Skip to main content
provider: "box" · Import and export · Preview validation Connect a user’s existing Box account, browse folders they can access, and import a selected folder into a vault. Box uses the same connection, transfer, sync, activity, reconnection, and disconnect APIs as Clio.
Box is available only when enabled for the environment and organization. Discover availability from GET /connectors/v1/connections; do not hardcode a connect button. The only supported scope tier is box.readwrite (root_readwrite at Box).

Browsing

A browse request without parameters returns All Files, with folder id 0 and the authenticated Box user id as container_id. Choose that root or descend into owned, shared, and collaborated folders visible to the account. Stable ids survive renames and moves.
Root browse response
Page children with the returned cursor. Box uses marker pagination; callers treat cursors as opaque.

Import, export, and two-way sync

One-time import request: POST /connectors/v1/transfer
Use POST /connectors/v1/sync-link for scheduled synchronization. As with Clio, direction: "both" creates paired import and export links. Exports use a separate destination under the selected root unless an explicit destination is provided. Imported objects are excluded from export, and the export destination is excluded from import to prevent echoes. The console uses the shared Import from… flow: connect Box, select a folder, select or create a vault, and optionally enable document sync. Box exposes only the documents collection; Clio-specific communications and tasks are not Box resources.

Change detection and recovery

The initial scan captures Box’s user-event position before walking the folder tree. Large scans save page progress and continue in another durable workflow step. Transfers resume from the saved snapshot rather than re-enumerating a changing folder. Subsequent runs consume the user changes feed, deduplicate events, and resolve each changed file’s current ancestry. Structural folder changes, collaboration changes, inaccessible ancestry, and rejected or expired cursors trigger a complete reconciliation. The shared scheduled reconciliation remains the backstop. Rename and move changes update path metadata without downloading unchanged content. Content identity uses the Box SHA-1 and file-version id.

Collision policies and crash recovery

Export never deletes Box content. If an upload succeeds but its response is lost, retries inspect the bounded destination folder and stable file/version identities. An ambiguous result halts with adoption_ambiguous instead of uploading again, including when the Vault source changed during the retry. Small uploads stream directly. Known sizes above 50 MiB use chunked upload sessions with SHA-1 part digests. The user’s maximum upload size is checked before uploading whenever the source size is known. Long download-readiness and pending-commit waits defer to the durable workflow. Chunked uploads persist their session, uploaded parts, digest, and commit result in the shared per-object recovery checkpoint. Retries commit the same session after Box’s retry deadline. A lost commit response or changed source fails closed as ambiguous; it never starts another session to bypass an unresolved upload.

Supported content

Ordinary files are ingested. Box Notes and web links become typed skipped results; native content is never silently treated as a document. Folder-depth, page, item, byte, and stream-idle limits bound traversal and transfers.

Reconnection and enterprise enablement

Box refresh tokens are single-use and rotate after each refresh. The shared token service checkpoints rotation under its refresh lease before downscoping. Invalid or expired refresh tokens move the connection to reauth_required; reconnect through the same hosted OAuth flow used by Clio.
Some enterprises block unpublished applications. Their administrator must enable the app using its Client ID before users can authorize it. Marketplace publication is optional for direct OAuth rollout. Reconnect after app scope changes.
Box does not use service accounts, JWT, enterprise impersonation, or as-user access.

Capabilities at a glance

See Import & Export for policies and activity, and Errors & Recovery for retry and reauthorization handling.