Skip to main content
Box brings regulated enterprise documents into Corunner by connecting your self-hosted or vendor-hosted MCP server. This page covers how to add the server, set usage guidance, verify the connection, and manage observation consent.

Connect with Box

Open the MCP Servers tab in the Corunner web app.

Server details

Connect Box

1
Sign in to Corunner at app.corunner.ai.
2
Open Integrations in the left sidebar.
3
Select the MCP Servers tab.
4
Find the Box card in the grid.
5
Turn on the Connect toggle. The Connect Box modal opens.
6
Verify the prefilled Server name (Box by default; rename if you run multiple instances).
7
Verify the prefilled Server URL. Value: https://your-box-mcp.example.com/mcp. Corunner does not manage the MCP endpoint URL for this server. Users paste the URL of their own MCP server (self-hosted or vendor-hosted). Placeholder from the app is used as the hint.
8
Click Test URL to confirm the endpoint format is valid and the server responds.
9
Select the authentication method (prefilled OAuth).
10
Click Advanced (Optional) to expand it. This panel contains the Usage guidance field, a free-text instruction that tells agents when and how to use this server. Corunner appends what you enter here to every tool description sent to the agent, so it directly influences when the agent picks Box over another source. Custom headers are hidden for OAuth servers.
11
In the Usage guidance field (placeholder: Tell agents when and how to use this server…), describe when this server should be used, which folders or files to prefer, what needs human approval, and what must not be accessed. Keep it short and imperative. Max 2000 characters. See the next section for a copyable example.
12
Click Connect with Box (OAuth).
13
Corunner redirects the current tab to the provider’s authorization page.
14
Review and approve the requested permissions in the provider consent screen.
15
After approval, return to Corunner automatically.
16
Confirm a green Connected badge and an enabled Connected toggle on the Box card.

Configure Usage Guidance

Usage guidance tells Corunner agents when to reach for this server and how to behave while using it. It takes free-form text and typically answers: When should the tool be used? What is it for? Which resources are permitted? Which require approval? What must never be accessed? How should results be presented?
Never enter secrets such as API keys, passwords, or tokens into Usage guidance. This field is saved as plain text and may be visible to other admins in your workspace.
Copy and adapt the example below for your organization:

Verify the Connection

After you connect, the Box card shows:
  • A green Connected status pill on the name row
  • An enabled Connected toggle
  • Connected to <workspace> with a relative connection time
  • A <N> capabilities button that expands into the capability list

Capabilities

  • search files
  • read files
Click the capability count or its chevron on the connected card to view the tools currently exposed by this server.

Check Connection Health

Use the Test connection icon (Wi-Fi glyph, next to the Connected toggle) to run a live probe.
  • Green check: the endpoint is reachable and credentials are valid.
  • Red warning: the probe failed.
If the test fails, open Edit configuration from the settings icon to refresh credentials or update the Server URL.

Edit Configuration

Click the Edit configuration icon (settings glyph) on the Box card to update:
  • Server name
  • Server URL (only if not managed by Corunner for this server)
  • Authentication method and credentials
  • Custom headers (non-OAuth only, under Advanced)
  • Usage guidance
Only workspace admins can create, edit, disconnect, or change observation-consent settings for MCP servers. Members see status and capabilities but cannot modify the connection.
Click the Observation consent icon (brain glyph) on the card to control whether Corunner passively reads resources into organizational memory. Observation is separate from tool connection. Turning it on or off does not change which capabilities are exposed to agents. It only controls whether Corunner may ingest content for memory and learning purposes. Each scope has:
  • Mode: Disabled, Shadow, or Active
  • Sensitivity: Standard, Restricted, or Excluded
Excluded scopes cannot be enabled.
The precise effect on Memory & Learnings for advanced observation modes should be confirmed with the Corunner product team if you plan to depend on it in policy.

Disable or Disconnect

Disconnecting deletes stored credentials for this connection. Provider-side OAuth tokens should also be revoked from the provider account if you want to eliminate them entirely.

Ready to go?

Open the MCP Servers tab and turn on the Box Connect toggle.

Integrations overview

Browse all Corunner integrations and connection types.

Memory & Learnings

Manage what Corunner remembers and how it learns from connected sources.

Governance

Set policies for tool access, approval flows, and agent guardrails.