Box

Box Web Links API

Web links are objects that point to URLs. These objects are also known as bookmarks within the Box web application.

Operations 4

POST /web_links Box Create web link #

Documentation

📖
Documentation
https://developer.box.com/reference/get-authorize
📖
Documentation
https://developer.box.com/reference/post-oauth2-token
📖
Documentation
https://developer.box.com/reference/post-files-id-copy
📖
Documentation
https://developer.box.com/reference/post-file-requests-id-copy
📖
Documentation
https://developer.box.com/reference/post-folders-id-copy
📖
Documentation
https://developer.box.com/reference/post-folder-locks
📖
Documentation
https://developer.box.com/reference/post-metadata-templates-schema
📖
Documentation
https://developer.box.com/reference/post-metadata-cascade-policies
📖
Documentation
https://developer.box.com/reference/post-metadata-queries-execute-read
📖
Documentation
https://developer.box.com/reference/post-comments
📖
Documentation
https://developer.box.com/reference/post-collaborations
📖
Documentation
https://developer.box.com/reference/post-tasks
📖
Documentation
https://developer.box.com/reference/post-task-assignments
📖
Documentation
https://developer.box.com/reference/put-files-id--add-shared-link
📖
Documentation
https://developer.box.com/reference/put-folders-id--add-shared-link
📖
Documentation
https://developer.box.com/reference/post-web-links
📖
Documentation
https://developer.box.com/reference/put-web-links-id--add-shared-link
📖
Documentation
https://developer.box.com/reference/post-users
📖
Documentation
https://developer.box.com/reference/post-invites
📖
Documentation
https://developer.box.com/reference/post-groups
📖
Documentation
https://developer.box.com/reference/post-group-memberships
📖
Documentation
https://developer.box.com/reference/post-webhooks
📖
Documentation
https://developer.box.com/reference/post-files-id-metadata-global-boxSkillsCards
📖
Documentation
https://developer.box.com/reference/options-events
📖
Documentation
https://developer.box.com/reference/get-collections-id
📖
Documentation
https://developer.box.com/reference/get-recent-items
📖
Documentation
https://developer.box.com/reference/post-retention-policies
📖
Documentation
https://developer.box.com/reference/post-retention-policy-assignments
📖
Documentation
https://developer.box.com/reference/post-legal-hold-policies
📖
Documentation
https://developer.box.com/reference/post-legal-hold-policy-assignments
📖
Documentation
https://developer.box.com/reference/get-file-version-retentions-id
📖
Documentation
https://developer.box.com/reference/get-file-version-legal-holds-id
📖
Documentation
https://developer.box.com/reference/post-shield-information-barriers-change-status
📖
Documentation
https://developer.box.com/reference/post-shield-information-barrier-reports
📖
Documentation
https://developer.box.com/reference/post-shield-information-barrier-segments
📖
Documentation
https://developer.box.com/reference/post-shield-information-barrier-segment-members
📖
Documentation
https://developer.box.com/reference/post-shield-information-barrier-segment-restrictions
📖
Documentation
https://developer.box.com/reference/get-device-pinners-id
📖
Documentation
https://developer.box.com/reference/post-terms-of-services
📖
Documentation
https://developer.box.com/reference/post-terms-of-service-user-statuses
📖
Documentation
https://developer.box.com/reference/post-collaboration-whitelist-entries
📖
Documentation
https://developer.box.com/

Specifications

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/box-web-links-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

box-web-links-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Box Platform Web Links API
  description: Box Platform provides functionality to provide access to content stored within Box. It provides endpoints for basic manipulation of files and folders, management of users within an enterprise, as well as more complex topics such as legal holds and retention policies.
  termsOfService: https://cloud.app.box.com/s/rmwxu64h1ipr41u49w3bbuvbsa29wku9
  contact:
    name: Box, Inc
    url: https://box.dev
    email: devrel@box.com
  license:
    name: Apache-2.0
    url: http://www.apache.org/licenses/LICENSE-2.0
  version: 2.0.0
  x-box-commit-hash: '5819125043'
servers:
- url: https://api.box.com/2.0
  description: Box Platform API server
security:
- OAuth2Security: []
tags:
- name: Web Links
  description: 'Web links are objects that point to URLs.

    These objects are also known as bookmarks

    within the Box web application.'
  x-box-tag: web_links
paths:
  /web_links:
    post:
      operationId: post_web_links
      summary: Box Create web link
      tags:
      - Web Links
      x-box-tag: web_links
      description: Creates a web link object within a folder.
      requestBody:
        content:
          application/json:
            schema:
              type: object
              required:
              - parent
              - url
              properties:
                url:
                  type: string
                  example: https://box.com
                  description: 'The URL that this web link links to. Must start with

                    `"http://"` or `"https://"`.'
                parent:
                  type: object
                  description: The parent folder to create the web link within.
                  required:
                  - id
                  properties:
                    id:
                      type: string
                      description: The ID of parent folder
                      example: '0'
                name:
                  type: string
                  example: Box Website
                  description: Name of the web link. Defaults to the URL if not set.
                description:
                  type: string
                  example: Cloud Content Management
                  description: Description of the web link.
      responses:
        '200':
          description: Returns the newly created web link object.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WebLink'
        default:
          description: An unexpected client error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ClientError'
  /web_links/{web_link_id}:
    get:
      operationId: get_web_links_id
      summary: Box Get web link
      tags:
      - Web Links
      x-box-tag: web_links
      description: Retrieve information about a web link.
      parameters:
      - name: web_link_id
        description: The ID of the web link.
        example: '12345'
        in: path
        required: true
        schema:
          type: string
      - name: boxapi
        description: 'The URL, and optional password, for the shared link of this item.


          This header can be used to access items that have not been

          explicitly shared with a user.


          Use the format `shared_link=[link]` or if a password is required then

          use `shared_link=[link]&shared_link_password=[password]`.


          This header can be used on the file or folder shared, as well as on any files

          or folders nested within the item.'
        example: shared_link=[link]&shared_link_password=[password]
        in: header
        required: false
        schema:
          type: string
      responses:
        '200':
          description: Returns the web link object.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WebLink'
        default:
          description: An unexpected client error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ClientError'
    put:
      operationId: put_web_links_id
      summary: Box Update web link
      tags:
      - Web Links
      x-box-tag: web_links
      description: Updates a web link object.
      parameters:
      - name: web_link_id
        description: The ID of the web link.
        example: '12345'
        in: path
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                url:
                  type: string
                  example: https://box.com
                  description: 'The new URL that the web link links to. Must start with

                    `"http://"` or `"https://"`.'
                parent:
                  allOf:
                  - type: object
                    description: The parent for this item
                    properties:
                      id:
                        type: string
                        description: The ID of parent item
                        example: '123'
                  - description: 'The new parent folder to put the web link in.

                      Use this to move the web link to a different folder.'
                name:
                  type: string
                  example: Box Website
                  description: A new name for the web link. Defaults to the URL if not set.
                description:
                  type: string
                  example: Cloud Content Management
                  description: A new description of the web link.
                shared_link:
                  description: The settings for the shared link to update.
                  type: object
                  properties:
                    access:
                      type: string
                      description: 'The level of access for the shared link. This can be

                        restricted to anyone with the link (`open`), only people

                        within the company (`company`) and only those who

                        have been invited to the folder (`collaborators`).


                        If not set, this field defaults to the access level specified

                        by the enterprise admin. To create a shared link with this

                        default setting pass the `shared_link` object with

                        no `access` field, for example `{ "shared_link": {} }`.


                        The `company` access level is only available to paid

                        accounts.'
                      enum:
                      - open
                      - company
                      - collaborators
                      example: open
                    password:
                      type: string
                      description: 'The password required to access the shared link. Set the

                        password to `null` to remove it.

                        Passwords must now be at least eight characters

                        long and include a number, upper case letter, or

                        a non-numeric or non-alphabetic character.

                        A password can only be set when `access` is set to `open`.'
                      example: do-not-use-this-password
                    vanity_name:
                      type: string
                      description: 'Defines a custom vanity name to use in the shared link URL,

                        for example `https://app.box.com/v/my-shared-link`.


                        Custom URLs should not be used when sharing sensitive content

                        as vanity URLs are a lot easier to guess than regular shared

                        links.'
                      minLength: 12
                      example: my-shared-link
                    unshared_at:
                      type: string
                      format: date-time
                      example: '2012-12-12T10:53:43-08:00'
                      description: 'The timestamp at which this shared link will

                        expire. This field can only be set by

                        users with paid accounts. The value must be greater than the

                        current date and time.'
      responses:
        '200':
          description: Returns the updated web link object.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WebLink'
        default:
          description: An unexpected client error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ClientError'
    delete:
      operationId: delete_web_links_id
      summary: Box Remove web link
      tags:
      - Web Links
      x-box-tag: web_links
      description: Deletes a web link.
      parameters:
      - name: web_link_id
        description: The ID of the web link.
        example: '12345'
        in: path
        required: true
        schema:
          type: string
      responses:
        '204':
          description: 'An empty response will be returned when the web link

            was successfully deleted.'
        default:
          description: An unexpected client error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ClientError'
components:
  schemas:
    User--Mini:
      title: User (Mini)
      type: object
      x-box-resource-id: user--mini
      x-box-variant: mini
      description: 'A mini representation of a user, as can be returned when nested within other

        resources.'
      allOf:
      - $ref: '#/components/schemas/User--Base'
      - properties:
          name:
            type: string
            description: The display name of this user
            example: Aaron Levie
            maxLength: 50
          login:
            type: string
            format: email
            description: The primary email address of this user
            example: ceo@example.com
    ClientError:
      title: Client error
      type: object
      x-box-resource-id: client_error
      description: A generic error
      properties:
        type:
          description: error
          example: error
          type: string
          enum:
          - error
        status:
          description: The HTTP status of the response.
          example: 400
          type: integer
          format: int32
        code:
          description: A Box-specific error code
          example: item_name_invalid
          type: string
          enum:
          - created
          - accepted
          - no_content
          - redirect
          - not_modified
          - bad_request
          - unauthorized
          - forbidden
          - not_found
          - method_not_allowed
          - conflict
          - precondition_failed
          - too_many_requests
          - internal_server_error
          - unavailable
          - item_name_invalid
          - insufficient_scope
        message:
          description: A short message describing the error.
          example: Method Not Allowed
          type: string
        context_info:
          description: 'A free-form object that contains additional context

            about the error. The possible fields are defined on

            a per-endpoint basis. `message` is only one example.'
          type:
          - object
          - 'null'
          properties:
            message:
              type: string
              description: More details on the error.
              example: Something went wrong.
        help_url:
          description: A URL that links to more information about why this error occurred.
          example: https://developer.box.com/guides/api-calls/permissions-and-errors/common-errors/
          type: string
        request_id:
          description: 'A unique identifier for this response, which can be used

            when contacting Box support.'
          type: string
          example: abcdef123456
    Folder--Mini:
      title: Folder (Mini)
      type: object
      x-box-resource-id: folder--mini
      x-box-variant: mini
      description: 'A mini representation of a file version, used when

        nested under another resource.'
      allOf:
      - $ref: '#/components/schemas/Folder--Base'
      - properties:
          sequence_id:
            allOf:
            - type:
              - string
              - 'null'
              example: '3'
              description: 'A numeric identifier that represents the most recent user event

                that has been applied to this item.


                This can be used in combination with the `GET /events`-endpoint

                to filter out user events that would have occurred before this

                identifier was read.


                An example would be where a Box Drive-like application

                would fetch an item via the API, and then listen to incoming

                user events for changes to the item. The application would

                ignore any user events where the `sequence_id` in the event

                is smaller than or equal to the `sequence_id` in the originally

                fetched resource.'
            - {}
          name:
            type: string
            description: The name of the folder.
            example: Contracts
    WebLink:
      title: Web link
      type: object
      x-box-resource-id: web_link
      x-box-variant: standard
      description: 'Web links are objects that point to URLs. These objects

        are also known as bookmarks within the Box web application.


        Web link objects are treated similarly to file objects,

        they will also support most actions that apply to regular files.'
      allOf:
      - $ref: '#/components/schemas/WebLink--Mini'
      - properties:
          parent:
            allOf:
            - $ref: '#/components/schemas/Folder--Mini'
            - description: The parent object the web link belongs to
          description:
            type: string
            example: Example page
            description: 'The description accompanying the web link. This is

              visible within the Box web application.'
          path_collection:
            allOf:
            - title: Path collection
              description: A list of parent folders for an item.
              type: object
              required:
              - total_count
              - entries
              properties:
                total_count:
                  description: The number of folders in this list.
                  example: 1
                  type: integer
                  format: int64
                entries:
                  type: array
                  description: The parent folders for this item
                  items:
                    $ref: '#/components/schemas/Folder--Mini'
            - description: 'The tree of folders that this web link is contained in,

                starting at the root.'
            - {}
          created_at:
            type: string
            format: date-time
            description: When this file was created on Box’s servers.
            example: '2012-12-12T10:53:43-08:00'
          modified_at:
            type: string
            format: date-time
            description: 'When this file was last updated on the Box

              servers.'
            example: '2012-12-12T10:53:43-08:00'
          trashed_at:
            type:
            - string
            - 'null'
            format: date-time
            description: When this file was moved to the trash.
            example: '2012-12-12T10:53:43-08:00'
          purged_at:
            type:
            - string
            - 'null'
            format: date-time
            description: When this file will be permanently deleted.
            example: '2012-12-12T10:53:43-08:00'
          created_by:
            allOf:
            - $ref: '#/components/schemas/User--Mini'
            - description: The user who created this web link
          modified_by:
            allOf:
            - $ref: '#/components/schemas/User--Mini'
            - description: The user who last modified this web link
          owned_by:
            allOf:
            - $ref: '#/components/schemas/User--Mini'
            - description: The user who owns this web link
          shared_link:
            allOf:
            - title: Shared link
              description: 'Shared links provide direct, read-only access to files or folder on Box.


                Shared links with open access level allow anyone with the URL

                to access the item, while shared links with company or collaborators access

                levels can only be accessed by appropriately authenticated Box users.'
              type: object
              required:
              - url
              - accessed
              - effective_access
              - effective_permission
              - is_password_enabled
              - download_count
              - preview_count
              properties:
                url:
                  type: string
                  format: url
                  description: 'The URL that can be used to access the item on Box.


                    This URL will display the item in Box''s preview UI where the file

                    can be downloaded if allowed.


                    This URL will continue to work even when a custom `vanity_url`

                    has been set for this shared link.'
                  example: https://www.box.com/s/vspke7y05sb214wjokpk
                download_url:
                  type:
                  - string
                  - 'null'
                  format: url
                  x-box-premium-feature: true
                  description: 'A URL that can be used to download the file. This URL can be used in

                    a browser to download the file. This URL includes the file

                    extension so that the file will be saved with the right file type.


                    This property will be `null` for folders.'
                  example: https://www.box.com/shared/static/rh935iit6ewrmw0unyul.jpeg
                vanity_url:
                  type:
                  - string
                  - 'null'
                  format: url
                  description: 'The "Custom URL" that can also be used to preview the item on Box.  Custom

                    URLs can only be created or modified in the Box Web application.'
                  example: https://acme.app.box.com/v/my_url/
                vanity_name:
                  type:
                  - string
                  - 'null'
                  description: The custom name of a shared link, as used in the `vanity_url` field.
                  example: my_url
                access:
                  type: string
                  description: "The access level for this shared link.\n\n* `open` - provides access to this item to anyone with this link\n* `company` - only provides access to this item to people the same company\n* `collaborators` - only provides access to this item to people who are\n   collaborators on this item\n\nIf this field is omitted when creating the shared link, the access level\nwill be set to the default access level specified by the enterprise admin."
                  enum:
                  - open
                  - company
                  - collaborators
                  example: open
                effective_access:
                  type: string
                  description: 'The effective access level for the shared link. This can be a more

                    restrictive access level than the value in the `access` field when the

                    enterprise settings restrict the allowed access levels.'
                  enum:
                  - open
                  - company
                  - collaborators
                  example: company
                effective_permission:
                  type: string
                  description: 'The effective permissions for this shared link.

                    These result in the more restrictive combination of

                    the share link permissions and the item permissions set

                    by the administrator, the owner, and any ancestor item

                    such as a folder.'
                  enum:
                  - can_edit
                  - can_download
                  - can_preview
                  - no_access
                  example: can_download
                unshared_at:
                  type:
                  - string
                  - 'null'
                  format: date-time
                  description: 'The date and time when this link will be unshared. This field can only be

                    set by users with paid accounts.'
                  example: '2018-04-13T13:53:23-07:00'
                is_password_enabled:
                  type: boolean
                  description: Defines if the shared link requires a password to access the item.
                  example: true
                permissions:
                  type: object
                  description: 'Defines if this link allows a user to preview, edit, and download an item.

                    These permissions refer to the shared link only and

                    do not supersede permissions applied to the item itself.'
                  required:
                  - can_download
                  - can_preview
                  - can_edit
                  properties:
                    can_download:
                      type: boolean
                      example: true
                      description: 'Defines if the shared link allows for the item to be downloaded. For

                        shared links on folders, this also applies to any items in the folder.


                        This value can be set to `true` when the effective access level is

                        set to `open` or `company`, not `collaborators`.'
                    can_preview:
                      type: boolean
                      example: true
                      description: 'Defines if the shared link allows for the item to be previewed.


                        This value is always `true`. For shared links on folders this also

                        applies to any items in the folder.'
                    can_edit:
                      type: boolean
                      example: false
                      description: 'Defines if the shared link allows for the item to be edited.


                        This value can only be `true` if `can_download` is also `true` and if

                        the item has a type of `file`.'
                download_count:
                  type: integer
                  example: 3
                  description: The number of times this item has been downloaded.
                preview_count:
                  type: integer
                  example: 3
                  description: The number of times this item has been previewed.
            - description: 'The shared link object for this item. Will be

                `null` if no shared link has been created.'
            - {}
          item_status:
            type: string
            example: active
            enum:
            - active
            - trashed
            - deleted
            description: 'Whether this item is deleted or not. Values include `active`,

              `trashed` if the file has been moved to the trash, and `deleted` if

              the file has been permanently deleted'
    WebLink--Mini:
      title: Web link (Mini)
      type: object
      x-box-resource-id: web_link--mini
      x-box-variant: mini
      description: 'Web links are objects that point to URLs. These objects

        are also known as bookmarks within the Box web application.


        Web link objects are treated similarly to file objects,

        they will also support most actions that apply to regular files.'
      allOf:
      - $ref: '#/components/schemas/WebLink--Base'
      - properties:
          url:
            type: string
            example: https://www.example.com/example/1234
            description: The URL this web link points to
          sequence_id:
            allOf:
            - type:
              - string
              - 'null'
              example: '3'
              description: 'A numeric identifier that represents the most recent user event

                that has been applied to this item.


                This can be used in combination with the `GET /events`-endpoint

                to filter out user events that would have occurred before this

                identifier was read.


                An example would be where a Box Drive-like application

                would fetch an item via the API, and then listen to incoming

                user events for changes to the item. The application would

                ignore any user events where the `sequence_id` in the event

                is smaller than or equal to the `sequence_id` in the originally

                fetched resource.'
            - {}
          name:
            type: string
            description: The name of the web link
            example: My Bookmark
    WebLink--Base:
      title: Web link (Base)
      type: object
      x-box-resource-id: web_link--base
      x-box-tag: web_links
      x-box-variants:
      - base
      - mini
      - standard
      x-box-variant: base
      description: 'Web links are objects that point to URLs. These objects

        are also known as bookmarks within the Box web application.


        Web link objects are treated similarly to file objects,

        they will also support most actions that apply to regular files.'
      required:
      - id
      - type
      properties:
        id:
          type: string
          description: The unique identifier for this web link
          example: '11446498'
        type:
          type: string
          description: '`web_link`'
          example: web_link
          enum:
          - web_link
        etag:
          type: string
          example: '1'
          description: 'The entity tag of this web link. Used with `If-Match`

            headers.'
    User--Base:
      title: User (Base)
      type: object
      x-box-resource-id: user--base
      x-box-tag: users
      x-box-variants:
      - base
      - mini
      - standard
      - full
      x-box-variant: base
      description: 'A mini representation of a user, used when

        nested within another resource.'
      required:
      - type
      - id
      properties:
        id:
          type: string
          description: The unique identifier for this user
          example: '11446498'
        type:
          type: string
          description: '`user`'
          example: user
          enum:
          - user
    Folder--Base:
      title: Folder (Base)
      type: object
      x-box-resource-id: folder--base
      x-box-sanitized: true
      x-box-tag: folders
      x-box-variants:
      - base
      - mini
      - standard
      - full
      x-box-variant: base
      description: 'The bare basic representation of a folder, the minimal

        amount of fields returned when using the `fields` query

        parameter.'
      required:
      - id
      - type
      properties:
        id:
          type: string
          description: 'The unique identifier that represent a folder.


            The ID for any folder can be determined

            by visiting a folder in the web application

            and copying the ID from the URL. For example,

            for the URL `https://*.app.box.com/folders/123`

            the `folder_id` is `123`.'
          example: '12345'
        etag:
          type:
          - string
          - 'null'
          example: '1'
          description: 'The HTTP `etag` of this folder. This can be used within some API

            endpoints in the `If-Match` and `If-None-Match` headers to only

            perform changes on the folder if (no) changes have happened.'
        type:
          type: string
          description: '`folder`'
          example: folder
          enum:
          - folder
  securitySchemes:
    OAuth2Security:
      type: oauth2
      flows:
        authorizationCode:
          authorizationUrl: https://account.box.com/api/oauth2/authorize
          tokenUrl: https://api.box.com/oauth2/token
          scopes:
            root_readonly: Read all files and folders stored in Box
            root_readwrite: Read and write all files and folders stored in Box
            manage_app_users: Provision and manage app users
            manage_managed_users: Provision and manage managed users
            manage_groups: Manage an enterprise's groups
            manage_webhook: Create webhooks programmatically through the API
            manage_enterprise_properties: Manage enterprise properties
            manage_data_retention: Manage data retention polices
            manage_legal_hold: Manage Legal Holds
externalDocs:
  description: Box Developer Documentation
  url: https://developer.box.com