Skip to main content
Question

Account with viewer uploader permission was able to delete files using API

  • December 2, 2025
  • 1 reply
  • 56 views

Forum|alt.badge.img

Our application was impersonating an account that had viewer uploader permissions on a folder in Box and was able to delete a file thru the API (not Web UI).
My understanding was a viewer uploader did not have delete permissions.  Is that in the Web UI only?

1 reply

Forum|alt.badge.img
  • Author
  • New Participant
  • January 12, 2026

Update to this issue.  It might be user error. The account above was a co-admin. 

If a user is co-admin, does that super cede any folder level permissions that were set on that account.  If a co-admin is assigned ‘viewer uploader’, that permission is ignored because they are a co-admin?