> ## Documentation Index
> Fetch the complete documentation index at: https://developer.box.com/llms.txt
> Use this file to discover all available pages before exploring further.

# App Tokens without SDKs

export const MultiRelatedLinks = ({sections = []}) => {
  if (!sections || sections.length === 0) {
    return null;
  }
  return <div className="space-y-8">
      {sections.map((section, index) => <RelatedLinks key={index} title={section.title} items={section.items} />)}
    </div>;
};

export const RelatedLinks = ({title, items = []}) => {
  const getBadgeClass = badge => {
    if (!badge) return "badge-default";
    const badgeType = badge.toLowerCase().replace(/\s+/g, "-");
    return `badge-${badge === "ガイド" ? "guide" : badgeType}`;
  };
  if (!items || items.length === 0) {
    return null;
  }
  return <div className="my-8">
      {}
      <h3 className="text-sm font-bold uppercase tracking-wider mb-4">{title}</h3>

      {}
      <div className="flex flex-col gap-3">
        {items.map((item, index) => <a key={index} href={item.href} className="py-2 px-3 rounded related_link hover:bg-[#f2f2f2] dark:hover:bg-[#111827] flex items-center gap-3 group no-underline hover:no-underline border-b-0">
            {}
            <span className={`px-2 py-1 rounded-full text-xs font-semibold uppercase tracking-wide flex-shrink-0 ${getBadgeClass(item.badge)}`}>
              {item.badge}
            </span>

            {}
            <span className="text-base">{item.label}</span>
          </a>)}
      </div>
    </div>;
};

<RelatedLinks
  title="REQUIRED GUIDES"
  items={[
{ label: translate("Select Auth Method"), href: "/guides/authentication/select", badge: "GUIDE" },
{ label: translate("Setup with App Token Auth"), href: "/guides/authentication/app-token/app-token-setup", badge: "GUIDE" }
]}
/>

If you are not ready to use any of the official Box SDKs, or an SDK is not
available in your language of choice, it is totally possible to use the Box APIs
without them.

App Token authentication is designed for working directly with the
Box API without requiring a user to redirect through Box to authorize your
application, yet is restricted to the application's own data.

<Note>
  The method of authentication through JWT is inherently tied to the Service
  Account for the application. Any API call made with this token will seem to
  come from this application and will not have access to files and folders from
  other users without explicitly getting access them.
</Note>

## Prerequisites

Before we can get started, you will need to have completed the following steps.

* Create a Box Application within the developer console
* Ensure the application is configured to use App Token authentication
* Generate a primary and secondary App Token for the application and store the tokens somewhere in your code.

## Making API calls

To use an App Token directly the application can use the App Token the same way
it would use any Access Token.

```sh theme={null}
curl https://api.box.com/2.0/users/me \
    -H "authorization: Bearer EGmDmRVfhfHsqesn5yVYHAqUkD0dyDfk"
```

<RelatedLinks
  title="RELATED APIS"
  items={[
{ label: translate("Authorize user"), href: "/reference/get-authorize", badge: "GET" }
]}
/>

<RelatedLinks
  title="RELATED GUIDES"
  items={[
{ label: translate("Downscope a Token"), href: "/guides/authentication/tokens/downscope", badge: "GUIDE" }
]}
/>
