Connecting to Box
Use the OAuth authentication standard to connect to REST. You can authenticate with a user account or a service account. The driver facilitates this as described below.
Using a User Account to Authenticate to REST
The user account flow requires the authenticating user to interact with REST via the browser.
Desktop ApplicationsSee Embedded Credentials to connect with the driver's embedded credentials and skip creating a custom OAuth app.
Headless MachinesSee Headless Machines to skip creating a custom OAuth app and authenticate an application running on a headless server or another machine where the driver is not authorized to open a browser.
Instead of connecting with the driver's embedded credentials, you can register an app to obtain the OAuthClientId and OAuthClientSecret.
When to Create a Custom OAuth App
You need to create a custom OAuth app in the web flow.
Creating a custom OAuth app is optional as the driver is already registered with REST and you can connect with its embedded credentials. You might want to create a custom OAuth app to change the information displayed when users log into the REST OAuth endpoint to grant permissions to the driver.
Creating a custom OAuth app is optional to authenticate a headless machine; the driver is already registered with REST and you can connect with its embedded credentials. In the headless OAuth flow, users need to authenticate via a browser on another machine. You might want to create a custom OAuth app to change the information displayed when users log into the REST OAuth endpoint to grant permissions to the driver.
Using a Service Account to Connect to REST
Service accounts have silent authentication, without user authentication in the browser. You can also use a service account to delegate enterprise-wide access scopes to the driver.
You need to create an OAuth application in this flow. You can then connect to REST data that the service account has permission to access. See Custom Credentials for an authentication guide.
Creating a Custom OAuth App
See Creating a Custom OAuth App for a procedure.