> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.dropboxapi.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.dropboxapi.com/_mcp/server.

# List Folder Get Latest Cursor

POST https://api.dropboxapi.com/2/files/list_folder/get_latest_cursor
Content-Type: application/json

A way to quickly get a cursor for the folder's state. Unlike [list_folder](api:dropbox-api:POST/2/files/list_folder),
 [list_folder/get_latest_cursor](api:dropbox-api:POST/2/files/list_folder/get_latest_cursor) doesn't return any entries. This endpoint is for app which
 only needs to know about new files and modifications and doesn't need to know about files
 that already exist in Dropbox.

**Required scope:** `files.metadata.read`

**Endpoint format:** [RPC](https://docs.dropboxapi.com/dropbox-api/docs/technical-reference/request-response-formats#rpc-endpoints)

**Authentication:** [User](https://docs.dropboxapi.com/dropbox-api/docs/auth-types#user-authentication), [Dropbox-API-Select-Admin (Whole Team)](https://docs.dropboxapi.com/dropbox-api/docs/auth-types#admin-authentication-via-dropbox-api-select-admin)

Reference: https://docs.dropboxapi.com/dropbox-api/api-reference/user-endpoints/files/list-folder-get-latest-cursor

## Authentication

- `Authorization` header (bearer token, required) — OAuth 2.0 token issued to a specific user. Use `Authorization: Bearer <token>`. Public clients should use the authorization code flow with PKCE (S256). For background or offline access, send `token_access_type=offline` during authorization and use the returned refresh token to obtain new access tokens. You can generate a short-lived access token from the App Console; see [Testing with a generated token](https://docs.dropboxapi.com/dropbox-api/docs/oauth#testing-with-a-generated-token).

## Request

### Headers

- `Dropbox-API-Select-User` (string, optional) — Acts on behalf of a team member for supported user-auth operations. Pass a team member ID such as `dbmid:...`. When used with a team token, that token must also include the `team_data.member` scope.
- `Dropbox-API-Select-Admin` (string, optional) — Acts as the specified team admin for supported user-auth operations. Pass a team member ID for an admin account. When used with a team token, that token must also include the `team_data.member` scope.
- `Dropbox-API-Path-Root` (string, optional) — Scopes path-based operations to a namespace (root). The value is a JSON serialization of the `common.PathRoot` union: `{".tag": "home"}`, `{".tag": "root", "root": "<namespace_id>"}`, or `{".tag": "namespace_id", "namespace_id": "<namespace_id>"}`. On failure the request returns 422 with a `common.PathRootError`.

### Body (application/json)

This endpoint expects an object.

- `path` (string, required) — A unique identifier for the file.
- `include_deleted` (boolean, optional, default: false) — If true, the results will include entries for files and folders that used to exist but were deleted.
- `include_has_explicit_shared_members` (boolean, optional, default: false) — If true, the results will include a flag for each file indicating whether or not that file has any explicit members.
- `include_mounted_folders` (boolean, optional, default: true) — If true, the results will include entries under mounted folders which includes app folder, shared folder and team folder.
- `include_non_downloadable_files` (boolean, optional, default: true) — If true, include files that are not downloadable, i.e. Google Docs.
- `include_property_groups` (object, optional, nullable) — If set to a valid list of template IDs, `FileMetadata.property_groups` is set if there exists property data associated with the file and each of the listed templates.
  - file_properties.TemplateFilterBase.filter_some
    - `.tag` (enum, required)
      - Allowed values: `filter_some`
    - `filter_some` (list of string, required)
- `include_restorable_info` (boolean, optional, default: false) — If true, each returned deleted entry will include whether that entry can be restored.
- `limit` (uint, optional, nullable) — The maximum number of results to return per request. Note: This is an approximate number and there can be slightly more entries returned in some cases.
- `recursive` (boolean, optional, default: false) — If true, the list folder operation will be applied recursively to all subfolders and the response will contain contents of all subfolders. In some cases, setting `ListFolderArg.recursive` to `true` may lead to performance issues or errors, especially when traversing folder structures with a large number of items. A workaround for such cases is to set `ListFolderArg.recursive` to `false` and traverse subfolders one at a time.
- `shared_link` (object, optional, nullable) — A shared link to list the contents of. If the link is password-protected, the password must be provided. If this field is present, `ListFolderArg.path` will be relative to root of the shared link. Only non-recursive mode is supported for shared link.
  - `url` (string, required) — Shared link url.
  - `password` (string, optional, nullable) — Password for the shared link.
- `include_media_info` (boolean, optional, default: false, deprecated) — If true, `FileMetadata.media_info` is set for photo and video. This parameter will no longer have an effect starting December 2, 2019.

## Response

### 200

Successful response

- `cursor` (string, required) — Pass the cursor into [list_folder/continue](api:dropbox-api:POST/2/files/list_folder/continue) to see what's changed in the folder since your previous query.

## Errors

### 401 Unauthorized Error

Bad or expired token

- `error` (object or object or object or object or object or object or object or object, required) — Errors occurred during authentication.
  - auth_apiv2.AuthError.invalid_access_token
    - `.tag` (enum, required)
      - Allowed values: `invalid_access_token`
  - auth_apiv2.AuthError.invalid_select_user
    - `.tag` (enum, required)
      - Allowed values: `invalid_select_user`
  - auth_apiv2.AuthError.invalid_select_admin
    - `.tag` (enum, required)
      - Allowed values: `invalid_select_admin`
  - auth_apiv2.AuthError.user_suspended
    - `.tag` (enum, required)
      - Allowed values: `user_suspended`
  - auth_apiv2.AuthError.expired_access_token
    - `.tag` (enum, required)
      - Allowed values: `expired_access_token`
  - auth_apiv2.AuthError.missing_scope
    - `.tag` (enum, required)
      - Allowed values: `missing_scope`
    - `required_scope` (string, required) — The required scope to access the route.
  - auth_apiv2.AuthError.route_access_denied
    - `.tag` (enum, required)
      - Allowed values: `route_access_denied`
  - Other
    - `.tag` (string, optional)
- `error_summary` (string, required) — A human-readable summary of the error.

### 403 Forbidden Error

The user or team account doesn't have access to the endpoint or feature

- `error` (object or object or object or object or object, required) — Error occurred because the account doesn't have permission to access the resource.
  - auth_apiv2.AccessError.invalid_account_type
    - `.tag` (enum, required)
      - Allowed values: `invalid_account_type`
    - `invalid_account_type` (object or object or object, required)
      - auth_apiv2.InvalidAccountTypeError.endpoint
        - `.tag` (enum, required)
          - Allowed values: `endpoint`
      - auth_apiv2.InvalidAccountTypeError.feature
        - `.tag` (enum, required)
          - Allowed values: `feature`
      - Other
        - `.tag` (string, optional)
  - auth_apiv2.AccessError.paper_access_denied
    - `.tag` (enum, required)
      - Allowed values: `paper_access_denied`
    - `paper_access_denied` (object or object or object, required)
      - auth_apiv2.PaperAccessError.paper_disabled
        - `.tag` (enum, required)
          - Allowed values: `paper_disabled`
      - auth_apiv2.PaperAccessError.not_paper_user
        - `.tag` (enum, required)
          - Allowed values: `not_paper_user`
      - Other
        - `.tag` (string, optional)
  - auth_apiv2.AccessError.team_access_denied
    - `.tag` (enum, required)
      - Allowed values: `team_access_denied`
  - auth_apiv2.AccessError.no_permission
    - `.tag` (enum, required)
      - Allowed values: `no_permission`
    - `no_permission` (object or object, required)
      - auth_apiv2.NoPermissionError.unauthorized_account_id_usage
        - `.tag` (enum, required)
          - Allowed values: `unauthorized_account_id_usage`
        - `unauthorized_account_ids` (list of string, required) — The account IDs that the caller does not have permission to use.
      - Other
        - `.tag` (string, optional)
  - Other
    - `.tag` (string, optional)
- `error_summary` (string, required) — A human-readable summary of the error.

### 409 Conflict Error

Endpoint-specific error

- `error` (object or object or object, required)
  - files.ListFolderError.path
    - `.tag` (enum, required)
      - Allowed values: `path`
    - `path` (object or object or object or object or object or object or object or object, required)
      - files.LookupError.malformed_path
        - `.tag` (enum, required)
          - Allowed values: `malformed_path`
        - `malformed_path` (string, required, nullable)
      - files.LookupError.not_found
        - `.tag` (enum, required)
          - Allowed values: `not_found`
      - files.LookupError.not_file
        - `.tag` (enum, required)
          - Allowed values: `not_file`
      - files.LookupError.not_folder
        - `.tag` (enum, required)
          - Allowed values: `not_folder`
      - files.LookupError.restricted_content
        - `.tag` (enum, required)
          - Allowed values: `restricted_content`
      - files.LookupError.unsupported_content_type
        - `.tag` (enum, required)
          - Allowed values: `unsupported_content_type`
      - files.LookupError.locked
        - `.tag` (enum, required)
          - Allowed values: `locked`
      - Other
        - `.tag` (string, optional)
  - files.ListFolderError.template_error
    - `.tag` (enum, required)
      - Allowed values: `template_error`
    - `template_error` (object or object or object, required)
      - file_properties.TemplateError.template_not_found
        - `.tag` (enum, required)
          - Allowed values: `template_not_found`
        - `template_not_found` (string, required, nullable) — Core data types
      - file_properties.TemplateError.restricted_content
        - `.tag` (enum, required)
          - Allowed values: `restricted_content`
      - Other
        - `.tag` (string, optional)
  - Other
    - `.tag` (string, optional)
- `error_summary` (string, required) — A human-readable summary of the error.
- `user_message` (object, optional)
  - `locale` (string, optional)
  - `text` (string, optional)

### 429 Too Many Requests Error

The app is making too many requests for the given user or team and is being rate limited. The app should wait for the number of seconds specified in the "Retry-After" response header before trying again.

- `error` (object, required) — Error occurred because the app is being rate limited.
  - `reason` (object or object or object, required) — The reason why the app is being rate limited.
    - auth_apiv2.RateLimitReason.too_many_requests
      - `.tag` (enum, required)
        - Allowed values: `too_many_requests`
    - auth_apiv2.RateLimitReason.too_many_write_operations
      - `.tag` (enum, required)
        - Allowed values: `too_many_write_operations`
    - Other
      - `.tag` (string, optional)
  - `retry_after` (uint64, optional, default: 1) — The number of seconds that the app should wait before making another request.
- `error_summary` (string, required) — A human-readable summary of the error.

### 500 Internal Server Error

Internal server error. An error occurred on the Dropbox servers. Check https://status.dropbox.com/ for announcements about Dropbox service issues.

- `any`

## Examples

**Request**

```json
{
  "path": "/Homework/math",
  "recursive": false
}
```

**Response**

```json
{
  "cursor": "ZtkX9_EHj3x7PMkVuFIhwKYXEpwpLwyxp9vMKomUhllil9q7eWiAu"
}
```

**SDK Code**

```python
import requests

url = "https://api.dropboxapi.com/2/files/list_folder/get_latest_cursor"

payload = {
    "path": "/Homework/math",
    "recursive": False
}
headers = {
    "Authorization": "Bearer <token>",
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.json())
```

```javascript
const url = 'https://api.dropboxapi.com/2/files/list_folder/get_latest_cursor';
const options = {
  method: 'POST',
  headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
  body: '{"path":"/Homework/math","recursive":false}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://api.dropboxapi.com/2/files/list_folder/get_latest_cursor"

	payload := strings.NewReader("{\n  \"path\": \"/Homework/math\",\n  \"recursive\": false\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://api.dropboxapi.com/2/files/list_folder/get_latest_cursor")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n  \"path\": \"/Homework/math\",\n  \"recursive\": false\n}"

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://api.dropboxapi.com/2/files/list_folder/get_latest_cursor")
  .header("Authorization", "Bearer <token>")
  .header("Content-Type", "application/json")
  .body("{\n  \"path\": \"/Homework/math\",\n  \"recursive\": false\n}")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.dropboxapi.com/2/files/list_folder/get_latest_cursor', [
  'body' => '{
  "path": "/Homework/math",
  "recursive": false
}',
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'Content-Type' => 'application/json',
  ],
]);

echo $response->getBody();
```

```csharp
using RestSharp;

var client = new RestClient("https://api.dropboxapi.com/2/files/list_folder/get_latest_cursor");
var request = new RestRequest(Method.POST);
request.AddHeader("Authorization", "Bearer <token>");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"path\": \"/Homework/math\",\n  \"recursive\": false\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let headers = [
  "Authorization": "Bearer <token>",
  "Content-Type": "application/json"
]
let parameters = [
  "path": "/Homework/math",
  "recursive": false
] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://api.dropboxapi.com/2/files/list_folder/get_latest_cursor")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```