- name:
- box-automation
- description:
- Automate Box operations including file upload/download, content search, folder management, collaboration, metadata queries, and sign requests through Composio's Box toolkit.
- risk:
- critical
- source:
- community
- date_added:
- 2026-02-27
@ Box Automation via Rube MCP
Automate Box operations including file upload/download, content search, folder management, collaboration, metadata queries, and sign requests through Composio's Box toolkit.
@ Prerequisites
- Rube MCP must be connected (RUBESEARCHTOOLS available)
- Active Box connection via RUBEMANAGECONNECTIONS with toolkit box
- Always call RUBESEARCHTOOLS first to get current tool schemas
@ Setup
Get Rube MCP: Add https://rube.app/mcp as an MCP server in your client configuration. No API keys needed — just add the endpoint and it works.
- Verify Rube MCP is available by confirming RUBESEARCHTOOLS responds
- Call RUBEMANAGECONNECTIONS with toolkit box
- If connection is not ACTIVE, follow the returned auth link to complete Box OAuth
- Confirm connection status shows ACTIVE before running any workflows
@ Core Workflows
@ 1. Upload and Download Files
When to use: User wants to upload files to Box or download files from it
Tool sequence:
- BOXSEARCHFOR_CONTENT - Find the target folder if path is unknown [Prerequisite]
- BOXGETFOLDERINFORMATION - Verify folder exists and get folderid [Prerequisite]
- BOXLISTITEMSINFOLDER - Browse folder contents and discover file IDs [Optional]
- BOXUPLOADFILE - Upload a file to a specific folder [Required for upload]
- BOXDOWNLOADFILE - Download a file by file_id [Required for download]
- BOXCREATEZIP_DOWNLOAD - Bundle multiple files/folders into a zip [Optional]
Key parameters:
- parent_id: Folder ID for upload destination (use "0" for root folder)
- file: FileUploadable object with s3key, mimetype, and name for uploads
- file_id: Unique file identifier for downloads
- version: Optional file version ID for downloading specific versions
- fields: Comma-separated list of attributes to return
Pitfalls:
- Uploading to a folder with existing filenames can trigger conflict behavior; decide overwrite vs rename semantics
- Files over 50MB should use chunk upload APIs (not available via standard tools)
- The attributes part of upload must come before the file part or you get HTTP 400 with metadataafterfile_contents
- File IDs and folder IDs are numeric strings extractable from Box web app URLs (e.g., https://*.app.box.com/files/123 gives file_id "123")
@ 2. Search and Browse Content
When to use: User wants to find files, folders, or web links by name, content, or metadata
Tool sequence:
- BOXSEARCHFOR_CONTENT - Full-text search across files, folders, and web links [Required]
- BOXLISTITEMSINFOLDER - Browse contents of a specific folder [Optional]
- BOXGETFILE_INFORMATION - Get detailed metadata for a specific file [Optional]
- BOXGETFOLDER_INFORMATION - Get detailed metadata for a specific folder [Optional]
- BOXQUERYFILESFOLDERSBY_METADATA - Search by metadata template values [Optional]
- BOXLISTRECENTLYACCESSEDITEMS - List recently accessed items [Optional]
Key parameters:
- query: Search string supporting operators ("" exact match, AND, OR, NOT - uppercase only)
- type: Filter by "file", "folder", or "web_link"
- ancestorfolderids: Limit search to specific folders (comma-separated IDs)
- file_extensions: Filter by file type (comma-separated, no dots)
- contenttypes: Search in "name", "description", "filecontent", "comments", "tags"
- createdatrange / updatedatrange: Date filters as comma-separated RFC3339 timestamps
- limit: Results per page (default 30)
- offset: Pagination offset (max 10000)
- folderid: For LISTITEMSINFOLDER (use "0" for root)
Pitfalls:
- Queries with offset > 10000 are rejected with HTTP 400
- BOXSEARCHFOR_CONTENT requires either query or mdfilters parameter
- Misconfigured filters can silently omit expected items; validate with small test queries first
- Boolean operators (AND, OR, NOT) must be uppercase
- BOXLISTITEMSINFOLDER requires pagination via marker or offset/usemarker; partial listings are common
- Standard folders sort items by type first (folders before files before web links)
@ 3. Manage Folders
When to use: User wants to create, update, move, copy, or delete folders
Tool sequence:
- BOXGETFOLDER_INFORMATION - Verify folder exists and check permissions [Prerequisite]
- BOXCREATEFOLDER - Create a new folder [Required for create]
- BOXUPDATEFOLDER - Rename, move, or update folder settings [Required for update]
- BOXCOPYFOLDER - Copy a folder to a new location [Optional]
- BOXDELETEFOLDER - Move folder to trash [Required for delete]
- BOXPERMANENTLYREMOVE_FOLDER - Permanently delete a trashed folder [Optional]
Key parameters:
- name: Folder name (no /, , trailing spaces, or./..)
- parent__id: Parent folder ID (use "0" for root)
- folder_id: Target folder ID for operations
- parent.id: Destination folder ID for moves via BOXUPDATEFOLDER
- recursive: Set true to delete non-empty folders
- shared_link: Object with access, password, permissions for creating shared links on folders
- description, tags: Optional metadata fields
Pitfalls:
- BOXDELETEFOLDER moves to trash by default; use BOXPERMANENTLYREMOVE_FOLDER for permanent deletion
- Non-empty folders require recursive: true for deletion
- Root folder (ID "0") cannot be copied or deleted
- Folder names cannot contain /, , non-printable ASCII, or trailing spaces
- Moving folders requires setting parent.id via BOXUPDATEFOLDER
@ 4. Share Files and Manage Collaborations
When to use: User wants to share files, manage access, or handle collaborations
Tool sequence:
- BOXGETFILE_INFORMATION - Get file details and current sharing status [Prerequisite]
- BOXLISTFILE_COLLABORATIONS - List who has access to a file [Required]
- BOXUPDATECOLLABORATION - Change access level or accept/reject invitations [Required]
- BOXGETCOLLABORATION - Get details of a specific collaboration [Optional]
- BOXUPDATEFILE - Create shared links, lock files, or update permissions [Optional]
- BOXUPDATEFOLDER - Create shared links on folders [Optional]
Key parameters:
- collaboration_id: Unique collaboration identifier
- role: Access level ("editor", "viewer", "co-owner", "owner", "previewer", "uploader", "viewer uploader", "previewer uploader")
- status: "accepted", "pending", or "rejected" for collaboration invites
- file_id: File to share or manage
- lock__access: Set to "lock" to lock a file
- permissionscandownload: "company" or "open" for download permissions
Pitfalls:
- Only certain roles can invite collaborators; insufficient permissions cause authorization errors
- canviewpath increases load time for the invitee's "All Files" page; limit to 1000 per user
- Collaboration expiration requires enterprise admin settings to be enabled
- Nested parameter names use double underscores (e.g., lockaccess, parentid)
@ 5. Box Sign Requests
When to use: User wants to manage document signature requests
Tool sequence:
- BOXLISTBOXSIGNREQUESTS - List all signature requests [Required]
- BOXGETBOXSIGNREQUESTBYID - Get details of a specific sign request [Optional]
- BOXCANCELBOXSIGNREQUEST - Cancel a pending sign request [Optional]
Key parameters:
- signrequestid: UUID of the sign request
- shared_requests: Set true to include requests where user is a collaborator (not owner)
- senders: Filter by sender emails (requires shared_requests: true)
- limit / marker: Pagination parameters
Pitfalls:
- Requires Box Sign to be enabled for the enterprise account
- Deleted sign files or parent folders cause requests to not appear in listings
- Only the creator can cancel a sign request
- Sign request statuses include: converting, created, sent, viewed, signed, declined, cancelled, expired, errorconverting, errorsending
@ Common Patterns
@ ID Resolution
Box uses numeric string IDs for all entities:
- Root folder: Always ID "0"
- File ID from URL: https://*.app.box.com/files/123 gives file_id "123"
- Folder ID from URL: https://*.app.box.com/folder/123 gives folder_id "123"
- Search to ID: Use BOXSEARCHFOR_CONTENT to find items, then extract IDs from results
- ETag: Use if_match with file's ETag for safe concurrent delete operations
@ Pagination
Box supports two pagination methods:
- Offset-based: Use offset + limit (max offset 10000)
- Marker-based: Set usemarker: true and follow marker from responses (preferred for large datasets)
- Always paginate to completion to avoid partial results
@ Nested Parameters
Box tools use double underscore notation for nested objects:
- parent__id for parent folder reference
- lockaccess, lockexpiresat, lockisdownloadprevented for file locks
- permissionscandownload for download permissions
@ Known Pitfalls
@ ID Formats
- All IDs are numeric strings (e.g., "123456", not integers)
- Root folder is always "0"
- File and folder IDs can be extracted from Box web app URLs
@ Rate Limits
- Box API has per-endpoint rate limits
- Search and list operations should use pagination responsibly
- Bulk operations should include delays between requests
@ Parameter Quirks
- fields parameter changes response shape: when specified, only mini representation + requested fields are returned
- Search requires either query or mdfilters; both are optional individually but one must be present
- BOXUPDATEFILE with lock set to null removes the lock (raw API only)
- Metadata query from field format: enterprise{enterpriseid}.templateKey or global.templateKey
@ Permissions
- Deletions fail without sufficient permissions; always handle error responses
- Collaboration roles determine what operations are allowed
- Enterprise settings may restrict certain sharing options
@ Quick Reference
Task; Tool Slug; Key Params
Search content; BOXSEARCHFORCONTENT; query, type, ancestorfolder_ids
List folder items; BOXLISTITEMSINFOLDER; folder_id, limit, marker
Get file info; BOXGETFILEINFORMATION; fileid, fields
Get folder info; BOXGETFOLDERINFORMATION; folderid, fields
Upload file; BOXUPLOADFILE; file, parent_id
Download file; BOXDOWNLOADFILE; file_id
Create folder; BOXCREATEFOLDER; name, parent__id
Update folder; BOXUPDATEFOLDER; folder_id, name, parent
Copy folder; BOXCOPYFOLDER; folderid, parent_id
Delete folder; BOXDELETEFOLDER; folder_id, recursive
Permanently delete folder; BOXPERMANENTLYREMOVEFOLDER; folderid
Update file; BOXUPDATEFILE; fileid, name, parent_id
Delete file; BOXDELETEFILE; fileid, ifmatch
List collaborations; BOXLISTFILECOLLABORATIONS; fileid
Update collaboration; BOXUPDATECOLLABORATION; collaboration_id, role
Get collaboration; BOXGETCOLLABORATION; collaboration_id
Query by metadata; BOXQUERYFILESFOLDERSBYMETADATA; from, ancestorfolder_id, query
List collections; BOXLISTALL_COLLECTIONS; (none)
List collection items; BOXLISTCOLLECTIONITEMS; collectionid
List sign requests; BOXLISTBOXSIGNREQUESTS; limit, marker
Get sign request; BOXGETBOXSIGNREQUESTBYID; signrequestid
Cancel sign request; BOXCANCELBOXSIGNREQUEST; signrequestid
Recent items; BOXLISTRECENTLYACCESSEDITEMS; (none)
Create zip download; BOXCREATEZIP_DOWNLOAD; item IDs
@ When to Use
This skill is applicable to execute the workflow or actions described in the overview.
@ Limitations
- Use this skill only when the task clearly matches the scope described above.
- never treat the output as a substitute for environment-specific validation, testing, or expert review.
- Stop and ask for clarification if required inputs, permissions, safety boundaries, or success criteria are missing.