Table of contents

Dropbox, a leading cloud storage and file sharing platform, helps teams streamline collaboration, organize content, safeguard backups, and increasingly leverage AI to automate workflows and insights.
Based on all of the file and folder data collected and used in Dropbox, integrating it with your internal applications or your product can offer a wealth of benefits.
To that end, we’ll walk through how you can connect to Dropbox’s API endpoints with Python.
But first, let’s review how Dropbox’s API works.
Before writing any code, you need to understand how the Dropbox API handles authentication and structures its endpoints as this directly impacts how you build your integration.
Dropbox uses OAuth 2.0 for authentication, but unlike many modern APIs, it doesn't provide refresh token rotation or simplified authentication flows. You need to manually implement the complete OAuth 2.0 flow, including generating authorization URLs, handling user consent, and managing token storage. This manual approach gives you control but requires significantly more implementation work compared to APIs that offer SDK-managed authentication.
Once authenticated, the API is primarily split across two domains:
This separation is designed for performance and scalability, but it requires you to coordinate requests between two different services.
You’ll also likely interact with the following endpoints:
Related: How to get your Dropbox API key
To follow along with this tutorial, you need the following:
You also need to install a few dependencies:
This installs the official Dropbox SDK and python-dotenv. The Dropbox SDK provides Python classes and methods for interacting with the Dropbox API, and python-dotenv allows you to load environment variables from an ENV file, keeping your API credentials secure and separate from your code.
Always consider installing packages within a Python virtual environment (<code class="blog_inline-code">venv</code>, <code class="blog_inline-code">virtualenv</code>, or <code class="blog_inline-code">conda</code>). This isolates your project's dependencies and ensures consistent versions across development, testing, and production environments.
To access the Dropbox API, you need to create and register your application in the Dropbox App Console.
Once you've signed into your Dropbox account, click Create app and select Scoped access. Then, select the type of access you need. For most use cases, Full Dropbox is fine as it allows your app to access all files and folders in a user's instance of Dropbox. App folder restricts access to a single, dedicated folder for your app. Finally, name your app and click Create app.

Navigate to the Permissions tab. To perform basic file operations, you need to enable the following scopes:

Then go to the Settings tab and find your App key and App secret. These are your application's credentials; treat them like passwords and store them securely.
Create a file in your project directory and name it <code class="blog_inline-code">.env</code>. Save your credentials here to store them as environment variables:
Dropbox uses OAuth 2.0 for authorization, but unlike some APIs, it doesn't provide helper libraries for the complete flow. You’ll need to implement the authorization process manually, which gives you control but requires more code.
Here's a complete OAuth 2.0 implementation:
This code uses the Dropbox Python SDK and the DropboxOAuth2FlowNoRedirect class to generate an authorization link. You visit this link in your browser, approve access, and then paste the code you get back into the app. That's how the app gets permission to use your Dropbox account.
The code also includes functions for storing and retrieving tokens, as well as creating the Dropbox client with the access and refresh tokens. While the SDK automatically refreshes expired access tokens, it doesn't manage token storage or allow rotating refresh tokens. You're responsible for securely storing these tokens and handling refresh token revocation according to your security policy.
To run the script, create a file named <code class="blog_inline-code">dropbox_auth.py</code> and add the previous code. Run it using the following:
Your output should look like this:
Related: How to authenticate with OneDrive's API
With authentication established, you can start working with files. The following are some of the key file operations you can perform with the Dropbox API.
To list the contents of a Dropbox folder, you need to handle pagination because Dropbox returns results in batches. The following example demonstrates how to retrieve all files and folders within a directory, iterating through each page of results until the entire folder is listed:
The code uses the files_list_folder method to retrieve the list of files within the folder. It then iterates over that list, printing the name and ID of each of the entries.
Note: When passing the <code class="blog_inline-code">folder_path</code> to the <code class="blog_inline-code">files_list_folder</code>, be mindful that Dropbox enforces strict path formatting. Absolute paths require a leading slash "/", and an empty "" targets the root. If the folder is shared, your app must have the necessary scopes enabled and may need to use its <code class="blog_inline-code">namespace_id</code> or enable <code class="blog_inline-code">include_mounted_folders</code> to ensure it's included in the results. This is because shared content can exist outside the user's primary namespace.
Related: How to retrieve folders via the Dropbox API
The Dropbox API provides different mechanisms for uploading files based on their size. For files smaller than 150 MB, the <code class="blog_inline-code">files_upload()</code> method is a straightforward approach. You can perform the upload in a single request by reading the file's binary content and passing it to the function along with the desired Dropbox path. An important parameter is mode, which controls how Dropbox handles the upload if a file with the same name already exists. Supported modes include <code class="blog_inline-code">WriteMode('overwrite')</code> to replace the file, <code class="blog_inline-code">WriteMode('add')</code> to keep the existing file and create a renamed copy, and <code class="blog_inline-code">WriteMode('update')</code> to overwrite only if the current revision matches a specific revision ID.
The following is a code snippet showing how to upload small files:
For larger files, the API requires a more robust, session-based approach to ensure reliability. This method involves sending the file in smaller, sequential chunks. The process begins by calling <code class="blog_inline-code">files_upload_session_start()</code> with the first chunk of data, which returns a unique session_id. For all subsequent chunks, use <code class="blog_inline-code">files_upload_session_append_v2()</code>, passing the session_id and using an <code class="blog_inline-code">UploadSessionCursor</code> to track the offset.
Once the final chunk is sent, a call to <code class="blog_inline-code">files_upload_session_finish()</code> commits the file to its path in Dropbox, completing the upload. This chunked approach ensures that large uploads can withstand connection interruptions as only the failed chunk needs to be resent, not the entire file.
Here's a code snippet that uploads a large file:
Just as with uploads, downloading files from Dropbox is a core operation. The <code class="blog_inline-code">files_download()</code> method allows you to retrieve a file's content and its metadata in a single call. However, keep in mind that the API does not provide a direct way to inspect the content type or generate previews; your application must handle the file content based on its extension or other metadata.
Here's a script to download a file:
In this code, the <code class="blog_inline-code">download_file</code> function takes a Dropbox client, the path to the file in Dropbox, and the local path where you want to save the file. It fetches the file from Dropbox and writes it to your local filesystem, printing out useful metadata like the file name and size. Error handling is included to catch and display any issues that occur during the download process, such as HTTP or API errors.
To run this code, copy it into a new file and save it as <code class="blog_inline-code">download_file.py</code>. Update the example file paths in the script to match the Dropbox file you want to download and your desired local filename. Then, open your terminal and run <code class="blog_inline-code">python download_file.py</code>.
All the code samples used in this tutorial are available on GitHub.
Related: A guide to getting files from dropbox
Building a feature-complete Dropbox integration requires you to solve several engineering problems. The OAuth 2.0 flow is manual, the API is split across domains, and large file uploads require a complex, stateful process.
Now, imagine your product needs to support a Google Drive integration. Google Drive uses a completely different resumable upload protocol, and Box has yet another strategy for chunking uploads. The SharePoint API architecture, based on Microsoft Graph, also has its own complexities.
In short, every new file storage platform forces you to learn and implement a new, provider-specific authentication system. You need to write custom logic for different data structures and file hierarchies. Upload and download mechanisms also vary, with different protocols, chunk sizes, and rate limits.
On top of that, each integration must be maintained separately as APIs change and new updates are released. This means supporting different platforms quickly spirals into a significant engineering and maintenance burden, diverting resources from your core product.
Instead of building and maintaining several file storage integrations individually, you can use Merge’s File Storage API to connect to all of them.

Merge also offers:
Learn how Merge can help you build file storage integrations faster and maintain them with ease by scheduling a demo with one of our integration experts.