Create the Dropbox app and connect your account
To let your site read your Dropbox, you create a private "app" in the Dropbox App Console, copy its two keys into WordPress and click Connect Dropbox account. The Dropbox Documents page guides you through it in numbered steps. This article explains each step in detail.
An "app" here is not something you publish or install on a phone. It is just a name and a pair of keys that Dropbox gives you, so that your site can prove it has your permission. Nobody else sees it.
Before you start
- Log in to dropbox.com with the Dropbox account that holds the files you want to share.
- In another browser tab, open your WordPress admin and click Dropbox Documents. Keep this tab open: you will copy values back and forth.
- Make sure your site address starts with
https://. If the plugin page shows "The site is not on HTTPS", enable an SSL certificate with your hosting provider first.
Step 1: create the app on Dropbox
- Open the Dropbox App Console (the page is also linked from step 1 of the plugin page).
- Click Create app.
- Under "Choose an API", select Scoped access.
- Under "Choose the type of access you need", pick one:
- App folder (recommended, safer): Dropbox creates a dedicated folder,
Apps/<your app name>, and the site can only read what is inside it. You put the files to share in that folder. - Full Dropbox: the site can read your whole Dropbox. Choose it if the files are already organised elsewhere in your Dropbox and you do not want to move them. Your access rules then decide which folders visitors actually see.
- App folder (recommended, safer): Dropbox creates a dedicated folder,
- Give the app a name, for example "Portal yoursite". The name must be unique across Dropbox, so add something personal to it.
- Click Create app. Dropbox opens the app settings page, with several tabs at the top.
Step 2: set the permissions
- Click the Permissions tab.
- Tick these three permissions (Dropbox calls them "scopes"):
account_info.readfiles.metadata.readfiles.content.read
- Scroll to the bottom of the page and click Submit.
Do not skip Submit. Without it the permissions are not saved and the connection will fail later with a permission error. If you add permissions after connecting the account, you must also disconnect and reconnect in WordPress: the connection keeps the permissions it was created with.
These are read-only permissions. The plugin never asks for the right to change or delete your files.
Step 3: paste the Redirect URI
The Redirect URI is the address of your site where Dropbox sends you back after you approve the connection. Dropbox only accepts addresses you registered in advance.
- In WordPress, on the Dropbox Documents page, look at step 1 Create your Dropbox app. Under "Settings tab: paste this Redirect URI and press Add." you see your address in a box, with a Copy button. Click Copy.
- Back on Dropbox, click the Settings tab of your app.
- Find the OAuth 2 section and the Redirect URIs field.
- Paste the address and click Add.
The address always has this shape, with your own site address at the start:
https://yoursite.com/wp-admin/admin.php?page=lr-dropbox-portal&lrdbp_oauth=callback
If WordPress is installed in a subfolder, the subfolder is part of it (for example https://yoursite.com/blog/wp-admin/...). Always copy the exact value shown by the plugin: it must match character for character, including the two parts after the question mark.
If your site answers both with and without www, the plugin warns you on the page. Register both variants on Dropbox, or make your site always redirect to one of them.
Step 4: copy the App key and App secret
- Still on the Dropbox Settings tab, find App key and App secret. For the secret, click Show to reveal it.
- Copy the App key and paste it into the App key field in step 1 of the WordPress page.
- Copy the App secret and paste it into the App secret field.
- Scroll to the bottom of the WordPress page and click Save settings.
After saving, the secret field stays empty and shows "Stored: leave empty to keep it". That is normal: the secret is saved but never shown again. Leave it empty when you save other settings later.
Step 5: connect the account
- In step 2 Connect the account, a Connect Dropbox account button is now visible. Click it.
- Dropbox opens and asks you to allow the app to access your account. Check that you are logged in to the right Dropbox account, then click Continue and Allow.
- Dropbox sends you back to WordPress, which shows "Dropbox account connected."
Step 2 now shows your Dropbox name and email with a green Connected badge, plus two buttons: Clear cache and Disconnect.
Check that it works
Under the account, the Connection check panel has a Run check button. It makes two real calls to Dropbox and prints what comes back, with a final line in plain words. If it ends with "Both calls work: the connection to Dropbox is fine.", you are done.
Next: Give roles access to folders. If the connection failed, see Fix Dropbox connection errors.
Installing on several client sites
Each site has its own Redirect URI, generated from its own address. The usual setup is one Dropbox app per site, created in the Dropbox account of that client. You can also add several Redirect URIs to the same app, one per site.
Write to us and tell us which plugin, what you tried and what you see. We answer from Italy, usually within one working day.