A community space to collaborate on Box APIs, explore SDKs, and build powerful applications
Recently active
I am trying to test the Box API endpoint /2.0/notes/convert in Postman, which is used to convert Markdown content into a native .boxnote file in a target Box folder.However, I am not receiving the expected output when making the API request. I would like assistance in understanding the correct request format, required parameters, headers, and any specific requirements for successfully creating a .boxnote file from Markdown content.API Endpoint:https://api.box.com/2.0/notes/convertEnvironment: PostmanExpected Result:The Markdown content should be converted into a native Box Note (.boxnote) and created in the specified target folder.Actual Result:The API request giving the below error (Screenshot attached)Please provide guidance on the correct API request and any required configuration or permissions needed for this operation.Are this APIs only available for higher tier subscriptions? If yes the description in the “Plan comparison” is misleading because it does not state which APIs are a
I have a free developer account which has an App created in it which I use to access files for some of my clients. I access the clients files by having them share access with the service account within the app, generate a token for the service account using the https://api.box.com/oauth2/token endpoint, and can then hit several endpoints to interact with their files/folders, such as https://api.box.com/2.0/folders/:folderId/items. This generally works well and have not ran into any issues. A new client has custom Terms of Service set up for their enterprise. They have shared access with my service account, however when I send this request (https://api.box.com/2.0/folders/:folderId/items) using their folder id, I get a 404 saying folder not found (request id 66e17dihmcfldadh, for an example of that request). Upon further investigation I found this endpoint: https://api.box.com/2.0/collaborations?status=pending&fields=status,acceptance_requirements_status which returns one pending co
My BoxAccessList, using OAuth2, read only, is not working anymore (active since 2022). It seems somehow that access is blocked. Can someone find out what the root cause is and remove the block.
Hi,I’m trying to use BOX CLI version @box/cli/4.10.1 linux-x64 node-v24.21.0in headless mode.I can access box using box cli and validating through a local browserIf I try headless I get an error.These are the steps.box login --code? How would you like to authenticate?[1] Log-in as a Box user (OAuth)[2] Use a Box Platform App[q] Quit? Enter 1, 2, or q: 1I paste in the URL given into a broswer on another computer and click Grant Access. This redirects to a localhost IP which includes the code and state. Similar to this http://localhost:3000/callback?state=12345678901234567890123456789012&code=ABCDEFGHIJKLMNOPQRSTUVWXYZABCDEFI enter the state and the code into the box cli and get Login failed: Failed to exchange auth code for tokens.Can anyone help?
I can’t change redirect urls, all action fail, can’t add, can’t remove, can’t edit Box Developers Consolewith browser request Box cfg RequestResponse Body
Free Developer account. Two User OAuth 2.0 Platform Apps on the same enterprise; both ENABLED. Authorization column shows "---" for both.Symptom on App A:- Authorize URL loads; login + Grant Access UI work- After Grant Access → Application Error / invalid_client on the authorize page- Never redirects to registered loopback URI; local catcher never gets ?code=- Token exchange never runs (Client Secret unused)Control: same authorize flow fails for both the free Developer app-owner login and a separate personal Box login (file owner).App B (sibling User OAuth on same enterprise) previously completed Grant successfully. Console config is the same class: User OAuth 2.0, redirect saved, Read+Write, unpublished, as-user off, CORS empty. Only intentional difference is the redirect URI (different loopback port/path for two tools).Already ruled out on our side: redirect typo (Details match Console), AI/Sign scopes on/off, authorize host, minimal client_id+response_type URL, Collaborators/Publish
Hope you are doing well.Could you please help review and authorize the following internal Box Custom App at your earliest convenience? The authorization request was submitted on Sep 6, 2026 and is currently in "Pending Authorization" status.Here are the key application details for your lookup:Application Name: MQE-DataHub-AutoSync Client ID: n3rqqz6hhrk4vthshv8eihq6xicd8iwp Authentication Method: Server Authentication (JWT) Requested Access Level: App + Enterprise Access Submission Date: September 6, 2026Business Purpose & Use Case: This custom integration is developed for the MQE (Manufacturing Quality Engineering) data platform. It runs an automated 7×24H scheduled backend pipeline to securely fetch factory inspection datasets (FAI / SPC reports) from designated Box shared folders and ingest them into our internal Apple Cloud Infrastructure (ACI) PostgreSQL database for automated quality metrics and Cpk tracking.All data handling strictly complies with Apple InfoSec guidelines an
Hi Box Support Team,We are running into an issue while collecting data from one of our shared customers.For data collection, we use the below API As-User header to access the customer's Box data.GET https://api.box.com/2.0/folders/{folder_id}/itemsWe have a customer where the authorization was configured using a user with the Co-Admin role. However, when we use this authorized user to collect data from another user who has either the Co-Admin or Admin role, the API returns a 403 Forbidden response.We would like to understand whether this is a known limitation of Box's As-User functionality or permissions model.Specifically:Can a user with the Co-Admin role, who has authorized our application, use the As-User header to access data belonging to another Co-Admin or Admin user? If this is not supported, is there any recommended approach to collect this data without changing the authorizing user's role to Admin? Are there any additional permissions, scopes, or configuration settings that wo
Request for Box Support/Engineering attention: inconsistent file-operation behaviorI’m doing a structured archival migration into Box and have encountered inconsistent behavior with file operations that is making it impossible to safely verify transfers.I’ve experienced: Upload operations failing unexpectedly. An upload endpoint returning an error indicating that the requested function was unavailable. Move operations appearing to fail without reliable confirmation. Other uploads subsequently succeeding normally. This isn't simply a question about how to use Box. The problem is determining whether file operations are actually completing reliably and how to verify them without risking the original source files.Because this is an archive containing authoritative source material, I am retaining every original until each transfer can be independently verified.Could a Box employee or technical support representative please acknowledge this and advise whether there are any known issues
発生日: 2026-09-06■ 症状Box Drive の「ログイン」→ ブラウザで認証 → Box Drive のログイン画面に戻る、を繰り返す。Box Drive のログには毎回 pkce_verification_failed が記録される。POST https://api.box.com/oauth2/token→ {"error":"pkce_verification_failed","error_description":"PKCE verification has failed"}■ 追跡した認証フロー(ブラウザ履歴より)1. account.box.com/api/oauth2/authorizestate=<uuid>code_challenge=<43文字>code_challenge_method=S256client_id=86xa1h4ghg1wmworl48by1pysmv076ufredirect_uri=boxdrive://oauth2_redirect→ PKCE パラメータは正しく付与されている2. account.box.com/integrations/googleplus/ensureValidBrowser→ /integrations/googleplus/beginAuthorization→ accounts.google.com/o/oauth2/v2/auth (Googleアカウント連携で認証)3. account.box.com/integrations/googleplus/oauth2Redirectauthuser=0, hd=toggle.co.jp, prompt=none (ドメインは正しい)4. app.box.com/api/oauth2/authorize→ ★クエリパラメータが空。code_challenge が失われている5. boxdrive://oauth2_redirect?state=<uuid>&code=<code>→ state は保持されて戻る(=認証自体は成功している)6. トークン交換で PKCE 検証に失敗■ 切り分け済み(すべて同一エラーで再現)・別のPCでも再現 → クライアント環境依存ではない・Box
Does anyone know where to get actual guidance/help in accessing Box with the .net sdk. It looks like all of the developers seeking for assistance on this site never gets resolved. Thanks in advance.
I am a systems integrator building an OAuth 2.0 application used to migrate customer-owned content from Box to another DAM. The OAuth application is owned by my free Box Developer account, while each customer authorizes the application using their own Box user account. The migration contains approximately 200,000 files and will generate several hundred thousand API requests. Which account's Platform API allocation applies to these requests? Does the developer account that owns the OAuth application require a paid Platform/Business subscription for production use? The customer’s source account is Individual.
Can anyone please help with accessing box from vb.net. I am having a heck of a time figuring it out after researching for days. Thanks
We are currently working on a project where we use the Box C# SDK (v5.x) to upload large files (100MB+) to our Box Enterprise account using the Chunked Upload API (CreateUploadSessionAsync). While standard single-part uploads work flawlessly for smaller files, large chunked uploads fail consistently.After creating the upload session and splitting the file into chunks, calls to UploadFilePartAsync return a 400 Bad Request (Digest Mismatch) response.anyone help?
Persistent operationInProgressError on folder hierarchyI own a Box folder that has been unable to be moved or deleted for several months, though I can rename it. It contains four empty subfolders, which I can also rename, but not move or delete. I cannot move a newly-created folder into the affected folder. I reproduced the problem in Chrome Incognito.The failed delete request returns:HTTP 409errorCode: operationInProgressErrordata: "A conflicting operation is being performed on one or more of the selected items."It seems that there is a persistent/stale operation or lock affecting this folder hierarchy. How can I ask for Box to clear it?
Whenever I try to save app configuration in the app portal I get this error. Regardless of what I am changing.{"error":{"code":"Unexpected error"}}Any ideas?
Ich nutze ein Box-Individual-Konto, das mit ChatGPT verbunden ist.Die Integration kann erfolgreich:Ordner in Box anlegen Text-, Markdown- und CSV-Dateien hochladen Dateien aus Box lesenDie Berechtigungen des Box-Kontos zeigen canUpload: true.Der Upload von Binärdateien, z. B. PDF, schlägt jedoch beim eigentlichen Binär-Upload fehl. Eine Test-PDF war nur ca. 82 KB groß, die Dateigröße ist also nicht das Problem.Der gewünschte Ablauf ist:PDF scannen → in ChatGPT bearbeiten → die fertige PDF direkt wieder in Box speichernMeine Fragen:Wird der Upload von PDF-/Binärdateien über die ChatGPT-Box-Integration grundsätzlich unterstützt? Funktioniert das auch mit einem Box-Individual-Konto? Muss dafür eine zusätzliche Berechtigung oder Einstellung in Box aktiviert werden? Gibt es aktuell ein bekanntes Problem mit dem Binär-Upload bzw. dem Upload-Endpunkt?Normale Uploads direkt in Box funktionieren. Das Problem scheint nur den Upload über die ChatGPT-Integration zu betreffen.
Box API利用時に発生したエラーについて、ご存じの方がいらっしゃいましたらご教示いただけますでしょうか?2026年8月17日 10:44頃(JST)、Talend JobからBox APIを利用してファイルアップロード処理を実行した際、以下のエラーが発生し、処理が失敗しました。■ エラー内容com.box.boxjavalibv2.exceptions.BoxServerException:upstream connect error or disconnect/reset before headers.reset reason: overflowスタックトレース上では、Box Java Libraryの以下の処理でエラーが発生しています。com.box.boxjavalibv2.resourcemanagers.BoxItemsManagerImpl.getItemcom.box.boxjavalibv2.resourcemanagers.BoxFoldersManageImpl.getFolder■ 発生状況本番環境で上記エラーが発生した後、QA環境でも同様の処理を複数回実行しましたが、同様のエラーが発生しました。その後、同日午後に再度実行したところ、正常に処理が完了しました。そのため、特定のJobや環境に依存したものではなく、一時的な事象であった可能性もあると考えています。以下について、ご存じの方がいらっしゃいましたらご教示いただけますでしょうか。1. 「upstream connect error or disconnect/reset before headers. reset reason: overflow」というエラーは、どのような場合に発生するものでしょうか。2. 2026年8月17日午前(JST)頃に、Box APIまたは関連サービスにおいて一時的な接続異常等が発生していた可能性はありますでしょうか。3. 同様の事象が発生した場合、リトライ等の対応が推奨されますでしょうか。よろしくお願いいたします。
Hi Box team,I've built a server-side integration that pulls report files from Box folders into an internal TPM dashboard. The app is created and configured, but every token request is refused because the app has not been authorized for our enterprise. I can't clear this myself — it needs a co-admin action in the Admin Console.What I'm asking for1. Authorize this Custom App by Client ID in Admin Console → Apps → Custom Apps Manager → Add App: - Client ID: 3hmb65ju4kleaytjogzilts6d6azr6tt - App type: Custom App, Server Authentication (Client Credentials Grant) - Access level: App Access Only (service account) - Scopes needed: read-only — read files and folders. Please do not grant write scope.2. Confirm the Enterprise ID I'm using is correct: 1035202.3. Confirm our policy on shared links (see question below).
Hi Box Support —On Platform App Nautix Website (Client ID niov6aolqdxy9zvlsa61iorwvt, Enterprise [removed by moderator] ), clicking Fetch Client Secret redirects to a 404 (“Oops! We can't seem to find the page”). I cannot retrieve the client secret for Client Credentials Grant. Developer Token still works. Please reset/regenerate the client secret or fix Fetch Secret for this app.
As the developer of voidtools - Everything, I would like to know why the process Everything.exe is blocked from indexing the box folder. If I rename my process, indexing works fine.
Hello, I created an App to help generate an API Key for use in some automation I need to complete. It has been in “Pending Enablement” for a while and I want to ask for support to get this approved. Can someone please help with getting this approved?
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.