@assemblyline-agents/dropbox
v10.3.2
Published
Official Assembly Line direct Dropbox API connection plugin.
Maintainers
Readme
@assemblyline-agents/dropbox
Official Assembly Line direct Dropbox API connection plugin. It calls Dropbox API v2 from the runtime host and does not use MCP.
Install and configure
assembly-line add dropbox agentThe command selects capabilities: [dropbox] and updates plugins.lock; it does
not create a root connection file.
Create one Dropbox API app in the Dropbox App Console. Enable these permissions for the full reviewed surface:
account_info.readfiles.metadata.readfiles.content.readfiles.content.writesharing.readsharing.write
Choose App Folder or Full Dropbox access to match the product boundary. Set the application credentials on the Assembly Line runtime:
DROPBOX_APP_KEY=your_app_key
DROPBOX_APP_SECRET=your_app_secretRegister the exact Assembly Line callback URL in the Dropbox app. It is the
public runtime origin followed by /assembly-line/connections/callback. Set
DROPBOX_REDIRECT_URI only when the connection should override the runtime's
derived callback URL.
The default OAuth flow uses Authorization Code + PKCE and requests offline access so the host can store and rotate a refreshable user grant. Tokens remain outside agent files and model context. Local tests use the same OAuth flow; tokens do not belong in source.
Reviewed surface
Read tools cover the connected account, space usage, metadata, folder listing, search, temporary content links, and existing shared links. Write tools create, copy, move, and delete files or folders and create shared links. New Dropbox routes stay hidden until this package reviews and classifies them.
Use plugins.dropbox.connections.dropbox.disable to remove named mutations or
approval to gate them. The exact reviewed action names are available through
assembly-line capabilities agent.
This first layer intentionally omits binary upload and download. Dropbox serves
those calls from a separate content origin, while Assembly Line's direct HTTP
tool results are JSON/text. files_get_temporary_link provides a bounded
content handoff without treating arbitrary file bytes as model text.
Official references:
License
MIT
