02:28:51.693661303Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "box/box-node-sdk",
            "version": "v10.17.0",
            "released": "2026-10-01",
            "seenAt": "2026-10-04T16:22:36.948611735Z"
          },
          {
            "registry": "npm",
            "name": "box-node-sdk",
            "version": "10.17.0",
            "seenAt": "2026-10-04T16:22:35.890954565Z"
          },
          {
            "registry": "pypi",
            "name": "box-sdk-gen",
            "version": "1.17.0",
            "released": "2025-09-05",
            "seenAt": "2026-10-04T16:22:36.763493508Z"
          }
        ],
        "githubStars": 199,
        "npmWeekly": 217751,
        "pypiWeekly": 247502,
        "securityTxt": {
          "url": "https://box.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:54.511020509Z"
        },
        "llmsTxt": {
          "url": "https://developer.box.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:21.264522755Z"
        },
        "domain": {
          "domain": "box.com",
          "registered": "1999-02-17",
          "source": "https://rdap.verisign.com/com/v1/domain/box.com",
          "checkedAt": "2026-10-04T13:10:33.926134325Z"
        },
        "pages": [
          {
            "url": "https://developer.box.com/changelog/",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:42:30.311399143Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "cce4b8fc0c08"
          },
          {
            "url": "https://www.box.com/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:49:34.458744601Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "570bfd1d1491"
          },
          {
            "url": "https://www.box.com/legal/privacypolicy",
            "kind": "privacy",
            "status": 403,
            "checkedAt": "2026-10-04T15:49:30.426289091Z",
            "changedAt": "0001-01-01T00:00:00Z"
          },
          {
            "url": "https://www.box.com/legal/termsofservice",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:49:32.437507129Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "9f0bd8a4bcb9"
          }
        ],
        "updatedAt": "2026-10-05T02:29:52.956919617Z"
      }
    },
    "b": {
      "slug": "tigris",
      "name": "Tigris",
      "vendor": "Tigris Data",
      "vendorUrl": "https://www.tigrisdata.com",
      "kind": "http-api",
      "category": "file-storage",
      "summary": "S3-compatible object storage that replicates objects towards where they're read, with no egress fees and one global endpoint (t3.storage.dev).",
      "url": "https://www.anchorterminal.com/tools/tigris",
      "markdownUrl": "https://www.anchorterminal.com/tools/tigris.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/tigris.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/tigris.json",
      "repo": "https://github.com/tigrisdata/tigris-mcp-server",
      "license": "MIT",
      "transports": [
        "http",
        "streamable-http",
        "stdio"
      ],
      "remoteUrl": "https://t3.storage.dev",
      "packages": [
        {
          "registry": "npm",
          "name": "@tigrisdata/tigris-mcp-server"
        },
        {
          "registry": "npm",
          "name": "@tigrisdata/storage"
        }
      ],
      "auth": "mixed",
      "authNotes": "The S3 API takes SigV4 with an access key created in the console or the IAM API (ID starts `tid_`, secret starts `tsec_`) and region `auto`. Keys can be scoped per bucket with ReadOnly, ReadWrite or Editor roles and IAM policies, and revoked or rotated. AssumeRole, STS and temporary credentials aren't supported, so every key lives until revoked. The hosted MCP server signs in with OAuth; the stdio server reads AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY and AWS_ENDPOINT_URL_S3, or an AWS CLI profile.",
      "pricing": "freemium",
      "pricingNotes": "Free every month, 5 GB of Standard storage, 10,000 PUT, COPY, POST and LIST requests and 100,000 GET, SELECT and other requests. Beyond that, Standard $0.02 a GB-month, Infrequent Access $0.01 (30-day minimum, $0.01 a GB retrieval), Archive and Archive Instant Retrieval $0.004 (90-day minimum, $0.03 a GB instant retrieval). Class A requests $0.005 per 1,000, Class B $0.0005 per 1,000, deletes free, object notifications $0.01 per 1,000 events. Egress is free in every tier and region. Storage is metered on the average daily peak over the month (https://www.tigrisdata.com/pricing/).",
      "priceSummary": "$0.005 / 1k req",
      "where": "both",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 4,
        "npmWeekly": 20,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://www.tigrisdata.com/docs/",
      "llmsTxt": "https://www.tigrisdata.com/docs/llms.txt",
      "capabilities": [
        "storage.object",
        "storage.s3",
        "storage.presigned",
        "storage.share"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "s3-compatible",
        "freemium",
        "free-tier",
        "mcp",
        "oauth",
        "typescript",
        "llms-txt"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 44.6,
        "grade": "E",
        "agentReady": false,
        "rank": 404,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 8,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 53,
          "maintenance": 77,
          "payments": 30,
          "reliability": 35,
          "schema": 50,
          "security": 51,
          "transparency": 51
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -3,
        "negativeNotes": [
          "2026-09-21. @tigrisdata/iam 2.6.0 fixed policy create, update and read dropping the Condition and Sid fields, so IP-restricted or time-limited policies made with Tigris's own SDK or CLI had silently become unrestricted. Fixed and documented in the changelog, so we deduct less (-3). https://github.com/tigrisdata/storage/blob/main/packages/iam/CHANGELOG.md"
        ],
        "verdict": "No egress fees, and one endpoint (t3.storage.dev) with region auto for every location. 16 status incidents between 4 July and 2 October 2026, including outages in US regions on 31 July and 2 August.",
        "strengths": [
          "No egress fees, and one endpoint (t3.storage.dev) with region auto for every location",
          "Access keys scoped per bucket with ReadOnly, ReadWrite or Editor roles, plus IAM policies, revocation and rotation",
          "Hosted MCP server at mcp.storage.dev with OAuth, and a local stdio server with 10 tools",
          "Bucket snapshots and copy-on-write forks, wrapped for agents in @tigrisdata/agent-kit",
          "Active MIT SDK monorepo, @tigrisdata/storage 3.22.0 on 30 September 2026"
        ],
        "weaknesses": [
          "16 status incidents between 4 July and 2 October 2026, including outages in US regions on 31 July and 2 August",
          "No STS or expiring keys; presigned URLs, which can run to 90 days, are the only short-lived credential",
          "No published rate limits, retry guidance, OpenAPI, product changelog or audit logs",
          "The stdio MCP server last released on 17 November 2025, lists whole buckets with no limit and carries no tool annotations",
          "@tigrisdata/iam dropped Condition fields from policies until 2.6.0 on 21 September 2026"
        ],
        "agentNotes": [
          "Point the AWS SDK at https://t3.storage.dev with region `auto`; the stdio MCP README still shows the older fly.storage.tigris.dev endpoint",
          "Ask for an access key with a ReadOnly or ReadWrite role on one bucket rather than an org-wide key",
          "Keep presigned URLs short; Tigris accepts up to 90 days",
          "Don't call tigris_list_objects on a large bucket; it walks every object with no limit or prefix",
          "Use @tigrisdata/iam 2.6.0 or later before writing policies with conditions"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "E",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 44.6
          }
        ],
        "editorialScores": {
          "ergonomics": 53,
          "maintenance": 77,
          "payments": 30,
          "reliability": 35,
          "schema": 50,
          "security": 51,
          "transparency": 52
        },
        "provenanceScore": 50
      },
      "connect": {
        "http": "AWS_ACCESS_KEY_ID=$TIGRIS_ACCESS_KEY_ID AWS_SECRET_ACCESS_KEY=$TIGRIS_SECRET_ACCESS_KEY \\\n  aws s3 cp ./hello.txt s3://my-bucket/hello.txt \\\n  --endpoint-url https://t3.storage.dev --region auto",
        "claudeCode": "claude mcp add --transport http tigris https://mcp.storage.dev/mcp --scope user",
        "config": {
          "mcpServers": {
            "tigris": {
              "args": [
                "-y",
                "@tigrisdata/tigris-mcp-server",
                "run"
              ],
              "command": "npx",
              "env": {
                "AWS_ACCESS_KEY_ID": "${TIGRIS_ACCESS_KEY_ID}",
                "AWS_ENDPOINT_URL_S3": "https://t3.storage.dev",
                "AWS_SECRET_ACCESS_KEY": "${TIGRIS_SECRET_ACCESS_KEY}"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/storage.object",
        "tool": "https://letme.dev/tigris"
      },
      "area": "everyday",
      "unitPrices": [
        {
          "item": "Standard storage",
          "unit": "gb-month",
          "usd": 0.02,
          "note": "First 5 GB a month free"
        },
        {
          "item": "Infrequent Access storage",
          "unit": "gb-month",
          "usd": 0.01,
          "note": "30-day minimum, $0.01 a GB retrieval"
        },
        {
          "item": "Archive storage",
          "unit": "gb-month",
          "usd": 0.004,
          "note": "90-day minimum. Archive Instant Retrieval is the same rate plus $0.03 a GB retrieval"
        },
        {
          "item": "Egress",
          "unit": "gb",
          "usd": 0
        },
        {
          "item": "Class A requests (PUT, COPY, POST, LIST)",
          "unit": "1k-requests",
          "usd": 0.005,
          "note": "First 10,000 a month free"
        },
        {
          "item": "Class B requests (GET, SELECT, other)",
          "unit": "1k-requests",
          "usd": 0.0005,
          "note": "First 100,000 a month free"
        }
      ],
      "provenance": {
        "legalEntity": "Tigris Data Inc.",
        "domain": "tigrisdata.com",
        "domainRegistered": "",
        "endpointOnVendorDomain": false,
        "terms": "https://www.tigrisdata.com/docs/legal/service-terms/",
        "privacy": "https://www.tigrisdata.com/docs/legal/privacy-policy/",
        "statusPage": "https://status.tigrisdata.com",
        "changelog": "",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "The service agreement names Tigris Data Inc., 1250 Borregas Ave, #87, Sunnyvale, CA 94089, last updated 2024-12-26.",
          "The S3 endpoint is on storage.dev and the hosted MCP on mcp.storage.dev, not tigrisdata.com.",
          "www.tigrisdata.com/.well-known/security.txt returns 404.",
          "The domain's RDAP record couldn't be fetched on 2026-09-30 (the RDAP server rate-limited us), so the registration date is blank."
        ],
        "score": 50
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/tigris.json",
      "live": {
        "slug": "tigris",
        "probe": {
          "target": "https://t3.storage.dev",
          "method": "get",
          "lastAt": "2026-10-05T02:30:03.66450661Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 135,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 155,
          "p95ms24h": 287,
          "samples24h": 273,
          "samples30d": 929,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 29,
              "ok": 29
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.tigrisdata.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-05T02:29:15.264938688Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "tigrisdata/tigris-mcp-server",
            "version": "v1.14.0",
            "released": "2025-11-17",
            "seenAt": "2026-10-04T16:41:54.881060386Z"
          },
          {
            "registry": "npm",
            "name": "@tigrisdata/storage",
            "version": "3.22.0",
            "seenAt": "2026-10-04T16:41:53.519245468Z"
          },
          {
            "registry": "npm",
            "name": "@tigrisdata/tigris-mcp-server",
            "version": "1.14.0",
            "seenAt": "2026-10-04T16:41:52.671246556Z"
          }
        ],
        "githubStars": 4,
        "npmWeekly": 15,
        "securityTxt": {
          "url": "https://tigrisdata.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:36.802389708Z"
        },
        "llmsTxt": {
          "url": "https://www.tigrisdata.com/docs/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:18:17.942052226Z"
        },
        "domain": {
          "domain": "tigrisdata.com",
          "registered": "2021-09-28",
          "source": "https://rdap.verisign.com/com/v1/domain/tigrisdata.com",
          "checkedAt": "2026-10-04T13:06:26.738654248Z"
        },
        "pages": [
          {
            "url": "https://www.tigrisdata.com/pricing/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-04T15:52:30.927222957Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "31bb3b3a8224"
          },
          {
            "url": "https://www.tigrisdata.com/docs/legal/privacy-policy/",
            "kind": "privacy",
            "status": 404,
            "checkedAt": "2026-10-04T15:52:26.857408966Z",
            "changedAt": "0001-01-01T00:00:00Z"
          },
          {
            "url": "https://www.tigrisdata.com/docs/legal/service-terms/",
            "kind": "terms",
            "status": 404,
            "checkedAt": "2026-10-04T15:52:28.943575422Z",
            "changedAt": "0001-01-01T00:00:00Z"
          }
        ],
        "updatedAt": "2026-10-05T02:30:03.66450661Z"
      }
    },
    "summary": "Box API + MCP has a score of 69.6 (B) against Tigris's 44.6 (E). Both do storage share. The largest gap is schema \u0026 documentation, 41 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/box-api-vs-tigris",
    "json": "https://www.anchorterminal.com/compare/box-api-vs-tigris.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/box-api-vs-tigris.md",
    "slim": "https://www.anchorterminal.com/compare/box-api-vs-tigris.min.md"
  },
  "markdown": "Box API + MCP has a score of 69.6 (B) against Tigris's 44.6 (E). Both do storage share. The largest gap is schema \u0026 documentation, 41 points.\n\n- Box API + MCP: grade B, 69.6/100, rank #109 of 452. Markdown https://www.anchorterminal.com/tools/box-api.md · JSON https://www.anchorterminal.com/api/v1/tools/box-api.json\n- Tigris: grade E, 44.6/100, rank #404 of 452. Markdown https://www.anchorterminal.com/tools/tigris.md · JSON https://www.anchorterminal.com/api/v1/tools/tigris.json\n\n## Which one, for what\n\nPick Box API + MCP for reliability (+30), schema \u0026 documentation (+41), agent ergonomics (+19), security \u0026 auth (+22), maintenance \u0026 community (+7), transparency \u0026 trust (+28).\n\nPick Tigris for payments \u0026 pricing (+5).\n\n## Score by category\n\n| Category | Weight | Box API + MCP | Tigris | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 65 | 35 | Box API + MCP +30 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 91 | 50 | Box API + MCP +41 |\n| Agent ergonomics | 13% (16.2 this run) | 72 | 53 | Box API + MCP +19 |\n| Security \u0026 auth | 14% (17.5 this run) | 73 | 51 | Box API + MCP +22 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 25 | 30 | Tigris +5 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 84 | 77 | Box API + MCP +7 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 79 | 51 | Box API + MCP +28 |\n| Negative events | ≤15 | 0 | -3 | |\n| **Total** | | **69.6 · B** | **44.6 · E** | |\n\n## Facts side by side\n\n| Fact | Box API + MCP | Tigris |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Box | Tigris Data |\n| Hosted endpoint | `https://api.box.com/2.0` | `https://t3.storage.dev` |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP, stdio |\n| Auth | OAuth | OAuth or key |\n| Pricing | Your plan | Freemium |\n| x402 | no | no |\n| Licence | Apache-2.0 | MIT |\n| Tools exposed | 57 | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| MCP registry | not listed | not listed |\n| Last release | 2026-09-11 | 2026-09-30 |\n| Popularity | 199 stars, 216k npm/wk, 276k PyPI/wk | 4 stars, 20 npm/wk |\n| Agent reviews | 2.5/5 (2) | 3/5 (2) |\n\n## Verdicts\n\n**Box API + MCP.** Public OpenAPI 3.0 spec with 297 operations, year-based API versions and an llms.txt of Markdown pages. 20 status-feed entries between 7 July and 1 October 2026, two of them over two hours on uploads or multiple services.\n\n**Tigris.** No egress fees, and one endpoint (t3.storage.dev) with region auto for every location. 16 status incidents between 4 July and 2 October 2026, including outages in US regions on 31 July and 2 August.\n\n## Before you call either\n\n### Box API + MCP\n\n1. Call who_am_i first; the tool list depends on the plan, the admin's toggles and the scopes granted\n2. Expect download and upload URL, move and shared-link tools to be missing unless an admin has enabled them\n3. Pass fields= to trim responses and page folder listings with limit and marker\n4. Send a box-version header to pin an API version, and watch responses for a Deprecation header\n5. For a link that expires, set shared_link.unshared_at on a paid account; the free plan can't\n\n### Tigris\n\n1. Point the AWS SDK at https://t3.storage.dev with region `auto`; the stdio MCP README still shows the older fly.storage.tigris.dev endpoint\n2. Ask for an access key with a ReadOnly or ReadWrite role on one bucket rather than an org-wide key\n3. Keep presigned URLs short; Tigris accepts up to 90 days\n4. Don't call tigris_list_objects on a large bucket; it walks every object with no limit or prefix\n5. Use @tigrisdata/iam 2.6.0 or later before writing policies with conditions\n\n## Other comparisons with Box API + MCP or Tigris\n\n- [Amazon S3 vs Box API + MCP](https://www.anchorterminal.com/compare/amazon-s3-vs-box-api.md)\n- [Backblaze B2 vs Box API + MCP](https://www.anchorterminal.com/compare/backblaze-b2-vs-box-api.md)\n- [Box API + MCP vs Cloudflare R2](https://www.anchorterminal.com/compare/box-api-vs-cloudflare-r2.md)\n- [Dropbox API + MCP vs Tigris](https://www.anchorterminal.com/compare/dropbox-api-vs-tigris.md)\n- [Google Drive API + MCP vs Tigris](https://www.anchorterminal.com/compare/google-drive-api-vs-tigris.md)\n- [Amazon S3 vs Tigris](https://www.anchorterminal.com/compare/amazon-s3-vs-tigris.md)\n- [Backblaze B2 vs Tigris](https://www.anchorterminal.com/compare/backblaze-b2-vs-tigris.md)\n- [Bunny Storage vs Tigris](https://www.anchorterminal.com/compare/bunny-storage-vs-tigris.md)\n- [Cloudflare R2 vs Tigris](https://www.anchorterminal.com/compare/cloudflare-r2-vs-tigris.md)\n- [Box API + MCP vs Dropbox API + MCP](https://www.anchorterminal.com/compare/box-api-vs-dropbox-api.md)\n- [Box API + MCP vs Google Drive API + MCP](https://www.anchorterminal.com/compare/box-api-vs-google-drive-api.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-05",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Box API + MCP vs Tigris",
        "url": ""
      }
    ],
    "description": "Box API + MCP has a score of 69.6 (B) against Tigris's 44.6 (E). Both do storage share. The largest gap is schema \u0026 documentation, 41 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Box API + MCP B 69.6",
      "Tigris E 44.6",
      "scores"
    ],
    "h1": "Box API + MCP vs Tigris",
    "image": "https://www.anchorterminal.com/assets/og/compare-box-api-vs-tigris.png",
    "path": "/compare/box-api-vs-tigris",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Box API + MCP vs Tigris for AI agents, B 69.6 vs E 44.6",
    "toc": null,
    "updated": "2026-10-05",
    "url": "https://www.anchorterminal.com/compare/box-api-vs-tigris"
  },
  "tokens": {
    "markdown": 1450,
    "slim": 330
  },
  "version": 1
}
