Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

All issues

'Full Dropbox' OAuth: third-party apps that can read your entire account

2021 (scoped-access rollout)

MediumStatus: OngoingProduct: Dropbox APIYear: 2021

Dropbox's API lets connected third-party apps request 'Full Dropbox' access to a user's entire account, and broad OAuth scopes mean an app users link for one task can often read far more than they expect.

What happened

Dropbox's developer platform offers apps two content-access levels: an isolated 'App folder,' or 'Full Dropbox,' which grants scoped access to the user's entire Dropbox. In 2020–2021 Dropbox migrated to granular OAuth scopes and short-lived tokens, and now reviews production apps to discourage unnecessarily broad permissions — improvements that acknowledge how much access apps had previously been granted.

The residual privacy issue is well documented in the OAuth ecosystem generally and applies to Dropbox: users routinely approve connection prompts without reading them, and a 'Full Dropbox' grant gives a third party persistent ability to read (and often write) across all of a user's files until the user manually revokes it in account settings. Because the granted token, not the user, then acts on the files, a compromised or careless integration can expose a user's documents without any further action by the user — a different privacy surface from Dropbox's own access, layered on top of it.

Impact

The model means a user's exposure is only as strong as the least-trustworthy app they have ever connected. 'Full Dropbox' grants and forgotten integrations create a long tail of third parties holding standing access to private files, and shift part of the privacy burden onto users to audit and revoke connections they no longer use.

Dropbox's Response / Official Position

Dropbox rolled out scoped apps, enhanced permissions, and short-lived tokens, urges developers to request least-privilege scopes, reviews apps for over-broad permissions during production approval, and provides an account page where users can review and revoke connected apps.

Sources

Related guides

Spot an error, or have a source to add?
Report an error / suggest update

Related issues

2 sources
Medium

2026 root-certificate change forces SDK upgrades or apps lose API access

Because some official Dropbox SDKs pinned root certificates, Dropbox's switch to a new certificate root starting 1 January 2026 means apps on the Java, .NET, or Python SDK must upgrade to specific minimum versions or lose access to the API.

Current / Ongoing Issues (2024–2026)Developer, API & Platform
Read documentation

Because Dash can be downloaded and set up with 'no sales or IT required,' an individual employee can connect and index an organization's apps and browser history without administrator oversight — recreating the shadow-IT data-governance risk that earlier consumer Dropbox use posed to enterprises.

Privacy & Encryption ConcernsCurrent / Ongoing Issues (2024–2026)Account Lockouts & Support Failures
Read documentation

Dropbox repeatedly assures users that AI features do not train on their data and that content is deleted within 30 days — but because these are revocable policy promises layered over server-side access rather than technical guarantees, security commentators remain skeptical that the assurances will hold.

Privacy & Encryption ConcernsCurrent / Ongoing Issues (2024–2026)
Read documentation

Through 2025 Dropbox pushed Dash to general availability with self-serve sign-up and no IT required, marketing it as an AI assistant that indexes content across all of a user's connected apps — a model that, by design, reaches far beyond the files stored in Dropbox.

Privacy & Encryption ConcernsProduct Changes & User BacklashCurrent / Ongoing Issues (2024–2026)
Read documentation