Imported from zapier/connectors (
apps/dropbox/SKILL.md). Install upstream withnpx skills add zapier/connectors --skill dropbox. Copyright stays with the author (Elastic-2.0).
Dropbox
Tools for working with files and folders in Dropbox — upload and write files, organize (move/copy/delete/create folders), navigate and search, read file contents, create and modify shared links, manage shared-folder membership, and create file requests. Wraps the Dropbox API v2 (https://api.dropboxapi.com/2/<namespace>/<method>, with uploads/downloads on https://content.dropboxapi.com). Read-only tools are clearly marked; write tools return clean file/folder metadata rather than silently attaching links or contents.
Independent, unofficial connector for Dropbox. Not affiliated with, endorsed by, or sponsored by Dropbox. "Dropbox" is a trademark of its owner, used only to identify the service this connector works with.
When to use this
- An agent needs to save, move, copy, rename, or delete files and folders in Dropbox.
- An agent needs to find a file or folder (by name or content) or list a folder's contents before acting on it.
- An agent needs to read a text file's contents inline, or hand off a file's bytes via a temporary or durable link.
- An agent needs to share a file/folder, change link settings, or manage who can access a shared folder.
Setup
This is an agentskills.io skill.
If the connector has not been installed as a skill yet, install it first with npx skills add zapier/connectors --skill dropbox (or your harness's own skill-install mechanism), then continue here. Installing the skill copies these files, not dependencies. Before running the CLI, a local MCP server, or zapier-sdk auth commands, run npm install --omit=dev here once. Importing the published package as a dependency in your own project instead? That npm install already resolves everything — see references/use-as-sdk.md.
Want the actual repo source instead — to browse references/, run this connector's tests, or hack on it? See README.md for a scoped git clone.
The connector runs on Node.js 22.18+. Pick the reference that matches how you're running it, and load it before doing anything else:
| You have... | Load |
|---|---|
An MCP-aware client — tools may already be loaded (e.g. mcp__dropbox__<tool>), or you can register a local server yourself (or guide the user to) |
references/use-as-mcp.md |
Terminal / subprocess access (you can run node) |
references/use-as-cli.md |
| Only your own code, importing this package as a dependency | references/use-as-sdk.md |
| No tool access, no terminal, no ability to import this package — you write your own code that calls the Dropbox API directly (e.g. a code-execution sandbox) | references/use-as-recipe.md |
Scripts
All 21 scripts use the single dropbox connection. Each script's inputSchema / outputSchema (Zod) inside the script file is the source of truth for its contract.
| Script | Script name | Connections | Description |
|---|---|---|---|
scripts/uploadFile.ts |
uploadFile |
Single (dropbox) |
Upload a file by fetching its bytes from a URL (chunked session for large files). |
scripts/createTextFile.ts |
createTextFile |
Single (dropbox) |
Create or overwrite a file from plain text content. |
scripts/appendToTextFile.ts |
appendToTextFile |
Single (dropbox) |
Append text to a text file (creates it if absent). |
scripts/createFolder.ts |
createFolder |
Single (dropbox) |
Create a folder at a path. |
scripts/moveFile.ts |
moveFile |
Single (dropbox) |
Move or rename a file or folder. |
scripts/copyFile.ts |
copyFile |
Single (dropbox) |
Copy a file or folder to a new path. |
scripts/deletePath.ts |
deletePath |
Single (dropbox) |
Delete a file or folder (recoverable for a limited time). |
scripts/listFolder.ts |
listFolder |
Single (dropbox) |
List a folder's immediate contents (cursor-paged). |
scripts/searchFiles.ts |
searchFiles |
Single (dropbox) |
Search files/folders by name or content (cursor-paged). |
scripts/getFileMetadata.ts |
getFileMetadata |
Single (dropbox) |
Get metadata for one file or folder by path or id. |
scripts/getTemporaryLink.ts |
getTemporaryLink |
Single (dropbox) |
Get a ~4h direct download URL for a file. |
scripts/getFileContents.ts |
getFileContents |
Single (dropbox) |
Read a text file's inline content (UTF-8, size-capped). |
scripts/createSharedLink.ts |
createSharedLink |
Single (dropbox) |
Create a durable shareable link (returns the existing one if present). |
scripts/modifySharedLinkSettings.ts |
modifySharedLinkSettings |
Single (dropbox) |
Change an existing shared link's settings. Resolve url via listSharedLinks. |
scripts/listSharedLinks.ts |
listSharedLinks |
Single (dropbox) |
List existing shared links, optionally for a path. |
scripts/listSharedFolders.ts |
listSharedFolders |
Single (dropbox) |
List shared folders the account belongs to (resolver for shared_folder_id). |
scripts/addFolderMember.ts |
addFolderMember |
Single (dropbox) |
Add members (by email) to a shared folder. Resolve shared_folder_id via listSharedFolders. |
scripts/removeFolderMember.ts |
removeFolderMember |
Single (dropbox) |
Remove a member from a shared folder (polls to completion). |
scripts/createFileRequest.ts |
createFileRequest |
Single (dropbox) |
Create a public upload page into a folder. |
scripts/listFileRequests.ts |
listFileRequests |
Single (dropbox) |
List the account's file requests. |
scripts/getCurrentAccount.ts |
getCurrentAccount |
Single (dropbox) |
Identify the account and its team/personal namespace ids. |
Several scripts take an id or url best resolved from another script — those resolution hints are in the field descriptions (e.g. addFolderMember.shared_folder_id ← listSharedFolders; modifySharedLinkSettings.url ← listSharedLinks).
Disambiguation & refusals
Disambiguating items by name. Dropbox addresses items by path or id, and paths are case-insensitive — two items can look like the same name. Before writing to (move/copy/delete/share) an item the user named in words rather than by exact path, resolve it first with searchFiles or listFolder:
- Exactly one match → act on it; don't over-confirm.
- Two or more matches that tie (e.g.
report.pdfin two different folders, or a shared-folder name that collides) → stop, list the candidates with a distinguishing field (fullpath_display, orshared_folder_idfor folders), and ask which one. Never silently pick.
The entity types most likely to collide here are files/folders by name (resolve via searchFiles/listFolder, disambiguate on path_display) and shared folders by name (resolve via listSharedFolders, disambiguate on shared_folder_id).
Operations this connector does NOT perform — say so, don't fake it. If the user asks for one of these, tell them it's unsupported rather than substituting a different tool and reporting success:
- Bulk/batch moves, copies, or deletes in one call. There is no batch tool — loop the single-item tools (
moveFile/copyFile/deletePath) yourself, or tell the user it'll be one call per item. - Reading binary documents (PDF/image/Office) as text, OCR, or document parsing.
getFileContentsreturns UTF-8 text only; for other files it returnsis_text:falseand you must hand off the bytes viagetTemporaryLink. Don't claim to have read a PDF's contents. - Fetching or editing an individual file request, or sharing a whole folder as a managed share. Only
createFileRequest+listFileRequestsare available; there is no get/update file-request orshareFoldertool.
Auth
Every shape passes auth as one connection selector, not the secret — a [<resolver>:]<value> string. Every connector accepts zapier:<connection-id> (Zapier-managed auth — routes through Zapier's auth, retries, and governance layer); some also accept one or more direct-token resolvers (naming and count vary per connector) — check this connector's own resolvers rather than assuming. The <resolver>: prefix is optional; a bare value goes to the first resolver that claims it — a UUID-shaped bare value always claims zapier:. Each script declares the connections it needs and the resolvers each accepts. The exact syntax for passing a connection (and how to see this connector's resolver list) differs by shape — see the reference you loaded above.
Checking what's already configured first? Don't dump environment values to do it — env or env | grep <name> prints the value along with the name, leaking a live credential into the transcript if one is set. Check names only (env | cut -d= -f1 | grep -i <name>) or test a known name directly ([ -n "$VAR_NAME" ]).
No connection yet? Pick one — and follow the reference's own flow to obtain it; never just ask the user for a connection id or token as if they already have one memorized:
| Load | |
|---|---|
| Pass the credential directly | references/use-without-zapier.md |
| Route it through a Zapier connection | references/use-with-zapier.md |
Output format
Every script returns a { data, meta } envelope:
data— the script's result (the shape itsoutputSchemadeclares; see the reference you loaded above for how to inspect a script's exact schema in your shape).meta.outputDataValidation— what validatingdatadid:{ skipped: false, droppedPaths: null }— validated, nothing removed.{ skipped: false, droppedPaths: [...], instruction }— validated, but those paths were stripped fromdata: fields the script returned from the API that theoutputSchemadoesn't declare. If you need them, re-run with output validation skipped.{ skipped: true }— validation was bypassed;datais the raw, unchecked script output.
Reading dropped fields / skipOutputDataValidation. To receive the raw, unvalidated result, opt out of output validation (the exact syntax differs by shape — see the reference you loaded above). Input validation is never skipped.
Trimming the result / filterOutputData. To shrink a large result down to the fields you need, pass a jq expression that post-processes data (again, exact syntax per shape). The jq runs against data only, NOT the { data, meta } envelope, so write it rooted at data (run the script's --help — or your shape's equivalent — to see its output schema). The transformed value replaces data, meta is preserved, and the result is NOT re-validated against the output schema.
References
Load the matching reference file before working in that area:
| Reference | Covers | Load it when |
|---|---|---|
references/dropbox-api-gotchas.md |
Stone .tag union shape, error_summary error model, read-vs-write not-found asymmetry, path rules (root is "" not "/"), cursor pagination via sibling /continue endpoints, rate limits + namespace write-locking, upload-session flow, shared-link recovery, team-space targeting via namespace_id |
Before making any direct Dropbox API calls or debugging unexpected API errors |