boxadm-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| BOX_API_BASE | No | API base URL (default https://api.box.com) | |
| BOX_AUTH_MODE | No | oauth or ccg (default ccg) | |
| BOX_CLIENT_ID | Yes | App Client ID | |
| BOX_TOKEN_CACHE | No | OAuth token cache path (default ~/.config/boxadm-mcp/token.json) | |
| BOX_CLIENT_SECRET | Yes | App Client Secret | |
| BOX_ENTERPRISE_ID | No | Enterprise ID (required for ccg mode) | |
| BOX_ALLOWED_DOMAINS | Yes | Internal email domains (comma-separated) | |
| BOX_OAUTH_REDIRECT_URI | No | OAuth redirect URI (default http://localhost:8787/callback) |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| health_checkA | Report server version, Box connectivity/auth, and configuration. Call this at session start (or after a tool-call timeout) to confirm the MCP
is up, see which version is running, verify the Box enterprise token can be
obtained (CCG) and that the Always returns the same keys: |
| recent_admin_eventsA | Fetch recent enterprise Diagnostic/starter tool: returns Box events verbatim so the real event types and field shapes can be confirmed before analytics tools are layered on. For external-sharing work the event types of interest are typically COLLABORATION_INVITE / COLLAB_ADD_COLLABORATOR, SHARED_LINK_CREATED / ITEM_SHARED_CREATE, and DOWNLOAD / PREVIEW. Args:
event_types: Comma-separated Box event_type filter (empty = all types).
since_hours: Look-back window in hours (default 24).
limit: Max events to return in this page (default 100).
stream_position: Continue a previous page by passing back the
|
| external_access_eventsA | Surface external file access (DOWNLOAD / PREVIEW) from enterprise admin_logs. Enterprise-wide (events stream): over the window, flags each access whose
actor ( Args:
since_hours: Look-back window in hours (default 24).
max_events: Cap on DOWNLOAD/PREVIEW events scanned (default 5000); the
result's Returns Notes:
|
| external_collaboratorsA | List external collaborators on Box folders (current state, enumeration). Walks folders the authenticating co-admin user can see (default from the root "All Files") and reports collaborations whose collaborator is outside the org domain allowlist — accepted external users or pending external invites. Useful to review who outside the organization has standing access. Args:
root_folder_id: Folder to start from ("0" = the user's root). A Box
folder id: decimal digits only, as shown at the end of a Box folder
URL. Anything else is refused with Externally-owned folders (this org is only a guest, not the owner) are out
of scope and skipped — we cannot govern their collaborations, and their
"external collaborators" are just the owner's own org accounts. They are
reported separately under Coverage note: limited to content the co-admin user can access (not provably
100% of the enterprise) and to the depth/folders caps. Returns
|
| public_shared_linksA | List items with an open ("anyone with the link") shared link (enumeration). Walks folders the authenticating co-admin user can see and reports files and
folders whose shared link access is Args:
root_folder_id: Folder to start from ("0" = the user's root). A Box
folder id: decimal digits only, as shown at the end of a Box folder
URL. Anything else is refused with Coverage note: limited to content the co-admin user can access and to the
caps. Returns |
| top_external_sharersA | Rank internal owners by their external exposure (enumeration). One traversal (same as external_collaborators / public_shared_links), then ranks internal file/folder owners by how much external exposure they hold: external collaborations + open shared links on content they own. Surfaces the people whose content is most exposed outside the organization. Args: root_folder_id / max_folders / max_depth: traversal bounds (see external_collaborators). top: How many owners to return (default 20). Coverage note: limited to the co-admin user's visible content and the caps.
Returns |
| get_userA | Look up ONE Box account by its exact login (the account's email address). Answers "what is this account's state?" — the question behind a ticket that says "my Box account is disabled". Every other tool here reads the event stream or walks folders, so an account with no recent events is invisible to them; this is one request against the user directory and the only tool that answers about an account directly. Use it when a specific account is named. It cannot list, search or enumerate accounts: it takes one login and answers about that login only. Args:
login: The account's full Box login, i.e. its email address
( This server is downstream of an identity provider, not the master. Read what comes back as "what Box currently believes", and compare it against the IdP's own record (which is authoritative for who the account is). A disagreement is the finding, and is usually drift on the Box side rather than a mistyped address:
One drift this tool cannot find for you: the same person under a second login at
another domain (an alias, or a duplicate left by a migration). Returns two shapes, distinguished by whether the lookup completed. On a completed lookup:
Why the filtering matters: Box's On failure the other shape is returned: |
| daily_briefA | Morning DLP brief: external access (events) + external-sharing state (enumeration). One call that combines:
Reuses the cached folder scan, so calling this alongside the other enumeration
tools doesn't re-walk. Args mirror the underlying tools; |
| list_folder_itemsA | List ONE Box folder's contents, newest first, with who uploaded each item. An Written for a help desk answering a submitted enquiry whose attachments land in a Box folder. Instead of a human going to find that folder, the answer can name the attachments and link straight to them. Args:
folder_id: The folder's Box id — decimal digits, the number at the end of
a Box folder URL. On Treat Returns, on a completed listing:
On failure the shape is |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 9 tools
The tools split clearly between event-stream inspection (external_access_events, recent_admin_events), current-state enumeration (external_collaborators, public_shared_links, top_external_sharers), and single-item lookups (get_user, list_folder_items). daily_brief aggregates several of these but is clearly documented as a combined convenience call, so confusion is unlikely though possible.
Names are readable and mostly self-explanatory, but they mix verb-object forms (list_folder_items, get_user) with noun-phrase forms (health_check, external_collaborators, top_external_sharers). There is no single consistent convention like verb_noun across the set.
Nine tools is well within the appropriate range for an admin/audit server, and each tool either covers a distinct workflow or is justified as a convenience/diagnostic wrapper (daily_brief, recent_admin_events). The enumeration cluster shares traversal logic but produces different outputs, so none feels redundant.
The core DLP workflows are covered: historical external access events, current external collaborations, open shared links, exposure ranking, account state lookup, and folder content listing. Missing remediation actions and broader user enumeration are understandable gaps for a read-only audit/help-desk tool, but they would prevent fully closing the loop on a finding.