dropbox-sdk-js is a free, open source file management & sync project written in JavaScript and released under MIT. It has 970 GitHub stars, 352 forks and 43 open issues, and was last pushed 5 days ago. On this registry it ranks #44 of 45 tracked projects in File Management & Sync, with 5 head-to-head comparisons available.

What is dropbox-sdk-js?

The Dropbox JavaScript SDK is the official MIT-licensed client library for Dropbox API v2, built for developers writing Node.js services, browser applications, and Web Workers that read from or write to Dropbox accounts.

What it is

The Dropbox JavaScript SDK is the officially maintained JavaScript and Node.js client for Dropbox API v2, published on npm as the package named dropbox. It exposes the Dropbox class for API routes across the files, sharing, users, teams, and other namespaces, the DropboxAuth class for OAuth URLs, PKCE, access tokens, and token refresh, and the DropboxResponseError class for errors returned by API requests, alongside a generated Global API that supplies route type definitions. Published packages already contain CommonJS, ES module, browser, and TypeScript builds, so applications install the package rather than compiling it themselves. Supported runtimes are Node.js 22 and newer, modern web browsers, and Web Workers, with continuous integration currently testing Node.js 22 and 24.

The concrete problem it solves is the hand-written HTTP layer that JavaScript developers would otherwise maintain against Dropbox API v2: request construction, generated route bindings, error typing, and the OAuth dance in both of its documented forms. Server applications that can keep an app secret confidential use the regular authorization-code flow, while browser and Worker applications that cannot keep a secret use the authorization-code flow with PKCE and an app key instead, including token refresh. It lives in the Dropbox developer ecosystem and assumes an app registered in the Dropbox Developer Console, whose credentials the SDK then handles for the application.

Key capabilities

  • The Dropbox class covers Dropbox API routes for files, sharing, users, teams, and other namespaces, as in dbx.filesListFolder({ path: '' }) for listing a folder.
  • The DropboxAuth class manages OAuth URLs, PKCE, access tokens, and token refresh; PKCE requires a secure context and the Web Crypto API.
  • The DropboxResponseError class surfaces errors returned by API requests, and a generated Global API publishes route type definitions and a full API reference on GitHub Pages.
  • Published npm packages ship CommonJS, ES module, browser, and TypeScript builds, so no build step is required to consume the SDK.
  • A CDN browser bundle exposes the SDK through the global Dropbox object and can be pinned to an exact version, for example [email protected]/dist/Dropbox-sdk.min.js on jsDelivr.
  • The same browser bundle loads inside a Web Worker through importScripts, allowing background Dropbox operations off the main thread.
  • Runtime requirements are explicit: Node.js uses its built-in fetch, while browsers and Workers must provide Promise, fetch, and TextEncoder, with polyfills for older environments.

Who uses it and how

  • Server-side Node.js applications that hold an app secret and run the regular authorization-code flow; the repository's simple backend example demonstrates a multi-step auth flow for short-lived tokens.
  • Browser applications assembled with bundlers such as Webpack, Rollup, or Vite, which consume the package's ES module build directly.
  • Client-side applications that cannot keep a secret, which use the authorization-code flow with PKCE and an app key, as shown in the browser PKCE example, and must never embed an app secret in browser or Worker code.
  • Web Worker code loading the pinned CDN bundle via importScripts, where the browser bundle's global Dropbox object is reused unchanged.
  • TypeScript teams, since the package includes TypeScript builds and most examples are published in both JavaScript and TypeScript.

Getting started

Create an app in the Dropbox Developer Console, install the SDK with npm install dropbox, and construct new Dropbox({ accessToken }) for server or bundler use, or load the pinned CDN bundle in a browser or Worker. Installing from source with git clone, npm install, and npm run build is only necessary when developing the SDK itself or running the repository's examples directly.

How it compares

This registry entry names no comparable sibling projects, and the facts provide no list of paid products the SDK replaces, so it stands alone in this registry on the evidence available. Its distinguishing position is simply that it is the official client rather than a community alternative, and no other tool in the provided facts occupies that slot.

When to use it — and when not to

There is no server to operate: this is a client library with no database, storage, or SMTP of its own, but it does require an app registration, OAuth credentials, and network access to Dropbox's hosted service, so the files it touches live in Dropbox rather than on infrastructure the developer controls. Teams that cannot depend on that hosted backend, that must keep user data on their own servers, or that target runtimes older than Node.js 22 or browsers lacking fetch, TextEncoder, and the Web Crypto API should expect to add polyfills or choose a different integration. The MIT licence covers the SDK source only, the README excerpt provided here is truncated partway through its example list, and 43 open issues are tracked, so details beyond authentication and the documented examples are worth confirming against the published API reference.

project readme (upstream, from github) — read inline

Dropbox JavaScript SDK

Node.js 22 and 24 npm version codecov

The official Dropbox API v2 SDK for JavaScript.

Runtime support

The SDK supports Node.js 22 and newer, modern web browsers, and Web Workers. Continuous integration currently tests Node.js 22 and 24, and Node.js uses its built-in fetch implementation. Browser and Worker environments must provide Promise, fetch, and TextEncoder; PKCE authentication also requires the Web Crypto API. Add polyfills when targeting older environments that do not provide the required APIs.

Installation

Create an app in the Developer Console, then install the SDK from npm. Published npm packages already contain CommonJS, ES module, browser, and TypeScript builds; applications do not need to build the SDK from source. Published versions and release history are available on the npm versions page.

npm install dropbox

Node.js

const { Dropbox } = require('dropbox');

const dbx = new Dropbox({
  accessToken: process.env.DROPBOX_ACCESS_TOKEN,
});

dbx.filesListFolder({ path: '' })
  .then(({ result }) => console.log(result.entries))
  .catch(console.error);

Browser application with a bundler

Webpack, Rollup, Vite, and similar tools can use the package's ES module build.

import { Dropbox } from 'dropbox';

const dbx = new Dropbox({ accessToken: 'YOUR_ACCESS_TOKEN' });

Browser application from a CDN

The browser bundle exposes the SDK through the global Dropbox object. Pin an exact SDK version so a future breaking release cannot change your application unexpectedly.

<script src="https://cdn.jsdelivr.net/npm/[email protected]/dist/Dropbox-sdk.min.js"></script>
<script>
  const dbx = new Dropbox.Dropbox({ accessToken: 'YOUR_ACCESS_TOKEN' });
</script>

Do not hard-code production access tokens in public source code.

For debugging, use the unminified bundle:

<script src="https://cdn.jsdelivr.net/npm/[email protected]/dist/Dropbox-sdk.js"></script>

Web Worker

The same browser bundle can be loaded in a Worker:

importScripts('https://cdn.jsdelivr.net/npm/[email protected]/dist/Dropbox-sdk.min.js');

const dbx = new Dropbox.Dropbox({ accessToken: 'YOUR_ACCESS_TOKEN' });

Install from source

Building is required only when developing the SDK itself or running examples directly from this repository.

git clone https://github.com/dropbox/dropbox-sdk-js.git
cd dropbox-sdk-js
npm install
npm run build

Browser authentication and PKCE

Client-side applications cannot keep an app secret confidential. Never embed a Dropbox app secret in browser or Worker code. Use the OAuth authorization-code flow with PKCE and your app key instead. See the browser PKCE example and the Dropbox OAuth guide. PKCE requires a secure context and the Web Crypto API.

Server applications can keep an app secret confidential and may use the regular authorization-code flow.

API reference

The complete generated API reference is published on GitHub Pages.

Examples

The examples demonstrate common SDK operations. Most are available in both JavaScript and TypeScript, with additional Node.js OAuth examples.

  • OAuth

    • Auth - [ JS ] - A simple auth example to get an access token and list the files in the root of your Dropbox account.
    • Simple Backend [ JS ] - A simple example of a node backend doing a multi-step auth flow for Short Lived Tokens.
    • PKCE Backend [ JS ] - A simple example of a node backend doing a multi-step auth flow using PKCE and Short Lived Tokens.
    • PKCE Browser [ JS ] - A simple example of a frontend doing a multi-step auth flow using PKCE and Short Lived Tokens.
  • Other Examples

    • Basic - [ TS, JS ] - A simple example that takes in a token and fetches files from your Dropbox account.
    • Backend Download - [ JS ] - An example showing resumable backend downloads to local storage.
    • Download - [ TS, JS ] - An example showing how to download a shared file.
    • Team As User - [ TS, JS ] - An example showing how to act as a user.
    • Team - [ TS, JS ] - An example showing how to use the team functionality and list team devices.
    • Upload [ TS, JS ] - An example showing how to upload a file to Dropbox.

Reliable file transfers

For Node.js applications that need resumable local downloads or retrying uploads, the SDK exports file transfer helpers alongside the generated API methods.

const {
  Dropbox,
  DropboxFileUploader,
  bytesUpload,
  downloadFile,
  fileUpload,
  readerUpload,
  sizedReaderUpload,
} = require('dropbox');

const dbx = new Dropbox({ accessToken: process.env.DROPBOX_ACCESS_TOKEN });

await downloadFile(dbx, '/large-file.bin', './large-file.bin', {
  parallelDownloads: 4,
  progress: ({ bytesWritten, totalBytes }) => {
    console.log(`${bytesWritten}/${totalBytes}`);
  },
});

const uploader = new DropboxFileUploader(dbx, {
  progress: ({ bytesCommitted, totalBytes }) => {
    console.log(`${bytesCommitted}/${totalBytes}`);
  },
});

await uploader.upload(
  await fileUpload('./large-file.bin'),
  { path: '/large-file.bin', mode: { '.tag': 'overwrite' } },
);

await uploader.upload(
  bytesUpload('hello from the Dropbox SDK\n'),
  { path: '/hello.txt' },
);

Downloads write to localPath + ".part" and rename the file after validating the final size and Dropbox content_hash metadata when present. Uploads retry transient failures at the individual session request, reconcile committed offsets after lost responses, and use upload sessions for every source. Pass parallelUploads for repeatable byte or file sources, or use readerUpload() and sizedReaderUpload() for one-shot Node readable streams.

Getting Help

If you find a bug, please see CONTRIBUTING.md for information on how to report it.

If you need help that is not specific to this SDK, please reach out to Dropbox Support.

License

This SDK is distributed under the MIT license, please see LICENSE for more information.

Frequently asked questions

Is dropbox-sdk-js free to use?

dropbox-sdk-js is open source under the MIT licence. There is no licence fee and no seat count — you can self-host it or, where the project offers one, pay a vendor for a managed version instead.

What does dropbox-sdk-js do?

The Official Dropbox API V2 SDK for Javascript

What is dropbox-sdk-js written in?

dropbox-sdk-js is primarily written in JavaScript. Its source is publicly available at https://github.com/dropbox/dropbox-sdk-js, and it has 970 GitHub stars.