Skip to main content
9 – 17 UHR +49 8031 3508270 LUITPOLDSTR. 9, 83022 ROSENHEIM
DE / EN
CompanyGPT Integration MCP server: streamable HTTP

Use Box with AI via MCP

For many organizations, Box is where contracts, proposals and project records live – usually with finely graded permissions. The official MCP server at `mcp.box.com` lets AI agents in CompanyGPT work with exactly that content without bypassing the existing rights model.

What is Box?

Box is a content cloud for enterprises: file storage, versioning, sharing, comments, retention rules and approval workflows in one platform. Its focus has always been governance – permissions, classification and traceability are more pronounced than in pure storage services, which is why Box is common in regulated industries.

That makes Box a particularly controllable document source for AI agents. Contracts, tenders, minutes or technical documentation can be searched and analysed on demand – and because permissions travel with the file, governance stays intact even when an assistant does the research.

Connection at a Glance

MCP server
Official, Box-hosted remote MCP server
Endpoint
mcp.box.com
Transport
Streamable HTTP
Prerequisite
Box admin enables MCP in the Admin Console; integration credentials for your own clients
Authentication
OAuth 2.0 with your own Box account
Operating model
SaaS
Permissions
Box sharing and classification remain authoritative

How to Connect Box to CompanyGPT

Box provides an official, Box-hosted remote MCP server at mcp.box.com. The connection uses streamable HTTP, and CompanyGPT calls the endpoint directly from your own cloud tenant.

One prerequisite sits on your side: a Box admin has to enable MCP in the Admin Console. For your own clients they also create integration credentials there – client ID and client secret, redirect URI and the required scopes.

Authentication runs through OAuth 2.0 with the individual user’s Box account. Folder and file permissions, collaboration roles and classifications from Box therefore continue to apply unchanged: an agent sees nothing the signed-in employee could not open anyway.

On top of that, your CompanyGPT administrators use roles and groups to control which departments may use the Box integration at all. Where documents are meant to serve as a permanent knowledge base, the connection can be combined with companyRAG – live research over MCP works independently of that.

Typical Use Cases

How AI agents in CompanyGPT work with Box

Open up contract archives

Legal asks about notice periods or liability clauses in filed contracts and gets an answer that points to the specific document.

Prepare proposals faster

Ahead of a new tender, the agent finds comparable earlier proposals in Box and summarizes their scope and structure.

Consolidate project records

For a project handover, the assistant condenses minutes, specifications and status reports from a Box folder into one handover document.

Frequently Asked Questions

Box and AI – the most important answers

Is there an official MCP server for Box?

Yes. Box runs an official, Box-hosted remote MCP server at mcp.box.com, connected via streamable HTTP. No server installation of your own is required; a Box admin does, however, have to enable MCP in the Admin Console and create integration credentials for your own clients.

Do our Box permissions still apply?

Yes. Sign-in uses OAuth 2.0 with each user's own account. Folder sharing, collaboration roles and classifications from Box apply unchanged – an agent cannot open content the user has no access to.

Are files copied for AI use?

Not for the MCP connection: the agent accesses content at runtime. Indexing only enters the picture if you deliberately want documents to serve as a permanent knowledge base via companyRAG – that remains your decision.

Can the AI store or modify files in Box?

The available tools are defined by the Box MCP server. In CompanyGPT your administrators decide per agent which of them are enabled – for example search and read operations only.

How does this fit our compliance requirements?

CompanyGPT runs as an isolated instance in your cloud tenant and communicates directly with the Box endpoint. Access happens under the individual user account and stays traceable in Box; your existing contracts and retention rules remain untouched.

Related Integrations

Files & Cloud Storage

Box and Your AI – GDPR-Compliant with CompanyGPT

CompanyGPT is the enterprise AI assistant in your own cloud tenant: all relevant AI models, your company data and integrations like Box – centrally managed, with roles and permissions. We set up the connection together with you.

Box is a trademark of its respective owner (Box, Inc.). Its mention describes compatibility and does not imply any partnership or endorsement. Availability and scope of the connection depend on the respective vendor.