Box
Use a Box Admin or Co-Admin account for the enterprise you are connecting. Sign in to the Box Admin Console at app.box.com/master.
The Box MCP Server is available on all Box plans, but its tools depend on your plan. Box AI tools require a Box AI-enabled plan. The Doc Gen scope requires an Enterprise Advanced license. Box meters and bills API calls made with the Integration Credentials created below.
Before creating credentials, enable Box AI or enable Box Doc Gen if users need those tools. Their scopes appear only after the corresponding feature is enabled. Then create credentials for the Custom Box MCP Server integration.
Sign in to the Box Admin Console
Sign in to the Box Admin Console at app.box.com/master with your Box Admin or Co-Admin account.
Find Custom Box MCP Server under Integrations
- Select Integrations.
- Apply the MCP Category filter, or type
Custom Box MCP Serverin the search bar at the top of the page. - Find the Custom Box MCP Server tile.
Do not select the Box MCP Server tab or a named partner tile.
Add Integration Credentials
Complete the credential entry through Save in one sitting.
- Hover over Custom Box MCP Server.
- Click Configure.
If Configuration appears:
- Open Configuration.
- Click Add Integration Credentials.
If Additional Configuration appears instead:
- Open Additional Configuration.
- Click + Add Integration Credentials.
- Retain the pre-filled credential name or enter a new one.
- Click Save.
- Open the created credential entry.
Set the Redirect URI
Replace the existing value or values in Redirect URIs with
https://app.getgram.ai/mcp/remote_login_callback.
Copy the Client ID and Client Secret
Box does not document whether the Client Secret remains visible later. Copy both values before leaving this flow.
- Copy the Client ID.
- Store the Client ID for Speakeasy setup.
- Copy the Client Secret.
- Store the Client Secret like a password for Speakeasy setup.
If you later cannot view the Client Secret, create and configure a new credential entry.
Check the Access scopes
- Review Access scopes.
- Select the options corresponding to the tool areas users need: Box content, Box AI, and Box Doc Gen.
The console’s checkbox labels may differ from the API scope strings
root_readwrite, ai.readwrite, and docgen.readwrite.
The Doc Gen scope requires an Enterprise Advanced license. Scopes cap what the connection can do; each user’s existing Box permissions still limit the content they can access.
If an AI or Doc Gen scope is absent, save the credential entry before leaving the page. Enable the corresponding feature below, reopen the credential entry, select the newly visible scope, and click Save again. If the saved entry cannot be edited, create and configure a new credential entry.
Save the credential entry
- Click Save.
- Reopen the credential entry.
- Confirm that Redirect URIs contains the value you entered.
If the value did not persist, enter it again and click Save.
Enable the Box AI API (AI tools only)
Complete this step only if users need Box AI tools. On Business, Business
Plus, and Enterprise plans, Box AI APIs require purchased Box AI Units.
Contact your Box account manager or sales@box.com to purchase them.
First-time enablement may require acceptance of the Box AI Product Addendum. If Review Agreement Offline appears, contact the Box Account Team.
- Open Box AI in the Admin Console.
- Select Settings.
- If Box AI is not fully enabled, click Enable Box AI.
- For Box AI APIs, click configure.
- Select Enable for all.
If you completed this prerequisite before creating credentials and users also need Doc Gen tools, complete Enable Box Doc Gen first unless it is already enabled. Otherwise, continue at Find Custom Box MCP Server under Integrations. If you came here because the Box AI scope was missing from a saved credential, return to Check the Access scopes.
Enable Box Doc Gen (Doc Gen tools only)
Complete this step only if users need Doc Gen tools. The Doc Gen scope requires an Enterprise Advanced license.
- Open Enterprise Settings.
- Select Content and Sharing.
- Scroll to Box Doc Gen.
- Under Box Doc Gen Permissions, click Configure.
- Select Enable for all managed users, Enable for select users and groups, or Enable for everyone except select users and groups.
The default is Disable for all managed users (default).
If you completed this prerequisite before creating credentials and users also need Box AI tools, complete Enable the Box AI API first unless it is already enabled. Otherwise, continue at Find Custom Box MCP Server under Integrations. If you came here because the Doc Gen scope was missing from a saved credential, return to Check the Access scopes.
Restrict which tools are exposed (optional)
Complete this step before rollout if you need to restrict tools or enable the external-sharing tools that are off by default. Changes apply across the enterprise and take effect immediately.
- Open the Admin Console.
- Select Integrations in the left sidebar.
- Select the Box MCP Server tab.
- For a tool category, choose Disable all tools, Enable read only tools, Enable read & write tools, or Custom configuration from Enablement.
To control individual tools:
- Click Configure for the category.
- Set the toggles under Read only MCP tools and Write MCP tools.
- Click Save.
If a client still shows the old tool list, refresh its tool list, start a new chat, or disconnect and reconnect it.
Add the server in Speakeasy
- In the Speakeasy AI Control Plane sidebar, select Sources under Connect.
- Click Add Source.
- Choose 3rd-party server.
- On the MCP Catalog page, use Search MCP servers… to find Box.
- Click View on the Box entry.
- Click Add.
- In the Add to Project dialog, click Add to Project.
This creates the hosted MCP server and opens its Overview page.
Connect your credentials
- From Overview, open Settings.
- Under Authentication, click Configure Manually, or click Use Discovered when offered.
- In Attach Remote Identity Provider, set Client Type to Manual.
- Confirm that the sheet’s Redirect URI, shown with a copy button, matches the value registered in Box under Redirect URIs.
- Paste the Box Client ID into Client ID.
- Paste the Box Client Secret into Client Secret (optional).
- Click Attach Identity Provider.
This guide covers setup only. For anything beyond it — billing, tool behavior, limits — see Box’s MCP documentation at https://docs.box.com/en/box-mcp/about-box-mcp-server.