Dropbox
<!-- BEGIN:skill-intro -->
Tools for working with files and folders in Dropbox — upload and write files, organize (move/copy/delete/create folders), navigate and search, read file contents, create and modify shared links, manage shared-folder membership, and create file requests. Wraps the
Dropbox API v2 (
https://api.dropboxapi.com/2/<namespace>/<method>
, with uploads/downloads on
https://content.dropboxapi.com
). Read-only tools are clearly marked; write tools return clean file/folder metadata rather than silently attaching links or contents.
<!-- legal:disclaimer -->
Independent, unofficial connector for Dropbox. Not affiliated with, endorsed by, or sponsored by Dropbox. "Dropbox" is a trademark of its owner, used only to identify the service this connector works with.
<!-- /legal:disclaimer -->
<!-- END:skill-intro -->
When to use this
<!-- BEGIN:skill-use-cases -->
- An agent needs to save, move, copy, rename, or delete files and folders in Dropbox.
- An agent needs to find a file or folder (by name or content) or list a folder's contents before acting on it.
- An agent needs to read a text file's contents inline, or hand off a file's bytes via a temporary or durable link.
- An agent needs to share a file/folder, change link settings, or manage who can access a shared folder.
<!-- END:skill-use-cases -->
Setup
This is an
agentskills.io skill.
If the connector has not been installed as a skill yet, install it first with
npx skills add zapier/connectors --skill dropbox
(or your harness's own skill-install mechanism), then continue here. Installing the skill copies these files, not dependencies. Before running the CLI, a local MCP server, or
auth commands, run
here once. Importing the published package as a dependency in your own project instead? That
already resolves everything — see
.
The connector runs on Node.js 22.18+. Pick the reference that matches how you're running it, and load it before doing anything else:
| You have... | Load |
|---|
| An MCP-aware client — tools may already be loaded (e.g. ), or you can register a local server yourself (or guide the user to) | |
| Terminal / subprocess access (you can run ) | |
| Only your own code, importing this package as a dependency | |
| No tool access, no terminal, no ability to import this package — you write your own code that calls the Dropbox API directly (e.g. a code-execution sandbox) | references/use-as-recipe.md
|
Scripts
<!-- BEGIN:skill-connections-note? -->
All 21 scripts use the single
connection. Each script's
/
(Zod) inside the script file is the source of truth for its contract.
<!-- END:skill-connections-note -->
<!-- BEGIN:skill-scripts-table -->
| Script | Script name | Connections | Description |
|---|
| | Single () | Upload a file by fetching its bytes from a URL (chunked session for large files). |
scripts/createTextFile.ts
| | Single () | Create or overwrite a file from plain text content. |
scripts/appendToTextFile.ts
| | Single () | Append text to a text file (creates it if absent). |
| | Single () | Create a folder at a path. |
| | Single () | Move or rename a file or folder. |
| | Single () | Copy a file or folder to a new path. |
| | Single () | Delete a file or folder (recoverable for a limited time). |
| | Single () | List a folder's immediate contents (cursor-paged). |
| | Single () | Search files/folders by name or content (cursor-paged). |
scripts/getFileMetadata.ts
| | Single () | Get metadata for one file or folder by path or id. |
scripts/getTemporaryLink.ts
| | Single () | Get a ~4h direct download URL for a file. |
scripts/getFileContents.ts
| | Single () | Read a text file's inline content (UTF-8, size-capped). |
scripts/createSharedLink.ts
| | Single () | Create a durable shareable link (returns the existing one if present). |
scripts/modifySharedLinkSettings.ts
| | Single () | Change an existing shared link's settings. Resolve via . |
scripts/listSharedLinks.ts
| | Single () | List existing shared links, optionally for a path. |
scripts/listSharedFolders.ts
| | Single () | List shared folders the account belongs to (resolver for ). |
scripts/addFolderMember.ts
| | Single () | Add members (by email) to a shared folder. Resolve via . |
scripts/removeFolderMember.ts
| | Single () | Remove a member from a shared folder (polls to completion). |
scripts/createFileRequest.ts
| | Single () | Create a public upload page into a folder. |
scripts/listFileRequests.ts
| | Single () | List the account's file requests. |
scripts/getCurrentAccount.ts
| | Single () | Identify the account and its team/personal namespace ids. |
Several scripts take an id or url best resolved from another script — those resolution hints are in the field descriptions (e.g.
addFolderMember.shared_folder_id
←
;
modifySharedLinkSettings.url
←
).
<!-- END:skill-scripts-table -->
<!-- BEGIN:disambiguation-and-refusals? -->
Disambiguation & refusals
Disambiguating items by name. Dropbox addresses items by
path or
id, and paths are case-insensitive — two items can look like the same name. Before writing to (move/copy/delete/share) an item the user named in words rather than by exact path, resolve it first with
or
:
- Exactly one match → act on it; don't over-confirm.
- Two or more matches that tie (e.g. in two different folders, or a shared-folder name that collides) → stop, list the candidates with a distinguishing field (full , or for folders), and ask which one. Never silently pick.
The entity types most likely to collide here are
files/folders by name (resolve via
/
, disambiguate on
) and
shared folders by name (resolve via
, disambiguate on
).
Operations this connector does NOT perform — say so, don't fake it. If the user asks for one of these, tell them it's unsupported rather than substituting a different tool and reporting success:
- Bulk/batch moves, copies, or deletes in one call. There is no batch tool — loop the single-item tools (//) yourself, or tell the user it'll be one call per item.
- Reading binary documents (PDF/image/Office) as text, OCR, or document parsing. returns UTF-8 text only; for other files it returns and you must hand off the bytes via . Don't claim to have read a PDF's contents.
- Fetching or editing an individual file request, or sharing a whole folder as a managed share. Only + are available; there is no get/update file-request or tool.
<!-- END:disambiguation-and-refusals -->
Auth
Every shape passes auth as one connection
selector, not the secret — a
string. Every connector accepts
(Zapier-managed auth — routes through Zapier's auth, retries, and governance layer); some also accept one or more direct-token resolvers (naming and count vary per connector) — check this connector's own resolvers rather than assuming. The
prefix is optional; a bare value goes to the first resolver that claims it — a UUID-shaped bare value always claims
. Each script declares the connections it needs and the resolvers each accepts. The exact syntax for passing a connection (and how to see this connector's resolver list) differs by shape — see the reference you loaded above.
Checking what's already configured first? Don't dump environment values to do it —
or
prints the value along with the name, leaking a live credential into the transcript if one is set. Check names only (
env | cut -d= -f1 | grep -i <name>
) or test a known name directly (
).
<!-- BEGIN:skill-auth-notes? operational behavior that differs by WHICH resolver is used — a safety gate only one path enforces, scopes/permissions that differ between resolvers, a billing/plan difference tied to the auth path, or a feature only available (or unavailable) on one resolver. Not for describing how to obtain or pass a credential — that's references/use-without-zapier.md's job. Leave this region empty (unfilled) if every resolver behaves identically. -->
<!-- END:skill-auth-notes -->
No connection yet? Pick one — and follow the reference's own flow to obtain it; never just ask the user for a connection id or token as if they already have one memorized:
| Load |
|---|
| Pass the credential directly | references/use-without-zapier.md
|
| Route it through a Zapier connection | references/use-with-zapier.md
|
Output format
Every script returns a
envelope:
- — the script's result (the shape its declares; see the reference you loaded above for how to inspect a script's exact schema in your shape).
meta.outputDataValidation
— what validating did:
{ skipped: false, droppedPaths: null }
— validated, nothing removed.
{ skipped: false, droppedPaths: [...], instruction }
— validated, but those paths were stripped from : fields the script returned from the API that the doesn't declare. If you need them, re-run with output validation skipped.
- — validation was bypassed; is the raw, unchecked script output.
Reading dropped fields / . To receive the raw, unvalidated result, opt out of output validation (the exact syntax differs by shape — see the reference you loaded above). Input validation is never skipped.
Trimming the result / . To shrink a large result down to the fields you need, pass a jq expression that post-processes
(again, exact syntax per shape). The jq runs against
only, NOT the
envelope, so write it rooted at
(run the script's
— or your shape's equivalent — to see its output schema). The transformed value replaces
,
is preserved, and the result is NOT re-validated against the output schema.
<!-- BEGIN:skill-references-table -->
References
Load the matching reference file before working in that area:
| Reference | Covers | Load it when |
|---|
references/dropbox-api-gotchas.md
| Stone union shape, error model, read-vs-write not-found asymmetry, path rules (root is not ), cursor pagination via sibling endpoints, rate limits + namespace write-locking, upload-session flow, shared-link recovery, team-space targeting via | Before making any direct Dropbox API calls or debugging unexpected API errors |
<!-- END:skill-references-table -->