DROPBOX_APP_KEY, DROPBOX_APP_SECRET and DROPBOX_REFRESH_TOKEN) when setup is complete.
Scope of this integration today. ConfigView reads who is on your Dropbox team and with which admin role, your groups, the third-party apps each person has connected to their Dropbox, every computer, phone and browser signed in to each account, your team’s sharing and link policies, and Dropbox’s audit log: sign-ins, sharing with people outside the company, app links, device links, member and admin changes, two-step verification and policy changes. ConfigView only reads. It never opens, lists or downloads files, and it never reads file or folder names.Plan: any Dropbox team plan (Standard, Advanced, Business, Business Plus, Enterprise). Personal plans (Basic, Plus, Essentials, Family) have no team API.
Step 1: Open the Dropbox page in ConfigView
Open ConfigView in a second browser tab and leave it open:https://{companyname}.configview.com/admin/integrations/dropbox
Step 2: Create the Dropbox app
You need to be a Team admin in Dropbox. The app is created under your own Dropbox account and stays in Dropbox’s development status, which is all a single team needs: there is nothing to submit to Dropbox for review.- Go to dropbox.com/developers/apps while signed in as the team admin and click Create app
- Choose an API: Scoped access
- Choose the type of access you need: Full Dropbox. Dropbox only offers team permissions to Full Dropbox apps. ConfigView does not use any file permission
- Name your app: something unique, e.g.
ConfigView - {Company}. Click Create app - Open the Permissions tab. Under Team scopes, tick exactly these:
account_info.read is always ticked by Dropbox and cannot be removed; leave it. Do not tick any files.*, sharing.*, team_data.* or *.write scope. If Dropbox ticks a scope automatically because another one depends on it, leave it ticked.
6. Click Submit at the bottom of the Permissions tab
7. Open the Settings tab. Copy the App key into DROPBOX_APP_KEY in ConfigView, then click Show beside App secret and copy it into DROPBOX_APP_SECRET. Click the save icon
Step 3: Authorise the app for your team and get a refresh token
This is a one-time step. Still signed in to Dropbox as the team admin:-
Paste this address into your browser, replacing
APP_KEYwith your app key:https://www.dropbox.com/oauth2/authorize?client_id=APP_KEY&response_type=code&token_access_type=offline - Dropbox shows the permissions the app asks for, on behalf of your team. Click Continue, then Allow
- Dropbox shows an access code. Copy it. The code works once and only for a few minutes, so do the next step straight away
-
Exchange the code for a refresh token. In a terminal (macOS, Linux, or Windows 10+ Command Prompt), replacing the three values:
or in Windows PowerShell:
-
The answer is a short block of JSON. Copy the value of
refresh_token(notaccess_token, which starts withsl.and expires in four hours) intoDROPBOX_REFRESH_TOKENin ConfigView and click the save icon. The answer should also contain ateam_id; if it does not, the person who clicked Allow was not a team admin. Start step 3 again as a team admin
Step 4: Connect and verify
- Back on
https://{companyname}.configview.com/admin/integrations/dropbox, confirm the three credentials show as saved - Click Connect. ConfigView creates its tables and schedules every collector at your default run time. Stop any you don’t want under Collectors:
- Click Verify now. The health check confirms the three secrets, trades the refresh token for an access token, shows which admin authorised it, then makes one small read with each of the five scopes.
- “Dropbox refused the refresh token”. The token was revoked, the app was deleted, or
DROPBOX_APP_KEY/DROPBOX_APP_SECRETbelong to a different app. Check the key and secret on the app’s Settings tab, then repeat step 3. - “needs the ’…’ scope”. That scope was not ticked when the refresh token was made. Tick it, click Submit, and repeat step 3.
- “this is a user token, not a team token”. Whoever clicked Allow was not a team admin, or no team scope was ticked. Repeat step 3 as a team admin.
- Audit log shows
skip. Your plan or settings do not let the API read the audit log. Everything else still works; the audit table stays empty.
Data Tables
Once the scripts run, these tables are created in your database. Each includes arun_at column. Every table keeps only the newest run, except the audit log, which keeps everything it has ever collected.
status is active, invited, suspended or removed. Suspended members can be restored with everything they had, including admin roles. roles lists admin roles by name (Team admin, User management admin, Support admin, Billing admin, …); is_admin is 1 when someone holds any of them.
is_app_folder is 1 when a linked app can only see its own folder in that person’s Dropbox, and 0 when it can read and write everything they can.
session_type is web (a browser session), desktop (the Dropbox desktop app; device_name is the computer’s name) or mobile (the phone or tablet app).
event_category and event_type are Dropbox’s own names, e.g. logins / login_success, sharing / shared_content_add_invitees, apps / app_link_team, tfa / tfa_change_status. external_recipient_emails lists outside addresses something was shared with. details holds the rest of the event as JSON, with Dropbox’s {".tag": …} values kept as they are.
Things worth knowing
Apps linked to the whole team are not indropbox_linked_apps. Dropbox lists those separately from the apps people link to their own accounts. ConfigView reads them from the audit log (app_link_team / app_unlink_team events); the ConfigView app itself is one of them.
There is no “has two-step verification” field. Dropbox’s API does not report each member’s current two-step setting. ConfigView reads the history of two-step changes from the audit log instead, the full history Dropbox still holds on the first run. Someone who turned it on before that history begins shows as “no record”; check them in the Admin console.
The first audit-log run is a backfill. It reads every two-step verification, policy and app event Dropbox still holds, and the last 90 days of the other categories, a week at a time. It stops starting new pages after 25 minutes and the next run carries on from where it got to (dropbox_team_event_sync.complete_through).
Dropbox gives audit events no id. ConfigView builds one (event_hash) from the whole event, so re-reading the same hour never creates duplicates.
If the admin who authorised the app leaves. The token belongs to the team, but authorized_by_email in dropbox_team shows whose consent it rests on. If that person is removed or loses the Team admin role, repeat step 3 as another team admin.
Rate limits. Dropbox publishes no numeric API limit. ConfigView paces itself (one call a second; two for the audit log) and waits as long as Dropbox asks when it answers 429.
What isn’t collected
- Files, folders and Paper documents: no contents, no names, no paths. ConfigView holds no file permission
- File operations, Paper, comments, file requests, Showcase and Dropbox Sign events from the audit log
- Shared-link URLs, file and folder names, and paths inside audit events. Keys that hold them are removed from
detailsbefore it is stored; the files an event touched are kept only as a count and a kind (asset_count,asset_types) - Profile photo URLs, browser user-agent strings and mobile carriers
- The app secret and tokens never leave Secret Manager; they are not written to any table