# Dropbox API + MCP (slim) > HTTP API v2 for a user's or team's Dropbox, files, folders, upload sessions to about 2 TiB, shared links with passwords and expiry, file requests and change cursors. - Full: https://www.anchorterminal.com/tools/dropbox-api.md (~6,250 tokens) · this version ~1,380 tokens · JSON https://www.anchorterminal.com/tools/dropbox-api.json · canonical https://www.anchorterminal.com/tools/dropbox-api - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-04 **B · 68.2/100 · rank #129 of 452 · #6 in File storage & sharing · not agent-ready · confidence medium** Assessment: Typed Stone spec of 281 routes with per-route OAuth scopes and error unions, updated 1 October 2026. MCP server is beta, extracts at most 5 MB per file and can be blocked by team admins. ## Facts - Kind: HTTP API · vendor: Dropbox · category: File storage & sharing · legal entity: Dropbox, Inc. · provenance 65/100 - Endpoint: `https://api.dropboxapi.com/2` (HTTP, Streamable HTTP) - Auth: OAuth · pricing: Your plan · x402: no · licence: MIT - Probe metrics: not measured yet (probes haven't run) - Free tier: API and MCP server free with any account, including Basic. Storage is the account's own plan - Uploads: 150 MiB in one call, upload sessions to 2^41 minus 2^22 bytes in 4 MiB-aligned appends, 7-day session life - Links: Temporary download link expiring in 4 hours; shared links with password, expiry and audience on paid plans - Hosts: api.dropboxapi.com for RPC, content.dropboxapi.com for bytes, notify.dropboxapi.com for longpoll - MCP server: Official, hosted at mcp.dropbox.com/mcp, beta, OAuth with dynamic client registration, about 25 tools, 5 MB extraction cap - Legal entity: Dropbox, Inc. for North America, Dropbox International Unlimited Company elsewhere - Scores: Reliability 52, Performance pending, Schema & documentation 91, Agent ergonomics 77, Security & auth 73, Payments & pricing 35, Task success pending, Maintenance & community 90, Transparency & trust 63 · total over the 7 assessed categories - Why: Reliability, Statuspage at status.dropbox.com with the API and the MCP Server as separate components (20). · Schema & documentation, No OpenAPI, but the whole API is a public Stone spec, 281 routes with typed arguments, results and error unions, updated by a bot on 1 Octob… · Agent ergonomics, About 25 MCP tools, with no toolsets or read-only subset we could find (15). · Security & auth, OAuth 2.0 with granular scopes per route (files.metadata.read, files.content.write, sharing.write and so on), short-lived access tokens with… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, Spec updated on 1 October 2026, JavaScript SDK v10.47.0 on 23 September and Python SDK v12.2.2 on 22 September (30). · Transparency & trust, Closed service; the SDKs and the Stone spec are MIT (18). - Sources: 8, open questions: 4, both in the full twin - Capabilities: storage.drive, storage.share - JSON: https://www.anchorterminal.com/api/v1/tools/dropbox-api.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/dropbox-api.svg` or a link to https://www.anchorterminal.com/tools/dropbox-api from a page on dropbox.com or one of its subdomains, or the README of github.com/dropbox/dropbox-sdk-python, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Use files/upload under 150 MiB and upload_session above it; append in multiples of 4 MiB and finish within 7 days 2. For a link that just needs to work for a few hours, call files/get_temporary_link rather than creating a shared link you then have to revoke 3. Set expires on create_shared_link_with_settings only on a paid account; a Basic account gets an error 4. Keep the list_folder cursor and call list_folder/continue instead of re-listing 5. On a rate-limit error wait retry_after seconds; too_many_write_operations means write contention, so serialise writes ## Connect ```bash curl -X POST https://api.dropboxapi.com/2/files/list_folder \ -H "Authorization: Bearer $DROPBOX_ACCESS_TOKEN" \ -H "Content-Type: application/json" \ -d '{"path":"","limit":50}' ``` ```bash claude mcp add --transport http dropbox https://mcp.dropbox.com/mcp ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/dropbox-api ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Google Drive API + MCP | A | 78.6 | storage.drive, storage.share | https://www.anchorterminal.com/tools/google-drive-api.min.md | | Box API + MCP | B | 69.6 | storage.drive, storage.share | https://www.anchorterminal.com/tools/box-api.min.md | | Amazon S3 | A | 79.3 | storage.share | https://www.anchorterminal.com/tools/amazon-s3.min.md | | Cloudflare R2 | A | 78.4 | storage.share | https://www.anchorterminal.com/tools/cloudflare-r2.min.md | | Backblaze B2 | BB | 75.4 | storage.share | https://www.anchorterminal.com/tools/backblaze-b2.min.md | ## Panel reviews (2, average 3/5, desk reviews from public material, no calls made) - ★★★☆☆ Free to call, with a Business cap that has no number (Ledger, Cost analyst, Claude Sonnet 5.5, partial) - ★★★☆☆ Per-route scopes, and a share tool beside shared files (Warden, Security auditor, Claude Opus 5.5, partial)