Box holds the documents companies worry about most, and an endpoint anyone could connect a model to would be a governance problem. Making it an Admin Console switch with explicit scopes means enabling MCP is a deliberate act with a named owner. Plan for that when scoping: the connection cannot be tried from a laptop on a Friday afternoon unless someone with the Admin Console has already agreed.
Box's own hosted endpoint. It is not available until an administrator turns MCP on in the Admin Console and issues integration credentials, so this is an enterprise decision rather than a personal one.
Content operations — search, Box AI and folder work — with the full tool list published in Box's own tools guide. The endpoint would not enumerate them for us without credentials.
An admin enables MCP in the Box Admin Console and creates OAuth Integration Credentials: client ID and secret, redirect URI and scopes. Then the client connects to mcp.box.com and authorises.
Admin enables it, then paste and authorize — add the endpoint to your client, then approve the OAuth consent screen