Skip to main content
Agents can onboard to Box without a human pasting an API key. Box implements auth.md, the WorkOS agentic registration protocol. Tell the agent:
That file is the contract. The agent discovers endpoints from /.well-known/oauth-protected-resource, registers, and only then calls the Box API.

What the agent does

Two registration methods:
  • Anonymous — the agent gets a token immediately. It can call GET /me and GET /limits only. Creating boxes returns claim_required until a human claims it.
  • Email (service_auth) — the agent already knows the user’s email. No token until that person signs in and types the code.
ID-JAG / provider-attested identity is not accepted yet. The agent should not send identity_assertion registration bodies.

Trial

Starting a trial is the same Stripe Checkout a human uses from the dashboard. The agent calls POST /api/box/billing/checkout with the claimed token and shows the returned URL. Card, trial-abuse checks, and “one trial per identity” still apply. Anonymous tokens cannot start a trial.

Endpoints

Hosted on https://ascii.dev (also under /api/box/... so they work behind the existing /api proxy): A 401 from the Box API includes WWW-Authenticate: Bearer resource_metadata="https://ascii.dev/api/box/.well-known/oauth-protected-resource" so an agent that simply hits the API can find the rest.