Box MCP Server
Box offers two MCP deployments: a remote server Box hosts at mcp.box.com that clients and agent platforms connect to directly, and a self-hosted open-source version maintained as a Box developer community project. Users authorize access with OAuth and agents call tools for search, Box AI and folder operations without the client ever handling raw file payloads. It is documented for Claude, Microsoft Copilot Studio and Mistral Le Chat. Worth knowing before you start: a Box admin has to enable the integration before it will work for anyone in the enterprise.
Install Box
- Published by
- Official (vendor)
- Transport
- Remote (HTTP)
- Authentication
- OAuth
Claude Desktop, Claude Code and Cursor
Add this to the mcpServers object in your client's
config file, then restart the client.
{
"mcpServers": {
"box": {
"type": "http",
"url": "https://mcp.box.com"
}
}
}
VS Code uses a different key — show that config
Identical entry, filed under servers rather than
mcpServers. Put it in
.vscode/mcp.json for one workspace.
{
"servers": {
"box": {
"type": "http",
"url": "https://mcp.box.com"
}
}
}
Before it will answer
Needs a client ID and secret generated under Integration Credentials in the Box Admin Console before it will connect — this is not a paste-and-go endpoint. Three scopes gate the functionality: root_readwrite, ai.readwrite, and docgen.readwrite, the last of which requires an Enterprise Advanced licence. Scopes are a ceiling, not a grant: users still only reach content they could already open in Box.