Server BoxSAFE
Securely connect AI agents to your enterprise content in Box
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[!WARNING] This repository is discontinued and no longer maintained. Box now provides an officially supported hosted MCP server with the best experience and full functionality. Please migrate to the hosted MCP server: [Set up the Box MCP Server →](https://developer.box.com/guides/box-mcp/setup)
Quick Start
Clone the repository:
git clone https://github.com/box-community/mcp-server-box.git cd mcp-server-box
Optional but recommended uv installation for virtual environment and dependency management:
Homebrew (macOS)
brew install uv
WinGet (Windows)
winget install --id=astral-sh.uv -e
On macOS and Linux
curl -LsSf https://astral.sh/uv/install.sh | sh
On Windows
powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"
Set up the virtual environment and install dependencies:
uv sync
Set environment variables:
Set the following environment variables for Box authentication in a .env file or your system environment.
For comprehensive authentication configuration options, see the Authentication Guide.
Using OAuth2.0 with a Box App
BOX_CLIENT_ID = YOUR_CLIENT_ID BOX_CLIENT_SECRET = YOUR_CLIENT_SECRET BOX_REDIRECT_URL = http://localhost:8000/callback # MCP Server Authentication (for HTTP transports) BOX_MCP_SERVER_AUTH_TOKEN = YOUR_BOX_MCP_SERVER_AUTH_TOKEN OAUTH_PROTECTED_RESOURCES_CONFIG_FILE = .oauth-protected-resource.json
Note: - TheBOX_MCP_SERVER_AUTH_TOKENis used to authenticate the MCP client to the MCP server when using--mcp-auth-type=token(independent of Box authentication)
Run the MCP server in STDIO mode:
uv run src/mcp_server_box.py
Box Community MCP Server Tools
Below is a summary of the available tools:
a936b8f3a794OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-server-box --env BOX_CLIENT_SECRET=${BOX_CLIENT_SECRET} --env BOX_MCP_SERVER_AUTH_TOKEN=${BOX_MCP_SERVER_AUTH_TOKEN} --env BOX_PRIVATE_KEY=${BOX_PRIVATE_KEY} --env BOX_PRIVATE_KEY_PASSPHRASE=${BOX_PRIVATE_KEY_PASSPHRASE} -- uvx mcp-server-box{
"mcpServers": {
"mcp-server-box": {
"command": "uvx",
"args": [
"mcp-server-box"
],
"env": {
"BOX_CLIENT_SECRET": "${BOX_CLIENT_SECRET}",
"BOX_MCP_SERVER_AUTH_TOKEN": "${BOX_MCP_SERVER_AUTH_TOKEN}",
"BOX_PRIVATE_KEY": "${BOX_PRIVATE_KEY}",
"BOX_PRIVATE_KEY_PASSPHRASE": "${BOX_PRIVATE_KEY_PASSPHRASE}"
}
}
}
}Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
mcp_server_info | read | Returns information about the MCP server. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (3)
- Uses a service account with elevated permissions
- **Use Case:** Initiate OAuth flow to obtain access tokens when not using Client Credentials Grant (CCG)
curl -LsSf https://astral.sh/uv/install.sh | sh
Gates applied: no_behavioural_pass.
a936b8f3a794full audit observations/trust-audit/mcp-server/box-community__server-box.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | a936b8f3a794 | SAFE | B | 89 | first audit |
Questions
What is the Server Box MCP server?
Securely connect AI agents to your enterprise content in Box
What tools does Server Box expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Server Box safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Server Box need?
It reads BOX_CLIENT_SECRET, BOX_MCP_SERVER_AUTH_TOKEN, BOX_PRIVATE_KEY, BOX_PRIVATE_KEY_PASSPHRASE, BOX_PUBLIC_KEY_ID and OAUTH_PROTECTED_RESOURCES_CONFIG_FILE from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Server Box run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as mcp-server-box.
How current is this page?
The grade is for one exact copy of the source (a936b8f3a794), read on 2026-10-07. The repository is watched and re-audited when it changes.