Box Developer Documentation
 
    Latest version

    Create retention policy

    post
    https://api.box.com/2.0
    /retention_policies

    This endpoint is in the version 2024.0. No changes are required to continue using it. For more details, see Box API versioning.

    Creates a retention policy.

    Request

    bearer [ACCESS_TOKEN]
    application/json

    Request Body

    booleanin bodyoptional
    true

    Whether owner and co-owners of a file are notified when the policy nears expiration.

    booleanin bodyoptional
    true

    Whether the owner of a file will be allowed to extend the retention.

    A list of users notified when the retention policy duration is about to end.

    stringin bodyoptional
    "Policy to retain all reports for at least one month"

    The additional text description of the retention policy.

    stringin bodyrequired
    "permanently_delete"

    The disposition action of the retention policy. permanently_delete deletes the content retained by the policy permanently. remove_retention lifts retention policy from the content, allowing it to be deleted by users once the retention policy has expired.

    Value is one of permanently_delete,remove_retention

    stringin bodyrequired
    "Some Policy Name"

    The name for the retention policy

    stringin bodyrequired
    "finite"

    The type of the retention policy. A retention policy type can either be finite, where a specific amount of time to retain the content is known upfront, or indefinite, where the amount of time to retain the content is still unknown.

    Value is one of finite,indefinite

    string (int32) / number (int32) in body
    "365"

    The length of the retention policy. This value specifies the duration in days that the retention policy will be active for after being assigned to content. If the policy has a policy_type of indefinite, the retention_length will also be indefinite.

    stringin bodyoptional
    "modifiable"

    Specifies the retention type:

    • modifiable: You can modify the retention policy. For example, you can add or remove folders, shorten or lengthen the policy duration, or delete the assignment. Use this type if your retention policy is not related to any regulatory purposes.

    • non_modifiable: You can modify the retention policy only in a limited way: add a folder, lengthen the duration, retire the policy, change the disposition action or notification settings. You cannot perform other actions, such as deleting the assignment or shortening the policy duration. Use this type to ensure compliance with regulatory retention policies.

    Value is one of modifiable,non_modifiable

    Response

    application/jsonRetention policy

    Returns a new retention policy object.

    application/jsonClient error

    Returns a bad_request error with the retention_length was specified for a infinite retention policy, an incorrect disposition_action was set, or description exceeds maximum length of 500 characters.

    application/jsonClient error

    Returns an error if a retention policy with the given name already exists

    application/jsonClient error

    An unexpected client error.

    post
    Create retention policy
    You can now try out some of our APIs live, right here in the documentation.
    Log in

    Request Example

    cURL
    curl -i -X POST "https://api.box.com/2.0/retention_policies" \
         -H "authorization: Bearer <ACCESS_TOKEN>" \
         -H "content-type: application/json" \
         -d '{
           "policy_name": "Some Policy Name",
           "policy_type": "finite",
           "retention_length": 365,
           "disposition_action": "permanently_delete"
         }'

    Response Example

    {
      "id": "12345",
      "type": "retention_policy",
      "are_owners_notified": false,
      "assignment_counts": {
        "enterprise": 1,
        "folder": 1,
        "metadata_template": 1
      },
      "can_owner_extend_retention": false,
      "created_at": "2012-12-12T10:53:43-08:00",
      "created_by": {
        "id": "11446498",
        "type": "user",
        "login": "ceo@example.com",
        "name": "Aaron Levie"
      },
      "custom_notification_recipients": [
        {
          "id": "11446498",
          "type": "user",
          "login": "ceo@example.com",
          "name": "Aaron Levie"
        }
      ],
      "description": "Policy to retain all reports for at least one month",
      "disposition_action": "permanently_delete",
      "modified_at": "2012-12-12T10:53:43-08:00",
      "policy_name": "Some Policy Name",
      "policy_type": "finite",
      "retention_length": "365",
      "retention_type": "non_modifiable",
      "status": "active"
    }