Box Connector

Index files, folders, comments, tasks, and web links in Box, along with the users and groups that control access to them.

The Box connector indexes files, folders, comments, tasks, and web links in Box, along with the users and groups that define who can access them.

Setup takes three steps:

  1. Create the Box app.
  2. Authorize it for your enterprise.
  3. Provide the connector its credentials.

Create the Box Application

Create a Custom App using Server Authentication (Client Credentials Grant) in the Box Developer Console (admin or co-admin account). In the app’s Configuration tab:

  • App Access Level: App + Enterprise Access — required to enumerate and impersonate managed users and groups.
  • Application Scopes: Read all files and folders stored in Box; Manage users; Manage groups; Manage enterprise properties.
  • Advanced Features: Generate user access tokens; Make API calls using the as-user header.

Save changes.

Authorize the Application

A CCG app cannot call the API until an admin authorizes it: in the Box Admin Console → Apps → Custom Apps Manager, add/authorize the app by its Client ID and confirm the scopes. Until then the connection test fails with an authorization error.

Credentials

CredentialWhere to find it
Client IDApp Configuration → OAuth 2.0 Credentials
Client SecretApp Configuration → OAuth 2.0 Credentials (Fetch/Reveal)
Enterprise IDBox Admin Console → Account & Billing → Account Info

Provide Configuration

Only the three credentials are required; every other field has a safe default.

connector: box
instance: default
source: box
common:
  enabled: true
configuration:
  client_id:
    value: "<your-client-id>"
  client_secret:
    value: "<your-client-secret>"
  enterprise_id:
    value: "<your-enterprise-id>"
ParameterTypeRequiredDefaultDescription
client_idsecretYes—CCG application client ID.
client_secretsecretYes—CCG application client secret.
enterprise_idsecretYes—Box enterprise (account) ID the app is authorized for.
base_urlstringNohttps://api.box.com/2.0Overrides the Box API base URL.
token_urlstringNohttps://api.box.com/oauth2/tokenOverrides the OAuth2 CCG token endpoint.
per_user_rpmintegerNo500Requests-per-minute cap per impersonated user (0 = default).
per_user_burstintegerNo5Per-user rate-limiter burst size (0 = default).
page_sizeintegerNo100Page size for list calls (Box caps most endpoints at 1000).
backfill_concurrencyintegerNo10Async (one-per-user) workers used during backfill.
reconcile_concurrencyintegerNo10Async workers handling pollable, retriable reconciliation tasks.
cache_sizeintegerNo100000Bounds the shared cache size for user->group, ACL and other mappings.
cache_ttl_hoursintegerNo48How long an entry stays valid in the ACL and root-owner caches before expiring and being re-resolved from the Box API.
event_poll_interval_secondsintegerNo1800How often Stream() polls the Box admin event log.
event_batch_size_maxintegerNo1000Caps the number of events processed per Stream() poll window.
stream_start_offset_secondsintegerNo3600How far back Stream() begins on first run, when no streaming checkpoint exists yet.
event_processing_delayintegerNo300Holds each Stream() poll window back from “now” by this many seconds, giving the admin event log time to settle before it’s read.
backfill_start_datestringNo1900-01-01Lower bound of the backfill window. Accepts an RFC3339 timestamp (2024-06-01T00:00:00Z) or a bare date (2024-06-01).
backfill_end_datestringNoNowUpper bound of that same window. Same accepted formats; empty leaves the window open-ended.
resourcesmapNo{}Per-resource include/exclude filters (see below).

Note: Leave the rate-limit, concurrency, cache, and event-polling knobs at their defaults unless tuning throughput, memory, event latency, or responding to 429 pressure.

Note: The backfill window only scopes what backfill emits — it does not limit Stream(), which always processes new events as they arrive.

Filtering Indexed Resources

By default everything reachable is indexed. To narrow scope, map a resource key to an included (allowlist) and/or excluded (blocklist).

configuration:
  # ... credentials ...
  resources:
    user:
      excluded:
        - svc-indexer@example.com
    acl_group:
      included:
        - "engineering"
        - "admins"

Semantics: no filters → index all; included → only listed entries; excluded → all but listed entries; both → included minus excluded (exclude wins). Match values are compared for exact equality.

Match values are the native Box identifiers (not Atolio xIDs), since filtering happens during enumeration before any xID is assigned:

Resource keyMatch value
userThe user’s Box login / email
acl_groupThe Box group Name

Filters are enforced for the identity resources (user, acl_group), which are backfilled first because the rest of the connector’s ACLs depend on them.

Indexed Resources

ResourceDisplay nameDescription
userBox UserEnterprise users; resolve ACLs and content ownership.
acl_groupBox GroupManaged groups and their members, used in ACLs.
fileBox FileFiles, including extracted text content.
folderBox FolderFolders and their collaboration-derived ACLs.
commentBox CommentComments attached to files.
taskBox TaskTasks attached to files.
web_linkBox Web LinkBookmarks / web links stored in Box.