# How to connect Dropbox to OpenClaw (no API keys)

> Connect Dropbox to OpenClaw with ClawLink in one click — 111 tools your AI agent can call from chat via hosted OAuth. No API keys, no manual setup.

Web version: https://claw-link.dev/openclaw/dropbox

The usual route to Dropbox access for OpenClaw is an MCP server you configure and keep running, plus your own OAuth app or API keys. ClawLink gives OpenClaw a more practical Dropbox setup: install one ClawHub skill, connect Dropbox in the browser, and OpenClaw can call real Dropbox actions from any chat surface with no auth, token refresh, or tool wiring to build yourself.

**Start here:** install the ClawLink plugin (`openclaw plugins install clawhub:clawlink-plugin`), pair it in the browser, then connect the app in the ClawLink dashboard. The interactive install prompt is on the web version of this page: https://claw-link.dev/openclaw/dropbox

## Setup

It takes three steps to connect OpenClaw to Dropbox.

1. **Install ClawLink** — add the plugin to OpenClaw once.
2. **Connect Dropbox** — one-click OAuth in the ClawLink dashboard.
3. **Use it from chat** — ask OpenClaw in plain English.

**Alternative for any agent (no plugin needed):** if the OpenClaw plugin route isn't available or doesn't work, any AI agent with shell access can use the ClawLink CLI instead:

```bash
npx -y @useclawlink/cli login          # sign in via browser — no API key to paste
npx -y @useclawlink/cli connect dropbox  # connect Dropbox (browser OAuth)
npx -y @useclawlink/cli actions dropbox  # list available actions
npx -y @useclawlink/cli run dropbox <action> --input '<json>'  # execute (add --confirm for writes)
```

### Install by command

The setup prompt above does all of this in one paste. By hand, it is one install command plus a browser approval:

```bash
openclaw plugins install clawhub:clawlink-plugin
```

Then ask OpenClaw to set up ClawLink. It starts browser pairing and prints an approval link — open it, approve the device, return to the chat, and say `done`. Finally, connect Dropbox in the [ClawLink dashboard](https://claw-link.dev/dashboard) — a one-click OAuth approval, no API keys.

Verify the connection by asking OpenClaw:

> Upload the attached file to my Dropbox folder /Projects/Q3 with dropbox_upload_file, then confirm the path and size with dropbox_get_metadata.

### Using a different agent?

The OpenClaw plugin is one client of ClawLink's MCP server. Claude Code, Cursor, Codex, or any agent that can run a shell command pairs with the same ClawLink account through the CLI:

```bash
npx -y @useclawlink/cli login
```

`login` opens the same browser approval and stores a credential locally. Once Dropbox is connected in the dashboard, that agent calls the same 111 Dropbox tools over MCP. Full setup for MCP clients and shell agents: [connect apps to any AI agent](https://claw-link.dev/learn/connect-apps-to-any-ai-agent).

## Dropbox MCP for OpenClaw

Looking for a Dropbox MCP server for OpenClaw? ClawLink connects Dropbox to OpenClaw and exposes 111 Dropbox tools your agent can call over [MCP](https://claw-link.dev/learn/what-is-an-mcp-server), with [hosted auth](https://claw-link.dev/learn/oauth-for-ai-agents) and nothing to run or maintain yourself. Using Hermes instead? The [Hermes Dropbox integration](https://claw-link.dev/hermes/dropbox) works the same way.

The answer the search engines give for "connect Dropbox to OpenClaw" is a walkthrough of someone else's bridge: create a workspace, flip on its intelligence mode, approve Dropbox in its import tab, then install a ClawHub skill by its author's name. Same mechanic this page uses, different brand, and the token story is the tell: those routes have you create a Dropbox app in the App Console and generate an access token, the exact steps this page removes. Here you install one ClawHub skill, click Connect next to Dropbox in the dashboard, and approve Dropbox's own consent screen: the app already exists, the OAuth grant is hosted, and the 111 tools below work from your next chat with no token in any file.

## Is it safe to connect Dropbox to OpenClaw?

The AI Overview's own answer to this query is "not completely safe by default", and its list of risks names data over-exposure, prompt injection, and third-party LLM handling of data. Those are real, and the hosted setup is the shape that answers them rather than ignoring them:

- **The token is never on your machine.** The manual route puts a generated access token in an environment file or config that every process on that machine can read. Here the OAuth grant lives server-side, and the connection is revoked from the dashboard, not by hunting down a pasted token.
- **The grant is scoped and human-approved.** You approve Dropbox's own consent screen once, and the connection acts as your account, exactly like a scoped OAuth token. Nothing in this flow asks for a Dropbox password or a long-lived app secret.
- **The remaining risk is behavioral, and it is settable in chat.** Prompt injection matters most when the agent is told to act on content it reads, so treat file contents as untrusted input, start with reads, and require a confirmation step before deletes, moves, and shared-link creation. For sensitive material, a dedicated folder or a secondary account is the same partition the engines recommend, achievable by scoping the agent's requests to one path.

The safety question is not "is the connection secure" but "what did you let it do". Hosted OAuth makes the first one structurally easy and the second one a matter of how you phrase the prompts.

## What the OpenClaw Dropbox integration can do

111 Dropbox tools are ready for OpenClaw once the account is connected. The 30 below are the ones people reach for most; your agent can call all 111.

### 30 of 111 Dropbox tools for OpenClaw

| Tool | What it does |
|---|---|
| **Copy file or folder** `dropbox_copy_file_or_folder` | Copy a file or folder in Dropbox |
| **Create folder** `dropbox_create_folder` | Create a new folder in Dropbox |
| **Create shared link** `dropbox_create_shared_link` | Create a shared link for a Dropbox file or folder |
| **Download zip** `dropbox_download_zip` | Download a Dropbox folder as a ZIP archive |
| **Get metadata** `dropbox_get_metadata` | Get metadata for a Dropbox file or folder |
| **Get space usage** `dropbox_get_space_usage` | Get current Dropbox storage space usage |
| **Get temporary link** `dropbox_get_temporary_link` | Get a temporary link to download a Dropbox file |
| **List file revisions** `dropbox_list_file_revisions` | List revisions of a Dropbox file |
| **List folder continue** `dropbox_list_folder_continue` | List files and folders in a Dropbox folder |
| **List shared links** `dropbox_list_shared_links` | List shared links in Dropbox |
| **Move file or folder** `dropbox_move_file_or_folder` | Move a file or folder in Dropbox |
| **Read file** `dropbox_read_file` | Read the contents of a Dropbox file |
| **Search file or folder** `dropbox_search_file_or_folder` | Search Dropbox for files and folders |
| **Share folder** `dropbox_share_folder` | Share a Dropbox folder with others |
| **Upload file** `dropbox_upload_file` | Upload a file to Dropbox |
| **Check copy batch** `dropbox_check_copy_batch` | Check the status of an asynchronous copy batch job in Dropbox |
| **Check folder batch** `dropbox_check_folder_batch` | Check the status of an asynchronous folder batch creation job |
| **Check job status** `dropbox_check_job_status` | Check the status of an asynchronous sharing job in Dropbox |
| **Check move batch** `dropbox_check_move_batch` | Check the status of an asynchronous move batch job |
| **Check save URL status** `dropbox_check_save_url_status` | Check the status of a save_url job in Dropbox |
| **Check share job status** `dropbox_check_share_job_status` | Check the status of an asynchronous folder sharing job in Dropbox |
| **Check upload batch** `dropbox_check_upload_batch` | Check the status of an asynchronous upload batch job in Dropbox |
| **Check user** `dropbox_check_user` | Test Dropbox API connection and validate access token by echoing back a supplied string |
| **Count file requests** `dropbox_count_file_requests` | Get the total number of file requests owned by the authenticated user |
| **Export file** `dropbox_export_file` | Export non-downloadable Dropbox files (especially Dropbox Paper) to Markdown/HTML/plain text |
| **Files search** `dropbox_files_search` | Search for files and folders in Dropbox by name or content |
| **Get about me** `dropbox_get_about_me` | Get information about the current user's Dropbox account |
| **Get account** `dropbox_get_account` | Get information about a user's Dropbox account using their account ID |
| **Get account batch** `dropbox_get_account_batch` | Get information about multiple user accounts in a single request |
| **Get copy reference** `dropbox_get_copy_reference` | Get a copy reference to a file or folder |

## Example prompts

**Upload a file**

> Upload the attached file to my Dropbox folder /Projects/Q3 with dropbox_upload_file, then confirm the path and size with dropbox_get_metadata.

**Find a file**

> Search my Dropbox with dropbox_search_file_or_folder for "budget" and show me the top matches with their paths and ids. Do not open any files yet.

**Summarize a document**

> Read the file at the path I name with dropbox_read_file and summarize it in plain English, noting anything that looks unfinished or needs a decision.

**Check what changed**

> List the recent revisions of the file \<path> with dropbox_list_file_revisions and tell me what changed in the last week and when the last edit was.

## ClawLink vs. building it yourself

The alternative to ClawLink is usually manual OAuth app setup plus your own token handling, permission troubleshooting, and tool plumbing for OpenClaw. That is fine if you want to build and maintain the integration yourself. Most teams just want Dropbox working from chat.

| | Manual | ClawLink |
|---|---|---|
| **Connection flow** | Register a Dropbox app, configure redirect URLs, manage consent details, and reconnect users when auth settings drift. | Users connect Dropbox through the hosted browser flow and ClawLink keeps the token lifecycle out of your app code. |
| **Ongoing maintenance** | You own refresh logic, permission debugging, environment config, and every provider-specific edge case for Dropbox. | ClawLink handles the repetitive integration plumbing so your team can focus on the workflow instead of the infrastructure. |
| **Agent usability** | You still need to expose the right Dropbox actions to the runtime in a format your agent can reliably use. | 111 tools for Dropbox are already exposed through ClawLink, so the agent can read and act from chat immediately. |

## ClawLink vs. Composio

Composio also exposes Dropbox to AI agents. It is developer infrastructure: Python and TypeScript SDKs, an MCP server, and a catalog past 1,000 apps, aimed at teams shipping agent products. ClawLink is built for OpenClaw users instead. You install the plugin once, connect Dropbox in the browser, and the 111 tools above work from chat. There is no SDK, no config file, and no API key handling. Choosing between them? Read the full [Composio alternatives](https://claw-link.dev/hub/composio-alternatives) comparison.

### OpenClaw installed the Dropbox skill but can't call the tools
The ClawHub skill teaches OpenClaw about Dropbox, but the calls run through the ClawLink plugin and your connected account. Make sure Dropbox is connected in the dashboard, then start a fresh chat so OpenClaw reloads the tool catalog. If OpenClaw runs as a persistent gateway, restart it so the new tools register.

### Connection succeeds but no tools appear
Reconnect Dropbox from the dashboard, then start a fresh chat if the runtime still has the old tool catalog loaded.

### "Tool schema not loaded yet" error when calling Dropbox tools
Dropbox tool schemas load on demand the first time a tool runs and are cached after that, so this error usually clears on its own: wait a few seconds and retry the same request. If every Dropbox call keeps failing with it in a fresh chat, reconnect from the dashboard, and contact support if it still persists — that pattern points to a configuration problem on our side, not something you can fix by reconnecting again.

### Dropbox returns 403 or "permission denied" on one action while others work
Two usual causes. The connected account may not have access to the specific workspace, inbox, store, or project in the request — check that first. If access looks right, the agent may have sent a placeholder value (like "YOUR_ID" or an example id from documentation) instead of a real one: ask it to run a list or search tool first, then retry the action with a real id from those results. Most failures at this stage are one of these two, not ClawLink bugs.

### Dropbox returns "permission denied" or 403 on one action while others work
Two usual causes, and both are about the request rather than the connection. First, the connected account may not actually hold the access the action needs: a file you can see because it was shared with you is not necessarily one you can delete, and some folder operations are owner-only. Second, the agent may have sent a placeholder or invented id (like "YOUR_ID" or an example path from documentation) instead of a real one: ask it to run `dropbox_get_metadata` or `dropbox_search_file_or_folder` first and retry with the real path or id from those results. Most 403s at this stage are one of these two, not a ClawLink bug, and reconnecting changes nothing until the request itself is corrected.

Ask the agent to diagnose it:

```text
Run dropbox_search_file_or_folder for the file you were acting on and show me its real path and id. Quote the exact 403 error text, then retry with the real id. Do not reconnect yet.
```

### Dropbox starts returning 429 or the agent stalls partway through a folder
Dropbox rate-limits dynamically, per user and per app, with no published per-minute caps, so the limit is a function of how much the connection has done recently rather than a fixed number. An agent walking a large folder, one file at a time, is the traffic shape that meets it. The response is not to retry immediately, which lands in the same window, but to change the shape of the work: name the folder or file you actually need instead of asking for a full inventory, and have the agent tell you what it intends to enumerate before it starts. A bulk sync across many files is better run in stages across turns than in one sweep.

Ask the agent to diagnose it:

```text
Tell me how many Dropbox calls you have made in the last minute and what you were reading. Quote the error text from the last response. Do not call Dropbox again until I reply.
```

### Dropbox tools are missing, or one tool name is not found
Two different failures. If OpenClaw shows no Dropbox tools at all, the connection or pairing is incomplete: confirm the skill was installed, that Dropbox shows as connected in the dashboard, and start a fresh chat so the tool catalog reloads. If most tools work and a single name fails, that name is wrong rather than missing: the error lists the closest real ones, and the real catalog is one `clawlink_list_tools --integration dropbox` away. There is also a first-call timing case unique to this setup: schemas load on demand, so the opening Dropbox call in a fresh session can arrive before the catalog and needs one retry. What does not apply is the usual advice for this symptom, which assumes a local MCP server or rclone config on the machine.

Ask the agent to diagnose it:

```text
List the Dropbox tools you actually have access to. If there are none, say so plainly and run clawlink_list_integrations. If there are, tell me which one searches files and use that exact name.
```

### OAuth finished in the browser but the account is still missing
Try reconnecting Dropbox and complete the consent flow in the same browser session. Partial OAuth approvals or switching accounts mid-flow can leave the connection incomplete.

### Is there a OpenClaw Dropbox integration?
Yes. ClawLink is the fastest way to connect OpenClaw to Dropbox: link your Dropbox account once in the browser and OpenClaw can call the Dropbox API through 111 ready-made tools — no custom code or token handling.

### How do I add Dropbox to OpenClaw with ClawLink?
Paste the setup prompt from this page into OpenClaw. It installs the ClawLink Dropbox skill from ClawHub, then you click Connect in the dashboard to authorize Dropbox. OpenClaw calls the tools from the next message — no config files or API keys to manage.

### How long does it take to connect Dropbox to OpenClaw?
About two minutes. Sign in, click Connect next to Dropbox in the dashboard, authenticate, and OpenClaw can use it from the next chat message.

### Why use ClawLink instead of wiring Dropbox up myself?
The alternative to ClawLink is usually manual OAuth app setup plus your own token handling, permission troubleshooting, and tool plumbing for OpenClaw. That is fine if you want to build and maintain the integration yourself. Most teams just want Dropbox working from chat.

### Can I connect Dropbox without creating my own app or token?
Yes, and that is the specific thing this page does. The manual route starts in the Dropbox App Console: create an app, set its permissions, generate an access token, and paste it somewhere your agent can read. Here the Dropbox app is ClawLink's, the authorization happens on Dropbox's consent screen in the browser, and the connection lives server-side. The phrasing "without own app" is exactly the p2-shaped query this flow answers: no App Console visit, no token generation, no app to maintain or revoke per-machine.

### Is it safe to connect Dropbox to an AI agent?
The AI Overview's answer to this query opens with "not completely safe by default", and its named mitigations are the ones a hosted connection already implements: scoped OAuth tokens instead of long-lived credentials, no app token sitting in an environment file, and revocation in one place. The remaining risk is behavioral and it is yours to set: the connected account has your file access, so start with reads, ask for a confirmation step before deletes and moves, and if the agent is working with a large folder, scope it by asking for one path at a time. Disconnecting from the ClawLink dashboard revokes the agent's access immediately, which is more control than a pasted token gives you.

### What can the agent actually do with my Dropbox?
The 111 tools cover the file surface: upload, download, and read files, create folders, search by name, move, copy, and delete, plus shared links, folder sharing, file revisions, and space usage. The writes to be deliberate about are delete and move, because they change files other people may be using, and create_shared_link, because it makes a file reachable by URL. Reads and searches are the safe first steps, and the revision tools mean a mistaken overwrite is usually recoverable.

### How is this different from the routes search results teach, like Fastio or rclone?
The underlying Dropbox API is the same, so the capability difference is small; the setup and upkeep difference is not. The bridge route the AI Overview teaches involves a workspace, an import step, a third-party skill install, and, depending on the variant, a Dropbox app token you generate yourself; the rclone route means owning a sync configuration. Here the skill install and one dashboard connection are the entire story, and Dropbox sits alongside your other connected accounts with one place to revoke. Choose on how much you want to run, not on features.

### OpenClaw installed the Dropbox skill but can't call the tools
The ClawHub skill teaches OpenClaw about Dropbox, but the calls run through the ClawLink plugin and your connected account. Make sure Dropbox is connected in the dashboard, then start a fresh chat so OpenClaw reloads the tool catalog. If OpenClaw runs as a persistent gateway, restart it so the new tools register.

## Related

- [OpenClaw Box integration](https://claw-link.dev/openclaw/box) — Store, share, and manage files and folders
- [Supabase](https://claw-link.dev/openclaw/supabase) — Query and manage Postgres databases
- [OpenClaw Neon integration](https://claw-link.dev/openclaw/neon) — Serverless Postgres with branching and scale-to-zero
