Skip to content
Status

Box

Connect the Speakeasy AI Control Plane to Box's hosted MCP server with credentials created by a Box Admin or Co-Admin.

You need a Box Admin or Co-Admin account for the enterprise you are connecting.

The Box MCP Server is available on all Box plans, but its tools depend on your plan. Box AI tools require an eligible Box AI plan or purchased Box AI Units. The Doc Gen scope requires an Enterprise Advanced license. Box meters and bills API calls made with the Integration Credentials created below.

Sign in to the Box Admin Console

Sign in to the Box Admin Console at app.box.com/master with your Box Admin or Co-Admin account.

Before creating credentials, complete one or both conditional sections as required: enable the Box AI API if users need Box AI tools, enable Box Doc Gen if users need Doc Gen tools, or both if they need both. If both are required, complete both before returning to Integrations. Then create credentials for the Custom Box MCP Server integration.

Find Custom Box MCP Server under Integrations

  1. Select Integrations.
  2. Apply the MCP Category filter, or type Custom Box MCP Server in the search bar at the top of the page.
  3. Find the Custom Box MCP Server tile.

Do not select the Box MCP Server tab or a named partner tile.

Add Integration Credentials

When adding credentials for the first time, use the branch the tile presents.

If the Custom Box MCP Server tile shows Configuration:

  1. Open Configuration.
  2. Click Add Integration Credentials.

Otherwise:

  1. Hover over Custom Box MCP Server.
  2. Click Configure.
  3. Open Additional Configuration.
  4. Click + Add Integration Credentials.
  5. Retain the pre-filled credential name or enter a new one.
  6. Click Save.
  7. Open the created credential entry.

Set the Redirect URI

Replace the existing value or values in Redirect URIs with this value:

https://app.getgram.ai/mcp/remote_login_callback

Copy the Client ID and Client Secret

Copy both values while Box shows them.

  1. Copy the Client ID.
  2. Store the Client ID for Speakeasy setup.
  3. Copy the Client Secret.
  4. Store the Client Secret like a password for Speakeasy setup.

Check the Access scopes

  1. Review Access scopes.
  2. Select Box content access and any optional tool areas users need.

The documented scope strings are root_readwrite for Box content, ai.readwrite for Box AI, and docgen.readwrite for Box Doc Gen. The console may present descriptive checkbox labels instead of these strings. Select Box AI or Box Doc Gen access only when the enterprise has enabled and licensed those features. The Doc Gen scope requires an Enterprise Advanced license. Scopes cap what the connection can do; each user’s existing Box permissions still limit the content they can access.

Save the credential entry

Click Save, or use the equivalent Update or Apply action shown by your tenant, to finish the integration credentials.

After saving, if you have completed every required Box AI or Doc Gen section, continue to Connect your credentials unless you need optional tool-policy setup. If you do, complete Manage tool access before rollout first, then continue to Connect your credentials.

Enable the Box AI API (AI tools only)

Complete this step only if users need Box AI tools. Box AI APIs require an eligible Box AI plan or purchased Box AI Units. If the setting is unavailable, resolve the enterprise’s Box AI entitlement before continuing.

  1. Open Box AI in the Admin Console.
  2. Select Settings.
  3. Enable Enable AI API.

If users also need Doc Gen tools and you have not completed that conditional section, complete Enable Box Doc Gen. Return to Find Custom Box MCP Server under Integrations only after all required conditional sections are complete.

Enable Box Doc Gen (Doc Gen tools only)

Complete this step only if users need Doc Gen tools. The Doc Gen scope requires an Enterprise Advanced license.

  1. Open Enterprise Settings.
  2. Select Content and Sharing.
  3. Scroll to Box Doc Gen.
  4. Under Box Doc Gen Permissions, choose to enable Doc Gen for all managed users, selected users and groups, or everyone except selected users and groups.

By default, Doc Gen is disabled for all managed users.

If users also need Box AI tools and you have not completed that conditional section, complete Enable the Box AI API. Return to Find Custom Box MCP Server under Integrations only after all required conditional sections are complete.

Manage tool access before rollout (optional)

Complete this step only when enterprise policy requires restrictions or when you must enable an external-sharing tool that Box disables by default. Changes apply across the enterprise.

  1. Open the Admin Console.
  2. Select Integrations.
  3. Select the Box MCP Server tab.
  4. For a tool category, choose Disable all tools, Enable read only tools, Enable read & write tools, or Custom configuration from Enablement.

To control individual tools:

  1. Click Configure for the category.
  2. Set the toggles under Read only MCP tools and Write MCP tools.
  3. Click Save.

File preview requires a compatible application. Upload and download URL tools require an application that can make network requests; a cloud security owner may also need to allowlist domains.

If a client still shows the old tool list, refresh its tool list, start a new chat, or disconnect and reconnect it.

Add the server in Speakeasy

  1. In the Speakeasy AI Control Plane sidebar, under Connect, select Sources.
  2. Click Add Source.
  3. Choose 3rd-party server.
  4. On the MCP Catalog page, use Search MCP servers… to find Box.
  5. Click View on the Box entry.
  6. Click Add.
  7. In the Add to Project dialog, click Add to Project.

This creates the hosted MCP server and opens its Overview page.

Connect your credentials

  1. From Overview, open Settings.
  2. Under Authentication, click Configure Manually, or click Use Discovered when offered.
  3. In Attach Remote Identity Provider, set Client Type to Manual.
  4. Before entering credentials, verify that https://app.getgram.ai/mcp/remote_login_callback has rendered as a concrete Speakeasy Redirect URI in the sheet. Do not enter the literal template marker in Box.
  5. Paste the Box Client ID into Client ID.
  6. Paste the Box Client Secret into Client Secret (optional).
  7. Click Attach Identity Provider.
  8. Confirm that the attached identity provider’s Redirect URI matches the value registered in Box under Redirect URIs.

This guide covers setup only. For anything beyond it — billing, tool behavior, limits — see Box’s MCP documentation.