Skip to main content
Question

Service account unable to accept Terms of Service

  • September 30, 2026
  • 0 replies
  • 20 views

I have a free developer account which has an App created in it which I use to access files for some of my clients. I access the clients files by having them share access with the service account within the app, generate a token for the service account using the https://api.box.com/oauth2/token endpoint, and can then hit several endpoints to interact with their files/folders, such as https://api.box.com/2.0/folders/:folderId/items. This generally works well and have not ran into any issues.

 

A new client has custom Terms of Service set up for their enterprise. They have shared access with my service account, however when I send this request (https://api.box.com/2.0/folders/:folderId/items) using their folder id, I get a 404 saying folder not found (request id 66e17dihmcfldadh, for an example of that request).

 

Upon further investigation I found this endpoint: https://api.box.com/2.0/collaborations?status=pending&fields=status,acceptance_requirements_status which returns one pending collaboration for the folder I am trying to access, and it specifies I have not accepted the terms of service yet, response with redacted ids below:
{
  "total_count": 1,
  "entries": [
    {
      "type": "collaboration",
      "id": "REDACTED_COLLAB_ID",
      "status": "pending",
      "acceptance_requirements_status": {
        "terms_of_service_requirement": {
          "terms_of_service": {
            "type": "terms_of_service",
            "id": "REDACTED_TOS_ID"
          },
          "is_accepted": false
        },
        "strong_password_requirement": {
          "enterprise_has_strong_password_required_for_external_users": true,
          "user_has_strong_password": true
        },
        "two_factor_authentication_requirement": {
          "enterprise_has_two_factor_auth_enabled": true,
          "user_has_two_factor_authentication_enabled": true
        }
      }
    }
  ],
  "limit": 100,
  "offset": 0
}

 

I am able to view the terms of service by using the REDACTED_TOS_ID from the previous response on this endpoint: `https://api.box.com/2.0/terms_of_services/REDACTED_TOS_ID`. I then tried sending a POST request to this endpoint https://api.box.com/2.0/terms_of_service_user_statuses with the following body:
{
       "tos": {
         "type": "terms_of_service",
         "id": "REDACTED_TOS_ID"
       },
       "user": {
         "type": "user",
         "id": "REDACTED_SERVICE_ACCOUNT_USER_ID"
       },
       "is_accepted": true
     }

 

Which gives me a 404 with the following response:
{"type":"error","status":404,"code":"not_found","context_info":{"errors":[{"reason":"invalid_parameter","name":"user","message":"Invalid value 'REDACTED_SERVICE_ACCOUNT_USER_ID'. 'user' with value 'REDACTED_SERVICE_ACCOUNT_USER_ID' not found"}]},"help_url":"http:\/\/developers.box.com\/docs\/#errors","message":"Not Found","request_id":"3vuw1wihmd71gtjs"}. I also tried the PUT version of this endpoint and got the same results.

 

My question is, if I am trying to interact with an enterprise which uses custom terms of service, how can I accept the ToS for a free service account and be able to view their folders/files? Do I have to pay for an enterprise account in order to accept an enterprises ToS or is there a way around this?