OneCLI connects AI agents to Dropbox through OAuth. Agents can browse files and folders, download and upload content, and manage sharing. The gateway injects OAuth credentials into requests to the Dropbox API automatically.
Open the OneCLI dashboard and navigate to Connections > Dropbox.
2
Authorize
Click Connect Dropbox. You’ll be redirected to Dropbox to authorize OneCLI. Review the requested permissions and click Allow.
The Dropbox connect window on OneCLI Cloud.
OneCLI requests read access to account info, file metadata, and file content by default. Write access for uploading, organizing, and sharing is optional.
3
Verify
After authorization, you’ll be redirected back to the dashboard. The connection will show as Connected with your Dropbox email.
Skip this section on OneCLI Cloud. It’s only for self-hosted OneCLI without DROPBOX_CLIENT_ID and DROPBOX_CLIENT_SECRET set, or if you want your own company name on Dropbox’s consent screen.
1. Create the Dropbox app
Go to the Dropbox App Console and select Create app. Choose Scoped access and Full Dropbox, name it (for example OneCLI-yourcompany), and create it.
2. Add the permissions
Open Permissions, tick these, and select Submit:account_info.read, files.metadata.read, files.content.read, files.content.write, sharing.read, sharing.write
The Permissions tab of your Dropbox app, with the file scopes ticked.
3. Add the redirect URI
In OneCLI, open Connections > Dropbox > Custom credentials and copy the Redirect URI. In Dropbox, open Settings, paste it into OAuth 2 > Redirect URIs, and select Add.
Copy the Redirect URI from Custom credentials in OneCLI.
The OAuth 2 section of your Dropbox app's Settings tab, with the OneCLI Redirect URI.
4. Connect with your app
On the Dropbox Settings tab, copy the App key and App secret. Paste both into Connections > Dropbox > Custom credentials, select Save & Connect, and allow access in Dropbox.
Access is per agent: grant the connection to each agent that needs it, choosing per tool what runs freely, what needs human approval, and what stays blocked — a read-only agent is a single grant. Organization rules add guardrails on top, like rate limits and blanket blocks. Everything is checked before credential injection, so a blocked request never reaches Dropbox.