Dropbox IntegrationSAFE
MCP Server for Dropbox
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) server that provides integration with Dropbox, allowing MCP-compatible clients to interact with Dropbox through a set of powerful tools.
Important Disclaimer: This project is not affiliated with, endorsed by, or sponsored by Dropbox. It is an independent integration that works with Dropbox's public API.
Table of Contents
- Quick Start
- Installation
- Authentication
- Available Tools
- Required Dropbox Permissions
- Usage Examples
- Development
- License
Quick Start
- Clone the repository
- Run
npm installto install dependencies - Run
npm run buildto build the project - Run
npm run setup - Configure your MCP client to use the server
Prerequisites
Register a Dropbox app at Dropbox App Console:
- Choose "Scoped access" API
- Choose the access type your app needs
- Name your app and click "Create app"
- Under "Permissions", select the desired permissions for the actions you will be using, for example:
files.metadata.readfiles.content.readfiles.content.writesharing.writeaccount_info.read- Add
http://localhostas your redirect URI - Note your App key and App secret
Installation
- Clone the repository
git clone https://github.com/your-username/dbx-mcp-server.git cd dbx-mcp-server
- Install dependencies and build
npm install npm run build
- Run the setup script
npm run setup
- Add to MCP settings
Add the following to your MCP settings file:
{
"mcpServers": {
"dbx": {
"command": "node",
"args": ["/path/to/dbx-mcp-server/build/index.js"]
}
}
}Authentication
The server uses OAuth 2.0
7c87610f8c63OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add dbx-mcp-server --env DROPBOX_ACCESS_TOKEN=${DROPBOX_ACCESS_TOKEN} --env DROPBOX_APP_KEY=${DROPBOX_APP_KEY} --env DROPBOX_APP_SECRET=${DROPBOX_APP_SECRET} --env MAX_TOKEN_REFRESH_RETRIES=${MAX_TOKEN_REFRESH_RETRIES} -- npx -y [email protected]{
"mcpServers": {
"dbx-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"DROPBOX_ACCESS_TOKEN": "${DROPBOX_ACCESS_TOKEN}",
"DROPBOX_APP_KEY": "${DROPBOX_APP_KEY}",
"DROPBOX_APP_SECRET": "${DROPBOX_APP_SECRET}",
"MAX_TOKEN_REFRESH_RETRIES": "${MAX_TOKEN_REFRESH_RETRIES}"
}
}
}
}Exposed tools (25)
18 read · 4 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
copy_item | read | Copy a file or folder to a new location |
create_folder | write | Create a new folder (integrates with Dropbox) |
dbx_help | read | Get help with file operations and commands (integrates with Dropbox) |
delete_item | destructive | Legacy delete operation (deprecated, use safe_delete_item instead) |
download_file | read | Download a file to local disk and return the file path. Files are saved to the |
file1 | read | Path to the first file |
file2 | read | Path to the second file |
fileTypes | read | Comma-separated list of file extensions to include (e.g., |
file_compare | read | Compare two files and highlight differences |
file_comparison | read | Compare two files |
file_detail | read | Provide detailed analysis of a specific file |
file_review | read | Review files in a specified folder and provide analysis |
folder_review | read | Review contents of a folder |
get_account_info | read | Get information about the connected account (integrates with Dropbox) |
get_file_content | read | Get the content of a file (integrates with Dropbox) |
get_file_metadata | read | Get metadata for a file or folder |
get_sharing_link | write | Create a shared link for a file or folder |
list_files | read | List files in a folder (integrates with Dropbox) |
move_item | write | Move or rename a file or folder |
operation | destructive | The operation to review (e.g., delete, move, copy) |
path | read | The file/folder path involved |
review_operation | read | Review a file operation before executing it (integrates with Dropbox) |
safe_delete_item | destructive | Safely delete a file or folder with recycle bin support, confirmation, and audit logging |
search_file_db | read | Advanced search for files and folders with filtering capabilities (integrates with Dropbox) |
upload_file | write | Upload a file (integrates with Dropbox) |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (7)
delete_item, operation, safe_delete_item
import { decryptData } from '../../src/security-utils.js';jest.mock('../../src/config.js');jest.mock('../../src/auth.js');jest.mock('../../src/dbx-api.js');import { ResourceHandler } from '../../src/resource/resource-handler.js';axios, crypto-js, dotenv, dropbox, httpx, open, winston, @babel/core
Gates applied: no_behavioural_pass.
7c87610f8c63full audit observations/trust-audit/mcp-server/amgadabdelhafez__dropbox-integration.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 7c87610f8c63 | SAFE | B | 89 | first audit |
Questions
What is the Dropbox Integration MCP server?
MCP Server for Dropbox
What tools does Dropbox Integration expose?
25 in total: 18 read-only, 4 that write, and 3 that can delete or overwrite (delete_item, operation, safe_delete_item). Every one is listed on this page with its risk.
Is Dropbox Integration safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Dropbox Integration need?
It reads DROPBOX_ACCESS_TOKEN, DROPBOX_APP_KEY, DROPBOX_APP_SECRET, MAX_TOKEN_REFRESH_RETRIES, TOKEN_ENCRYPTION_KEY, TOKEN_REFRESH_RETRY_DELAY_MS, TOKEN_REFRESH_THRESHOLD_MINUTES and TOKEN_STORE_PATH from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Dropbox Integration run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as dbx-mcp-server at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (7c87610f8c63), read on 2026-10-08. The repository is watched and re-audited when it changes.