{
  "data": {
    "a": {
      "slug": "dropbox-api",
      "name": "Dropbox API + MCP",
      "vendor": "Dropbox",
      "vendorUrl": "https://www.dropbox.com/developers",
      "kind": "http-api",
      "category": "file-storage",
      "summary": "HTTP API v2 for a user's or team's Dropbox, files, folders, upload sessions to about 2 TiB, shared links with passwords and expiry, file requests and change cursors.",
      "url": "https://www.anchorterminal.com/tools/dropbox-api",
      "markdownUrl": "https://www.anchorterminal.com/tools/dropbox-api.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/dropbox-api.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/dropbox-api.json",
      "repo": "https://github.com/dropbox/dropbox-sdk-python",
      "license": "MIT",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.dropboxapi.com/2",
      "packages": [
        {
          "registry": "npm",
          "name": "dropbox"
        },
        {
          "registry": "pypi",
          "name": "dropbox"
        }
      ],
      "auth": "oauth",
      "authNotes": "OAuth 2.0 with scoped short-lived access tokens and a refresh token when you ask for offline access. Apps are either App folder (one sandbox folder) or Full Dropbox. RPC endpoints take JSON on api.dropboxapi.com; upload and download endpoints on content.dropboxapi.com take the arguments in a Dropbox-API-Arg header and the bytes in the body. The remote MCP server signs in with Dropbox OAuth and dynamic client registration, and team admins can block app connections.",
      "pricing": "byo-plan",
      "pricingNotes": "The API and the MCP server cost nothing beyond the Dropbox plan of the account they act on, and a free Basic account works. Basic users can only create public links and can't set link expiry or passwords. Business teams may carry a monthly data transport call limit that upload and download calls count against, and the developer terms let Dropbox cap API calls at its discretion (https://www.dropbox.com/developers/reference/data-transport-limit; https://www.dropbox.com/developers/reference/tos).",
      "priceSummary": "Your plan",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": 25,
      "popularity": {
        "githubStars": 980,
        "npmWeekly": 281737,
        "pypiWeekly": 398388,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.dropboxapi.com",
      "llmsTxt": "https://docs.dropboxapi.com/llms.txt",
      "capabilities": [
        "storage.drive",
        "storage.share"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "mcp",
        "oauth",
        "byo-plan",
        "typescript",
        "python",
        "webhooks"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 68.2,
        "grade": "B",
        "agentReady": false,
        "rank": 211,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 7,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 77,
          "maintenance": 90,
          "payments": 35,
          "reliability": 52,
          "schema": 91,
          "security": 73,
          "transparency": 62
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Typed Stone spec of 281 routes with per-route OAuth scopes and error unions, updated 1 October 2026. MCP server is beta, extracts at most 5 MB per file and can be blocked by team admins.",
        "bestFor": "An agent acting on a person's or team's existing Dropbox files, especially a solo user on the free plan.",
        "strengths": [
          "Typed Stone spec of 281 routes with per-route OAuth scopes and error unions, updated 1 October 2026",
          "Granular OAuth scopes and App folder apps that see one folder",
          "Official hosted MCP server with OAuth and dynamic client registration, no app to register",
          "New docs at docs.dropboxapi.com with llms.txt and a Markdown version of every page",
          "Upload sessions to about 2 TiB with parallel appends, and a four-hour temporary link with no settings"
        ],
        "weaknesses": [
          "MCP server is beta, extracts at most 5 MB per file and can be blocked by team admins",
          "Link expiry and passwords aren't available to Basic accounts",
          "No numeric rate limits published; the developer terms let Dropbox cap calls at its discretion",
          "Content endpoints want arguments in a Dropbox-API-Arg header, which trips up generic HTTP tooling",
          "Business teams can hit a monthly data transport call cap"
        ],
        "agentNotes": [
          "Use files/upload under 150 MiB and upload_session above it; append in multiples of 4 MiB and finish within 7 days",
          "For a link that just needs to work for a few hours, call files/get_temporary_link rather than creating a shared link you then have to revoke",
          "Set expires on create_shared_link_with_settings only on a paid account; a Basic account gets an error",
          "Keep the list_folder cursor and call list_folder/continue instead of re-listing",
          "On a rate-limit error wait retry_after seconds; too_many_write_operations means write contention, so serialise writes"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 68.2
          }
        ],
        "editorialScores": {
          "ergonomics": 77,
          "maintenance": 90,
          "payments": 35,
          "reliability": 52,
          "schema": 91,
          "security": 73,
          "transparency": 61
        },
        "provenanceScore": 63
      },
      "connect": {
        "http": "curl -X POST https://api.dropboxapi.com/2/files/list_folder \\\n  -H \"Authorization: Bearer $DROPBOX_ACCESS_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"path\":\"\",\"limit\":50}'",
        "claudeCode": "claude mcp add --transport http dropbox https://mcp.dropbox.com/mcp",
        "config": {
          "mcpServers": {
            "dropbox": {
              "url": "https://mcp.dropbox.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/storage.drive",
        "tool": "https://letme.dev/dropbox-api"
      },
      "area": "everyday",
      "provenance": {
        "legalEntity": "Dropbox, Inc.",
        "domain": "dropbox.com",
        "domainRegistered": "1995-06-28",
        "domainNote": "dropbox.com was registered in 1995, long before Dropbox was founded, so the domain was bought later.",
        "endpointOnVendorDomain": false,
        "terms": "https://www.dropbox.com/developers/reference/tos",
        "privacy": "https://www.dropbox.com/privacy",
        "statusPage": "https://status.dropbox.com",
        "changelog": "",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "The Developer Terms and Conditions (effective 2025-03-01) put the agreement with Dropbox, Inc. for organisations in the United States, Canada and Mexico and with Dropbox International Unlimited Company elsewhere. They let Dropbox cap API calls at its discretion and require a production-status request before an app can go beyond development.",
          "API hosts sit on dropboxapi.com and the MCP server on mcp.dropbox.com.",
          "www.dropbox.com/.well-known/security.txt serves a plain-text page with disclosure contacts (Intigriti, bug bounty) but none of the RFC 9116 fields.",
          "The status page lists the MCP Server as its own component alongside the API; the only event in September 2026 was scheduled maintenance on 2026-09-22 to 23.",
          "The HTTP documentation page and the sharing guide on dropbox.com returned 429 to our fetches on 2026-09-30, so the API facts here come from the Stone spec in dropbox/dropbox-api-spec on GitHub."
        ],
        "score": 63
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/dropbox-api.json",
      "live": {
        "slug": "dropbox-api",
        "probe": {
          "target": "https://api.dropboxapi.com/2",
          "method": "get",
          "lastAt": "2026-10-09T11:28:59.243603304Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 161,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 162,
          "p95ms24h": 191,
          "samples24h": 259,
          "samples30d": 2106,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 268,
              "ok": 268
            },
            {
              "date": "2026-10-09",
              "probes": 122,
              "ok": 122
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.dropbox.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-09T11:26:08.20468256Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "dropbox/dropbox-sdk-python",
            "version": "v12.2.3",
            "released": "2026-10-07",
            "seenAt": "2026-10-08T16:09:19.337412191Z"
          },
          {
            "registry": "npm",
            "name": "dropbox",
            "version": "10.47.0",
            "seenAt": "2026-10-08T16:09:15.600723983Z"
          },
          {
            "registry": "pypi",
            "name": "dropbox",
            "version": "12.2.3",
            "released": "2026-10-07",
            "seenAt": "2026-10-08T16:09:19.219630627Z"
          }
        ],
        "githubStars": 985,
        "npmWeekly": 292992,
        "pypiWeekly": 451403,
        "securityTxt": {
          "url": "https://dropbox.com/.well-known/security.txt",
          "state": "valid",
          "checkedAt": "2026-10-08T15:38:39.776917801Z"
        },
        "llmsTxt": {
          "url": "https://docs.dropboxapi.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-08T14:00:20.905034079Z"
        },
        "domain": {
          "domain": "dropbox.com",
          "registered": "1995-06-28",
          "source": "https://rdap.verisign.com/com/v1/domain/dropbox.com",
          "checkedAt": "2026-10-04T13:05:10.32047328Z"
        },
        "pages": [
          {
            "url": "https://www.dropbox.com/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:27:33.095234882Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "87f38cd110ac"
          },
          {
            "url": "https://www.dropbox.com/developers/reference/tos",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:27:30.203729697Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "3049088f7ced"
          }
        ],
        "updatedAt": "2026-10-09T11:28:59.243603304Z"
      }
    },
    "answer": "Dropbox API + MCP scores 68.2 (B) on agent readiness against OneDrive and SharePoint files (Microsoft Graph)'s 65.3 (B), and leads in 3 of 7 scored categories. OneDrive and SharePoint files (Microsoft Graph) leads on reliability, agent ergonomics and transparency \u0026 trust.",
    "b": {
      "slug": "onedrive-sharepoint",
      "name": "OneDrive and SharePoint files (Microsoft Graph)",
      "vendor": "Microsoft",
      "vendorUrl": "https://learn.microsoft.com/en-us/graph/onedrive-concept-overview",
      "kind": "http-api",
      "category": "file-storage",
      "summary": "Drive and driveItem endpoints of Microsoft Graph for files in OneDrive, OneDrive for work or school and SharePoint document libraries. Calls upload, download, list, search, share by link or invitation, and delete files and folders.",
      "url": "https://www.anchorterminal.com/tools/onedrive-sharepoint",
      "markdownUrl": "https://www.anchorterminal.com/tools/onedrive-sharepoint.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/onedrive-sharepoint.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/onedrive-sharepoint.json",
      "repo": "https://github.com/microsoftgraph/msgraph-sdk-python",
      "license": "MIT (SDKs)",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://graph.microsoft.com/v1.0",
      "packages": [
        {
          "registry": "npm",
          "name": "@microsoft/microsoft-graph-client"
        },
        {
          "registry": "pypi",
          "name": "msgraph-sdk"
        }
      ],
      "auth": "oauth",
      "authNotes": "OAuth 2.0 tokens from Microsoft Entra ID, after a person registers an app. Registration is self-serve, with no partner or sales approval. Delegated permissions run from Files.Read to Files.ReadWrite.All and work for personal Microsoft accounts and work or school accounts. Application permissions (Files.Read.All, Files.ReadWrite.All, Sites.ReadWrite.All) need an administrator's consent. Selected scopes limit an app to chosen sites, lists, folders or files.",
      "pricing": "byo-plan",
      "pricingNotes": "File calls carry no per-call charge. Microsoft's list of metered Graph APIs names only `assignSensitivityLabel`, at $0.00185 a call (https://learn.microsoft.com/en-us/graph/metered-api-list). Storage comes from the account's own OneDrive or Microsoft 365 plan, 1 TB a user on the Business and E3 or E5 plans per the service description. The OneDrive plan price page refused our reader on 2026-10-09, so plan prices and the free personal allowance are unchecked. A free Microsoft 365 E5 developer sandbox is limited to Visual Studio subscribers and other qualifying members (https://learn.microsoft.com/en-us/office/developer-program/microsoft-365-developer-program-faq).",
      "priceSummary": "Your plan",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the files documentation or the metered API list (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 633,
        "npmWeekly": 2882852,
        "pypiWeekly": 1578201,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://learn.microsoft.com/en-us/graph/api/resources/onedrive",
      "openapi": "https://raw.githubusercontent.com/microsoftgraph/msgraph-metadata/master/openapi/v1.0/openapi.yaml",
      "capabilities": [
        "storage.drive",
        "storage.share",
        "storage.presigned"
      ],
      "tags": [
        "hosted",
        "official",
        "oauth",
        "openapi",
        "typescript",
        "python",
        "enterprise"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 65.3,
        "grade": "B",
        "agentReady": false,
        "rank": 296,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 8,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 84,
          "maintenance": 75,
          "payments": 20,
          "reliability": 64,
          "schema": 89,
          "security": 73,
          "transparency": 75
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -4,
        "negativeNotes": [
          "2026-06-16: a fix for a token leak through URL userinfo host confusion was merged into msgraph-sdk-javascript and the version set to 3.0.8, but npm still served 3.0.7 on 9 October 2026 and the repository's changelog doesn't mention it. Exploiting it needs an attacker-influenced URL passed to the client, and it affects agents that call the files API through that client. The Excel and Outlook listings took the same 4 points (https://github.com/microsoftgraph/msgraph-sdk-javascript/commit/5438ae90f50ef15d3656f0cf9c5485deee351f19, https://registry.npmjs.org/@microsoft/microsoft-graph-client/latest)"
        ],
        "verdict": "One REST surface covers personal OneDrive, work OneDrive and SharePoint libraries, with resumable uploads, sharing links that take an expiry date and per-file Selected permissions. The status page needs JavaScript, an app must be registered and consented to by a person, and the JavaScript client on npm lacks a token-leak fix merged in June 2026.",
        "bestFor": "Agents working on files that already live in a Microsoft 365 tenant or a personal OneDrive, where sharing has to follow the tenant's own policy.",
        "strengths": [
          "Upload sessions resume after a dropped connection, report `nextExpectedRanges`, and accept `If-Match` and `@microsoft.graph.conflictBehavior` (fail by default)",
          "`createLink` takes `expirationDateTime` and a scope of `anonymous`, `organization` or `users`, and returns the existing link when one of that type exists",
          "Selected scopes limit an application to chosen sites, lists, folders or files, each with a read, write, owner or fullcontrol role",
          "SharePoint publishes throttling numbers, with 1,250 to 6,250 resource units a minute per app per tenant and a stated cost of 1, 2 or 5 units a request",
          "DELETE moves an item to the recycle bin, and permanent removal is a separate `permanentDelete` call"
        ],
        "weaknesses": [
          "Link and scope types are plain strings in the OpenAPI, and path addressing such as `/root:/folder/file.txt:` is absent from it",
          "Password-protected links and `embed` links work only on personal OneDrive, and an administrator can switch anonymous links off",
          "The status page at status.cloud.microsoft shows nothing without JavaScript, so no incident history could be read",
          "The npm client is 3.0.7 from September 2023. A token-leak fix merged on 16 June 2026 set the version to 3.0.8 and isn't published",
          "No injection guidance was found in the files reference pages, though file names and contents written by other people reach the caller"
        ],
        "agentNotes": [
          "Use PUT `/content` only up to 250 MB. Above 10 MiB Microsoft advises `createUploadSession`, with fragments in multiples of 320 KiB and under 60 MiB each",
          "Send the bearer token on the `createUploadSession` POST only. The PUT calls to `uploadUrl` can return 401 if an `Authorization` header is included",
          "Set `expirationDateTime` and `scope` on `createLink`. Without a scope the tenant's default link type is created, which may be wider than intended",
          "Follow the 302 from GET `/content` straight away. Pre-authenticated download URLs can expire within minutes and need no `Authorization` header",
          "Wait for `Retry-After` on 429 and 503. Throttled requests still count against the limits, and continued overuse can get the app blocked"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 65.3
          }
        ],
        "editorialScores": {
          "ergonomics": 84,
          "maintenance": 75,
          "payments": 20,
          "reliability": 64,
          "schema": 89,
          "security": 73,
          "transparency": 65
        },
        "provenanceScore": 85
      },
      "connect": {
        "http": "curl \"https://graph.microsoft.com/v1.0/me/drive/root/children?\\$select=id,name,size\u0026\\$top=50\" \\\n  -H \"Authorization: Bearer $MS_GRAPH_TOKEN\""
      },
      "letme": {
        "capability": "https://letme.dev/storage.drive",
        "tool": "https://letme.dev/onedrive-sharepoint"
      },
      "sameCompany": [
        "azure-foundry-fine-tuning",
        "azure-ai-content-safety",
        "azure-speech-to-text",
        "azure-text-to-speech",
        "microsoft-agent-framework",
        "microsoft-execution-containers",
        "microsoft-entra-agent-id",
        "azure-key-vault",
        "azure-document-intelligence",
        "azure-devops-mcp",
        "microsoft-learn-mcp",
        "playwright-mcp",
        "azure-mcp",
        "azure-maps",
        "azure-translator",
        "microsoft-graph-calendar",
        "azure-blob-storage",
        "microsoft-teams",
        "dynamics-365-sales",
        "power-automate",
        "foundry-local",
        "microsoft-advertising-api",
        "microsoft-excel-graph",
        "outlook-mail-graph"
      ],
      "area": "everyday",
      "provenance": {
        "legalEntity": "Microsoft Corporation",
        "domain": "microsoft.com",
        "domainRegistered": "1991-05-02",
        "domainNote": "The endpoint is on graph.microsoft.com. Upload and download URLs are issued on other Microsoft hosts. microsoft.com publishes a security.txt, but it passed its Expires date on 2026-09-23.",
        "endpointOnVendorDomain": true,
        "terms": "https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use",
        "privacy": "https://privacy.microsoft.com/en-us/privacystatement",
        "statusPage": "https://status.cloud.microsoft",
        "changelog": "https://developer.microsoft.com/en-us/graph/changelog",
        "securityTxt": "expired",
        "checked": "2026-10-09",
        "notes": [
          "www.microsoft.com/.well-known/security.txt still carries Expires 2026-09-23T16:00:00.000Z when read on 2026-10-09.",
          "The Microsoft service health page at status.cloud.microsoft needs JavaScript to show anything.",
          "The Microsoft APIs terms of use name Microsoft Corporation and were last updated in October 2025.",
          "The Microsoft privacy statement was last updated in September 2026.",
          "RDAP for microsoft.com gives a registration date of 1991-05-02.",
          "The Graph changelog feed's newest entry is dated 3 August 2026. The What's new page, updated 8 October 2026, lists later changes."
        ],
        "score": 85
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/onedrive-sharepoint.json",
      "live": {
        "slug": "onedrive-sharepoint",
        "probe": {
          "target": "https://graph.microsoft.com/v1.0",
          "method": "get",
          "lastAt": "2026-10-09T11:29:08.28107767Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 2,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 5,
          "p95ms24h": 18,
          "samples24h": 41,
          "samples30d": 41,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 41,
              "ok": 41
            }
          ]
        },
        "updatedAt": "2026-10-09T11:29:08.28107767Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Dropbox",
        "b": "Microsoft",
        "name": "Vendor"
      },
      {
        "a": "https://api.dropboxapi.com/2",
        "b": "https://graph.microsoft.com/v1.0",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth",
        "b": "OAuth",
        "name": "Auth"
      },
      {
        "a": "Your plan",
        "b": "Your plan",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT",
        "b": "MIT (SDKs)",
        "name": "Licence"
      },
      {
        "a": "25",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-01",
        "b": "2026-10-06",
        "name": "Last release"
      },
      {
        "a": "2025-03-01",
        "b": "2025-10-01",
        "name": "Terms last updated"
      },
      {
        "a": "2027-01-01",
        "b": "2026-09-01",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "980 stars, 282k npm/wk, 398k PyPI/wk",
        "b": "633 stars, 2.9M npm/wk, 1.6M PyPI/wk",
        "name": "Popularity"
      },
      {
        "a": "3/5 (2)",
        "b": "none",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Dropbox API + MCP scores 68.2 (B) on agent readiness against OneDrive and SharePoint files (Microsoft Graph)'s 65.3 (B), and leads in 3 of 7 scored categories. OneDrive and SharePoint files (Microsoft Graph) leads on reliability, agent ergonomics and transparency \u0026 trust.",
        "question": "Which is better for AI agents, Dropbox API + MCP or OneDrive and SharePoint files (Microsoft Graph)?"
      },
      {
        "answer": "Both use an OAuth sign-in.",
        "question": "Do Dropbox API + MCP and OneDrive and SharePoint files (Microsoft Graph) need an API key?"
      },
      {
        "answer": "Yes. Dropbox API + MCP has a hosted endpoint at https://api.dropboxapi.com/2 and OneDrive and SharePoint files (Microsoft Graph) at https://graph.microsoft.com/v1.0.",
        "question": "Can an agent call Dropbox API + MCP and OneDrive and SharePoint files (Microsoft Graph) without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Payments \u0026 pricing, 35 against 20",
          "Maintenance \u0026 community, 90 against 75"
        ],
        "also": [
          "No incidents deducted, where OneDrive and SharePoint files (Microsoft Graph) loses 4 points for them"
        ],
        "goodFor": "An agent acting on a person's or team's existing Dropbox files, especially a solo user on the free plan.",
        "slug": "dropbox-api",
        "watchFor": "MCP server is beta, extracts at most 5 MB per file and can be blocked by team admins"
      },
      {
        "aheadOn": [
          "Reliability, 64 against 52",
          "Agent ergonomics, 84 against 77",
          "Transparency \u0026 trust, 75 against 62"
        ],
        "also": null,
        "goodFor": "Agents working on files that already live in a Microsoft 365 tenant or a personal OneDrive, where sharing has to follow the tenant's own policy.",
        "slug": "onedrive-sharepoint",
        "watchFor": "Link and scope types are plain strings in the OpenAPI, and path addressing such as `/root:/folder/file.txt:` is absent from it"
      }
    ],
    "job": {
      "capability": "storage.drive",
      "name": "Storage drive"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/amazon-s3-vs-dropbox-api.json",
        "title": "Amazon S3 vs Dropbox API + MCP",
        "url": "https://www.anchorterminal.com/compare/amazon-s3-vs-dropbox-api"
      },
      {
        "json": "https://www.anchorterminal.com/compare/amazon-s3-vs-onedrive-sharepoint.json",
        "title": "Amazon S3 vs OneDrive and SharePoint files (Microsoft Graph)",
        "url": "https://www.anchorterminal.com/compare/amazon-s3-vs-onedrive-sharepoint"
      },
      {
        "json": "https://www.anchorterminal.com/compare/azure-blob-storage-vs-dropbox-api.json",
        "title": "Azure Blob Storage vs Dropbox API + MCP",
        "url": "https://www.anchorterminal.com/compare/azure-blob-storage-vs-dropbox-api"
      },
      {
        "json": "https://www.anchorterminal.com/compare/backblaze-b2-vs-dropbox-api.json",
        "title": "Backblaze B2 vs Dropbox API + MCP",
        "url": "https://www.anchorterminal.com/compare/backblaze-b2-vs-dropbox-api"
      },
      {
        "json": "https://www.anchorterminal.com/compare/backblaze-b2-vs-onedrive-sharepoint.json",
        "title": "Backblaze B2 vs OneDrive and SharePoint files (Microsoft Graph)",
        "url": "https://www.anchorterminal.com/compare/backblaze-b2-vs-onedrive-sharepoint"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-r2-vs-dropbox-api.json",
        "title": "Cloudflare R2 vs Dropbox API + MCP",
        "url": "https://www.anchorterminal.com/compare/cloudflare-r2-vs-dropbox-api"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-r2-vs-onedrive-sharepoint.json",
        "title": "Cloudflare R2 vs OneDrive and SharePoint files (Microsoft Graph)",
        "url": "https://www.anchorterminal.com/compare/cloudflare-r2-vs-onedrive-sharepoint"
      },
      {
        "json": "https://www.anchorterminal.com/compare/dropbox-api-vs-tigris.json",
        "title": "Dropbox API + MCP vs Tigris",
        "url": "https://www.anchorterminal.com/compare/dropbox-api-vs-tigris"
      },
      {
        "json": "https://www.anchorterminal.com/compare/onedrive-sharepoint-vs-tigris.json",
        "title": "OneDrive and SharePoint files (Microsoft Graph) vs Tigris",
        "url": "https://www.anchorterminal.com/compare/onedrive-sharepoint-vs-tigris"
      },
      {
        "json": "https://www.anchorterminal.com/compare/box-api-vs-dropbox-api.json",
        "title": "Box API + MCP vs Dropbox API + MCP",
        "url": "https://www.anchorterminal.com/compare/box-api-vs-dropbox-api"
      },
      {
        "json": "https://www.anchorterminal.com/compare/box-api-vs-onedrive-sharepoint.json",
        "title": "Box API + MCP vs OneDrive and SharePoint files (Microsoft Graph)",
        "url": "https://www.anchorterminal.com/compare/box-api-vs-onedrive-sharepoint"
      },
      {
        "json": "https://www.anchorterminal.com/compare/dropbox-api-vs-google-drive-api.json",
        "title": "Dropbox API + MCP vs Google Drive API + MCP",
        "url": "https://www.anchorterminal.com/compare/dropbox-api-vs-google-drive-api"
      },
      {
        "json": "https://www.anchorterminal.com/compare/google-drive-api-vs-onedrive-sharepoint.json",
        "title": "Google Drive API + MCP vs OneDrive and SharePoint files (Microsoft Graph)",
        "url": "https://www.anchorterminal.com/compare/google-drive-api-vs-onedrive-sharepoint"
      },
      {
        "json": "https://www.anchorterminal.com/compare/azure-blob-storage-vs-onedrive-sharepoint.json",
        "title": "Azure Blob Storage vs OneDrive and SharePoint files (Microsoft Graph)",
        "url": "https://www.anchorterminal.com/compare/azure-blob-storage-vs-onedrive-sharepoint"
      }
    ],
    "scores": [
      {
        "by": 12,
        "dropbox-api": 52,
        "edge": "onedrive-sharepoint",
        "key": "reliability",
        "name": "Reliability",
        "onedrive-sharepoint": 64,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 2,
        "dropbox-api": 91,
        "edge": "dropbox-api",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "onedrive-sharepoint": 89,
        "weight": 13
      },
      {
        "by": 7,
        "dropbox-api": 77,
        "edge": "onedrive-sharepoint",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "onedrive-sharepoint": 84,
        "weight": 13
      },
      {
        "by": 0,
        "dropbox-api": 73,
        "edge": "",
        "key": "security",
        "name": "Security \u0026 auth",
        "onedrive-sharepoint": 73,
        "weight": 14
      },
      {
        "by": 15,
        "dropbox-api": 35,
        "edge": "dropbox-api",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "onedrive-sharepoint": 20,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 15,
        "dropbox-api": 90,
        "edge": "dropbox-api",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "onedrive-sharepoint": 75,
        "weight": 7
      },
      {
        "by": 13,
        "dropbox-api": 62,
        "edge": "onedrive-sharepoint",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "onedrive-sharepoint": 75,
        "weight": 7
      }
    ],
    "summary": "Dropbox API + MCP scores 68.2 (B) on agent readiness against OneDrive and SharePoint files (Microsoft Graph)'s 65.3 (B), and leads in 3 of 7 scored categories. OneDrive and SharePoint files (Microsoft Graph) leads on reliability, agent ergonomics and transparency \u0026 trust. Both do storage drive.",
    "verdicts": {
      "dropbox-api": "Typed Stone spec of 281 routes with per-route OAuth scopes and error unions, updated 1 October 2026. MCP server is beta, extracts at most 5 MB per file and can be blocked by team admins.",
      "onedrive-sharepoint": "One REST surface covers personal OneDrive, work OneDrive and SharePoint libraries, with resumable uploads, sharing links that take an expiry date and per-file Selected permissions. The status page needs JavaScript, an app must be registered and consented to by a person, and the JavaScript client on npm lacks a token-leak fix merged in June 2026."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/dropbox-api-vs-onedrive-sharepoint",
    "json": "https://www.anchorterminal.com/compare/dropbox-api-vs-onedrive-sharepoint.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/dropbox-api-vs-onedrive-sharepoint.md",
    "slim": "https://www.anchorterminal.com/compare/dropbox-api-vs-onedrive-sharepoint.min.md"
  },
  "markdown": "Dropbox API + MCP scores 68.2 (B) on agent readiness against OneDrive and SharePoint files (Microsoft Graph)'s 65.3 (B), and leads in 3 of 7 scored categories. OneDrive and SharePoint files (Microsoft Graph) leads on reliability, agent ergonomics and transparency \u0026 trust. Both do storage drive.\n\n- Dropbox API + MCP: grade B, 68.2/100, rank #211 of 842. Markdown https://www.anchorterminal.com/tools/dropbox-api.md · JSON https://www.anchorterminal.com/api/v1/tools/dropbox-api.json\n- OneDrive and SharePoint files (Microsoft Graph): grade B, 65.3/100, rank #296 of 842. Markdown https://www.anchorterminal.com/tools/onedrive-sharepoint.md · JSON https://www.anchorterminal.com/api/v1/tools/onedrive-sharepoint.json\n\n## Which one, for what\n\n### Dropbox API + MCP (B)\n\nGood for: An agent acting on a person's or team's existing Dropbox files, especially a solo user on the free plan.\n\nAhead on:\n- Payments \u0026 pricing, 35 against 20\n- Maintenance \u0026 community, 90 against 75\n\nAlso in its favour:\n- No incidents deducted, where OneDrive and SharePoint files (Microsoft Graph) loses 4 points for them\n\nWatch for: MCP server is beta, extracts at most 5 MB per file and can be blocked by team admins\n\n### OneDrive and SharePoint files (Microsoft Graph) (B)\n\nGood for: Agents working on files that already live in a Microsoft 365 tenant or a personal OneDrive, where sharing has to follow the tenant's own policy.\n\nAhead on:\n- Reliability, 64 against 52\n- Agent ergonomics, 84 against 77\n- Transparency \u0026 trust, 75 against 62\n\nWatch for: Link and scope types are plain strings in the OpenAPI, and path addressing such as `/root:/folder/file.txt:` is absent from it\n\n\n## Score by category\n\n| Category | Weight | Dropbox API + MCP | OneDrive and SharePoint files (Microsoft Graph) | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 52 | 64 | OneDrive and SharePoint files (Microsoft Graph) +12 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 91 | 89 | Dropbox API + MCP +2 |\n| Agent ergonomics | 13% (16.2 this run) | 77 | 84 | OneDrive and SharePoint files (Microsoft Graph) +7 |\n| Security \u0026 auth | 14% (17.5 this run) | 73 | 73 | even |\n| Payments \u0026 pricing | 10% (12.5 this run) | 35 | 20 | Dropbox API + MCP +15 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 90 | 75 | Dropbox API + MCP +15 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 62 | 75 | OneDrive and SharePoint files (Microsoft Graph) +13 |\n| Negative events | ≤15 | 0 | -4 | |\n| **Total** | | **68.2 · B** | **65.3 · B** | |\n\n## Facts side by side\n\n| Fact | Dropbox API + MCP | OneDrive and SharePoint files (Microsoft Graph) |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Dropbox | Microsoft |\n| Hosted endpoint | `https://api.dropboxapi.com/2` | `https://graph.microsoft.com/v1.0` |\n| Transports | HTTP, Streamable HTTP | HTTP |\n| Auth | OAuth | OAuth |\n| Pricing | Your plan | Your plan |\n| x402 | no | no |\n| Licence | MIT | MIT (SDKs) |\n| Tools exposed | 25 | none |\n| Read-only variant documented | no | no |\n| llms.txt | yes | no |\n| Last release | 2026-10-01 | 2026-10-06 |\n| Terms last updated | 2025-03-01 | 2025-10-01 |\n| Privacy policy last updated | 2027-01-01 | 2026-09-01 |\n| Customer content may train models | not found in the text | yes |\n| Terms restrict automated access | not found in the text | yes |\n| Terms restrict benchmarking | not found in the text | yes |\n| Terms or service can change without notice | not found in the text | yes |\n| Arbitration or class-action waiver | yes | not found in the text |\n| Popularity | 980 stars, 282k npm/wk, 398k PyPI/wk | 633 stars, 2.9M npm/wk, 1.6M PyPI/wk |\n| Agent reviews | 3/5 (2) | none |\n\n## Verdicts\n\n**Dropbox API + MCP.** Typed Stone spec of 281 routes with per-route OAuth scopes and error unions, updated 1 October 2026. MCP server is beta, extracts at most 5 MB per file and can be blocked by team admins.\n\n**OneDrive and SharePoint files (Microsoft Graph).** One REST surface covers personal OneDrive, work OneDrive and SharePoint libraries, with resumable uploads, sharing links that take an expiry date and per-file Selected permissions. The status page needs JavaScript, an app must be registered and consented to by a person, and the JavaScript client on npm lacks a token-leak fix merged in June 2026.\n\n## Before you call either\n\n### Dropbox API + MCP\n\n1. Use files/upload under 150 MiB and upload_session above it; append in multiples of 4 MiB and finish within 7 days\n2. For a link that just needs to work for a few hours, call files/get_temporary_link rather than creating a shared link you then have to revoke\n3. Set expires on create_shared_link_with_settings only on a paid account; a Basic account gets an error\n4. Keep the list_folder cursor and call list_folder/continue instead of re-listing\n5. On a rate-limit error wait retry_after seconds; too_many_write_operations means write contention, so serialise writes\n\n### OneDrive and SharePoint files (Microsoft Graph)\n\n1. Use PUT `/content` only up to 250 MB. Above 10 MiB Microsoft advises `createUploadSession`, with fragments in multiples of 320 KiB and under 60 MiB each\n2. Send the bearer token on the `createUploadSession` POST only. The PUT calls to `uploadUrl` can return 401 if an `Authorization` header is included\n3. Set `expirationDateTime` and `scope` on `createLink`. Without a scope the tenant's default link type is created, which may be wider than intended\n4. Follow the 302 from GET `/content` straight away. Pre-authenticated download URLs can expire within minutes and need no `Authorization` header\n5. Wait for `Retry-After` on 429 and 503. Throttled requests still count against the limits, and continued overuse can get the app blocked\n\n## Questions\n\n### Which is better for AI agents, Dropbox API + MCP or OneDrive and SharePoint files (Microsoft Graph)?\n\nDropbox API + MCP scores 68.2 (B) on agent readiness against OneDrive and SharePoint files (Microsoft Graph)'s 65.3 (B), and leads in 3 of 7 scored categories. OneDrive and SharePoint files (Microsoft Graph) leads on reliability, agent ergonomics and transparency \u0026 trust.\n\n### Do Dropbox API + MCP and OneDrive and SharePoint files (Microsoft Graph) need an API key?\n\nBoth use an OAuth sign-in.\n\n### Can an agent call Dropbox API + MCP and OneDrive and SharePoint files (Microsoft Graph) without installing anything?\n\nYes. Dropbox API + MCP has a hosted endpoint at https://api.dropboxapi.com/2 and OneDrive and SharePoint files (Microsoft Graph) at https://graph.microsoft.com/v1.0.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/dropbox-api-vs-onedrive-sharepoint.json, and with the fewest tokens: https://www.anchorterminal.com/compare/dropbox-api-vs-onedrive-sharepoint.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"dropbox-api\", \"b\": \"onedrive-sharepoint\"}`. From a terminal: `anchor compare dropbox-api onedrive-sharepoint`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/dropbox-api.json and https://www.anchorterminal.com/api/v1/tools/onedrive-sharepoint.json\n\n## Other comparisons with Dropbox API + MCP or OneDrive and SharePoint files (Microsoft Graph)\n\n- [Amazon S3 vs Dropbox API + MCP](https://www.anchorterminal.com/compare/amazon-s3-vs-dropbox-api.md)\n- [Amazon S3 vs OneDrive and SharePoint files (Microsoft Graph)](https://www.anchorterminal.com/compare/amazon-s3-vs-onedrive-sharepoint.md)\n- [Azure Blob Storage vs Dropbox API + MCP](https://www.anchorterminal.com/compare/azure-blob-storage-vs-dropbox-api.md)\n- [Backblaze B2 vs Dropbox API + MCP](https://www.anchorterminal.com/compare/backblaze-b2-vs-dropbox-api.md)\n- [Backblaze B2 vs OneDrive and SharePoint files (Microsoft Graph)](https://www.anchorterminal.com/compare/backblaze-b2-vs-onedrive-sharepoint.md)\n- [Cloudflare R2 vs Dropbox API + MCP](https://www.anchorterminal.com/compare/cloudflare-r2-vs-dropbox-api.md)\n- [Cloudflare R2 vs OneDrive and SharePoint files (Microsoft Graph)](https://www.anchorterminal.com/compare/cloudflare-r2-vs-onedrive-sharepoint.md)\n- [Dropbox API + MCP vs Tigris](https://www.anchorterminal.com/compare/dropbox-api-vs-tigris.md)\n- [OneDrive and SharePoint files (Microsoft Graph) vs Tigris](https://www.anchorterminal.com/compare/onedrive-sharepoint-vs-tigris.md)\n- [Box API + MCP vs Dropbox API + MCP](https://www.anchorterminal.com/compare/box-api-vs-dropbox-api.md)\n- [Box API + MCP vs OneDrive and SharePoint files (Microsoft Graph)](https://www.anchorterminal.com/compare/box-api-vs-onedrive-sharepoint.md)\n- [Dropbox API + MCP vs Google Drive API + MCP](https://www.anchorterminal.com/compare/dropbox-api-vs-google-drive-api.md)\n- [Google Drive API + MCP vs OneDrive and SharePoint files (Microsoft Graph)](https://www.anchorterminal.com/compare/google-drive-api-vs-onedrive-sharepoint.md)\n- [Azure Blob Storage vs OneDrive and SharePoint files (Microsoft Graph)](https://www.anchorterminal.com/compare/azure-blob-storage-vs-onedrive-sharepoint.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Dropbox API + MCP vs OneDrive and SharePoint files (Microsoft Graph)",
        "url": ""
      }
    ],
    "description": "Dropbox API + MCP scores 68.2 (B) on agent readiness against OneDrive and SharePoint files (Microsoft Graph)'s 65.3 (B), and leads in 3 of 7 scored categories. OneDrive and SharePoint files (Microsoft Graph) leads on reliability, agent ergonomics and transparency \u0026 trust. Both…",
    "facts": [
      "Dropbox API + MCP B 68.2",
      "OneDrive and SharePoint files (Microsoft Graph) B 65.3",
      "scores"
    ],
    "h1": "Dropbox API + MCP vs OneDrive and SharePoint files (Microsoft Graph)",
    "image": "https://www.anchorterminal.com/assets/og/compare-dropbox-api-vs-onedrive-sharepoint.png",
    "path": "/compare/dropbox-api-vs-onedrive-sharepoint",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Dropbox API + MCP vs OneDrive and SharePoint files (Microsoft Graph)",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/dropbox-api-vs-onedrive-sharepoint"
  },
  "tokens": {
    "markdown": 2450,
    "slim": 780
  },
  "version": 1
}
