Box sign in

Remote stays available: paste the box token once, or sign in with an installed owner/admin login. Either sets an httpOnly session cookie via the same-origin /api proxy. Admin (or the box token) is required to create users and issue grants. First owner is POST /api/install/owner, not anonymous POST /users.

Owner setup code

Got a one-time setup code? Use it to create your admin login, or to reset its password if you already have one. Pick a password of at least 12 characters. The code works once.