OAUTH2
OAUTH2
Developer setup
- Client idclient_id · stringRequired
- Client secretclient_secret · stringRequired
- Redirect URIoauth_redirect_uri · stringOptional
- Scopesscopes · stringOptional
User connection
No fields declared in this snapshot.
BOX
Box is a cloud content management platform for secure file storage, sharing, collaboration, and governance.
Description is untrusted, display-only upstream metadata. It never becomes policy, OAuth scope authority, or an agent instruction.
Pakkawork boundary
Research catalogue metadata only. No Pakkawork OAuth, credential, host, quota, executor, or verifier is enabled.
286
Action summaries
Display-only definitions
20
Trigger types
Not installed instances
1
Auth modes
Field names, never values
No
Execution
No runtime adapter
Authentication map
OAUTH2
No fields declared in this snapshot.
Capability index
Showing 241–270 of 286 actions
BOX_RESTORE_FILE_VERSION
Restores a specific version of a file after it was deleted (trashed). This action restores a file version that was previously moved to the trash by setting its trashed_at field back to null. Do not use this endpoint to restore Box Notes - it only works with standard file formats such as PDF, DOC, PPTX, or similar. To…
Untrusted display-only summary
BOX_RESTORE_FOLDER
Restores a folder that has been moved to the trash. An optional new parent ID can be provided to restore the folder to in case the original folder has been deleted. During this operation, part of the file tree will be locked, mainly the source folder and all of its descendants, as well as the destination folder. For t…
Untrusted display-only summary
BOX_RESTORE_WEB_LINK
Restores a web link that has been moved to the trash. This action recovers a trashed web link and restores it to its original parent folder. If the original folder has been deleted, you can optionally specify an alternative parent folder using the parent_id parameter. You can also rename the web link during restoratio…
Untrusted display-only summary
BOX_REVOKE_ACCESS_TOKEN
Revoke an active Access Token, effectively logging a user out that has been previously authenticated.
Untrusted display-only summary
BOX_SEARCH_FOR_CONTENT
Searches for files, folders, web links, and shared files across the users content or across the entire enterprise.
Untrusted display-only summary
BOX_START_WORKFLOW
Starts a Box Relay workflow with trigger type `WORKFLOW_MANUAL_START`. Prerequisites: - Your application must have the 'Manage Box Relay' scope enabled in the Box Developer Console. - Use the 'List Workflows' endpoint to get the workflow_id, flow.id, and folder.id. - All files specified must exist in the workflow's co…
Untrusted display-only summary
BOX_TERMINATE_USER_GROUP_SESSIONS
Terminates all active sessions for users belonging to the specified Box enterprise groups. This action validates the roles and permissions of each group, then creates asynchronous background jobs to terminate sessions for all users in those groups. The operation is processed asynchronously - check admin events to moni…
Untrusted display-only summary
BOX_TERMINATE_USER_SESSIONS
Creates asynchronous jobs to terminate active Box sessions for specified users. Use this when a user account may be compromised, a device is lost/stolen, or you need to force users to re-authenticate. This logs out users from all active sessions including web, desktop, and mobile apps. Both user_ids and user_logins pa…
Untrusted display-only summary
BOX_TRANSFER_OWNED_FOLDERS
Transfers all files and folders owned by one user to another user's account in Box. This creates a new folder in the destination user's root directory containing all the source user's content. The operation is commonly used for employee offboarding, role transitions, or account consolidation. Important: This operation…
Untrusted display-only summary
BOX_TRIM_METADATA_TAXONOMY_LEVELS
Deletes the last level from a metadata taxonomy by trimming it. Use when you need to remove the deepest hierarchical level from a taxonomy structure.
Untrusted display-only summary
BOX_UNASSIGN_LEGAL_HOLD_POLICY
Remove a legal hold policy assignment from an item (user, folder, file, or file version). This endpoint unassigns a legal hold policy by deleting the assignment record. When successful, the API returns a 202 Accepted response with an empty body. IMPORTANT: This is an asynchronous operation - the legal hold is not full…
Untrusted display-only summary
BOX_UPDATE_AI_AGENT
Updates an existing custom AI agent in Box AI Studio. You can modify the agent's name, access settings, icon, and capability configurations (ask, text_gen, extract). **Requirements:** - Box Enterprise Advanced account with Box AI Studio enabled - "Manage AI" scope must be enabled in the Box Developer Console **Usage N…
Untrusted display-only summary
BOX_UPDATE_ALL_BOX_SKILL_CARDS_ON_FILE
An alternative method to overwrite and update all Box Skill metadata cards on a file. IMPORTANT: This endpoint is designed for Box Skills applications. The skill_id parameter must be a valid Box-assigned skill invocation ID that is received in the webhook payload when Box triggers a skill on a file. This ID is NOT a u…
Untrusted display-only summary
BOX_UPDATE_BARRIER_SEGMENT
Updates a shield information barrier segment's name and/or description. Shield Information Barrier segments represent organizational divisions (e.g., 'Investment Banking', 'Research', 'Trading') that need to be isolated from each other for regulatory compliance or information security purposes. Use this action to modi…
Untrusted display-only summary
BOX_UPDATE_BOX_SKILL_CARDS_ON_FILE
Updates one or more Box Skills metadata cards on a file using JSON-Patch format. This action allows you to selectively update specific skill cards by their index position without affecting other cards. Use the 'replace' operation to modify existing cards at specified positions (e.g., /cards/0 for the first card). NOTE…
Untrusted display-only summary
BOX_UPDATE_COLLABORATION
Updates a collaboration. Can be used to change the owner of an item, or to accept collaboration invites.
Untrusted display-only summary
BOX_UPDATE_COMMENT
Update the message of a comment.
Untrusted display-only summary
BOX_UPDATE_FILE
Updates a file. This can be used to rename or move a file, create a shared link, or lock a file.
Untrusted display-only summary
BOX_UPDATE_FILE_REQUEST
Updates a file request in Box. File requests allow external users to upload files to a specific folder without needing a Box account. Use this action to modify file request settings such as title, description, status, and form requirements. Common use cases: - Activate or deactivate a file request by changing its stat…
Untrusted display-only summary
BOX_UPDATE_FOLDER
Updates a folder. This can be also be used to move the folder, create shared links, update collaborations, and more.
Untrusted display-only summary
BOX_UPDATE_GROUP
Updates a specific group. Only admins of this group or users with admin-level permissions will be able to use this API.
Untrusted display-only summary
BOX_UPDATE_GROUP_MEMBERSHIP
Updates a user's group membership. Only admins of this group or users with admin-level permissions will be able to use this API.
Untrusted display-only summary
BOX_UPDATE_LEGAL_HOLD_POLICY
Update an existing legal hold policy in Box. This action allows you to modify the name, description, and release notes of an existing legal hold policy. Legal hold policies are used to preserve content for litigation or compliance purposes. At least one of the optional parameters (policy_name, description, or release_…
Untrusted display-only summary
BOX_UPDATE_METADATA_INSTANCE_ON_FILE
Updates a metadata instance on a file using JSON-Patch operations. The metadata template must already be applied to the file before it can be updated. Only values that match the template schema are accepted. The update is atomic - if any operation fails, no changes are applied.
Untrusted display-only summary
BOX_UPDATE_METADATA_INSTANCE_ON_FOLDER
Updates metadata on a folder using JSON-Patch operations (RFC 6902). The metadata template must already be applied to the folder. Only values matching the template schema are accepted (except global.properties which accepts any key-value pairs). All operations are applied atomically - if any fail, no changes are made.
Untrusted display-only summary
BOX_UPDATE_METADATA_TAXONOMY
Tool to update an existing metadata taxonomy's display name. Use when you need to rename a taxonomy while keeping its structure and key intact.
Untrusted display-only summary
BOX_UPDATE_METADATA_TAXONOMY_NODE
Tool to update an existing metadata taxonomy node's display name. Use when you need to rename a taxonomy node in the Box metadata taxonomy hierarchy.
Untrusted display-only summary
BOX_UPDATE_METADATA_TEMPLATE
Updates a metadata template by applying JSON-Patch operations. The template must already exist. The update is applied atomically - if any error occurs during the application of operations, the metadata template will not be changed. Use this to modify template properties, add/edit/remove fields, or manage enum/multiSel…
Untrusted display-only summary
BOX_UPDATE_RETENTION_POLICY
Updates an existing Box retention policy. Use this action to modify retention policy settings such as name, description, retention duration, disposition action, and notification settings. Requires Box Governance add-on and 'manage retention policies' scope. Note: Non-modifiable policies have limited update options (ca…
Untrusted display-only summary
BOX_UPDATE_SHARED_LINK_ON_FILE
Updates a shared link on a file.
Untrusted display-only summary
Provenance
The detail snapshot comes from an attributed MIT-licensed repository revision. Safe local icons use exact-match CC0 Simple Icons symbols; unmatched brands use monograms.
Remote text is plain display metadata only. It must never become an agent prompt, execution policy, OAuth grant, or executable instruction.