Box 数据 API:文件、配额与协作接口
Box Android 应用是 Box 企业内容平台的移动客户端——美国及全球大型企业存放合同、报告与共享工作区的系统记录。团队用它浏览“全部文件”、预览文档、邀请协作者、解析共享链接,并就自己的内容向内置 AI 助手提问。
作为数据源,该应用开放了这些界面背后的对象:带 space_used、space_amount 与 max_upload_size 配额计数器的账户资料;条目携带 sha1、owned_by 与 shared_link 统计的分页文件夹列表;以 accessible_by 和 invite_email 为键的协作者名单;以及最近项目、事件流、评论与 AI 会话。合规与 IT 团队在其之上构建存储配额看板、面向过度共享文档的 DLP 扫描、共享链接访问审计与 HRIS 名单同步。
Box 是 Box 企业内容云的官方 Android 应用,被美国及全球企业广泛用于存储、预览、共享和评论工作文档。其界面背后是一套丰富的业务数据集:带存储配额的账户资料,含哈希值、所有者与共享链接统计的文件夹和文件清单,协作者名单、评论、事件流,以及 AI 辅助的文档问答。openData Studio 将这些数据转化为可调用的开放数据,用于存储配额看板、DLP 过度共享扫描、共享链接访问审计与 HRIS 名单同步。
应用截图
API 端点一览
以下端点与请求/响应示例均依据应用界面推导重构,为示意说明,并非实际抓包。
OAuth2 令牌签发与刷新
POST
/v1/identity/tokenopendata把授权码或 refresh_token 兑换为其余内容 API 所需的 Bearer access_token,支持 PKCE code_verifier 与 JWT-bearer 企业登录。
认证方式: OAuth2 authorization_code 或 refresh_token 授权,携带 client_id、client_secret 及(PKCE 场景)code_verifier。返回的 Bearer access_token 会附加到后续 API 调用。
- access_token
- expires_in
- refresh_token
- token_type
- issued_token_type
- restricted_to
POST /v1/identity/token HTTP/1.1 Content-Type: application/x-www-form-urlencoded grant_type=authorization_code&code=SplxlOBeZQQYbYS6WxSbIA&client_id=example-client-id&client_secret=******&code_verifier=dBjftJeZ4CVP-mB92K27uhbUJU1p1r_wW1gFWFOEjXk{ "access_token": "c3FIOG9vZE5ob2VlOW1pZg", "expires_in": 3600, "restricted_to": [], "refresh_token": "XAa1eFv3k3qQYk1z3xY2bQ", "token_type": "bearer", "issued_token_type": "urn:ietf:params:oauth:token-type:access_token" }依据应用的登录与静默令牌刷新流程重建先于其他所有内容调用运行,用于签发 Bearer 令牌
当前用户身份与存储配额
GET
/v1/cloud/accountosint返回已登录用户的资料,以及账户页面与上传预检所用的存储配额(space_amount / space_used)和 max_upload_size。
认证方式: Authorization: Bearer <access_token>,取自 POST /v1/identity/token。
- type
- id
- name
- login
- space_amount
- space_used
- max_upload_size
- avatar_url
- hostname
- enterprise
- created_at
- modified_at
- my_tags
GET /v1/cloud/account?fields=type,id,name,login,created_at,modified_at,space_amount,space_used,max_upload_size,avatar_url,enterprise HTTP/1.1 Authorization: Bearer c3FIOG9vZE5ob2VlOW1pZg{ "type": "user", "id": "17738362", "name": "Jane Doe", "login": "[email protected]", "created_at": "2021-03-04T09:12:36-08:00", "modified_at": "2026-09-12T11:04:02-07:00", "space_amount": 10737418240, "space_used": 2147483648, "max_upload_size": 53687091200, "avatar_url": "https://cdn.example.net/avatar/large/17738362", "hostname": "https://cloud.example.net/", "enterprise": {"type": "enterprise", "id": "421317", "name": "Acme Corp"}, "my_tags": ["legal", "q3"] }与账户页面的存储用量条和套餐上限一致上传预检在开始前读取这些配额字段
列出文件夹条目
GET
/v1/cloud/folders/{folder_id}/itemsopendata分页返回文件夹内容(“全部文件”使用 folder_id 0),条目含文件/文件夹类型、size、sha1、所有者与可选 shared_link——对应“全部文件”浏览页。
认证方式: Authorization: Bearer <access_token>,取自 POST /v1/identity/token。
- entries
- total_count
- limit
- offset
- order
- next_marker
- id
- type
- name
- size
- etag
- sha1
- owned_by
- shared_link
GET /v1/cloud/folders/0/items?limit=100&offset=0&fields=id,type,name,size,etag,parent,owned_by,modified_at,sha1,shared_link HTTP/1.1 Authorization: Bearer c3FIOG9vZE5ob2VlOW1pZg{ "total_count": 2, "limit": 100, "offset": 0, "order": [{"by": "type", "direction": "ASC"}], "next_marker": null, "entries": [ {"type": "folder", "id": "192429761", "name": "Contracts", "etag": "1", "modified_at": "2026-09-01T10:11:12-07:00", "owned_by": {"type": "user", "id": "17738362", "name": "Jane Doe", "login": "[email protected]"}}, {"type": "file", "id": "5000948880", "name": "Q3-report.pdf", "size": 629644, "sha1": "134b65991ed521fcfe4724b7d1761c795645de57", "etag": "3", "shared_link": {"url": "https://share.example.net/s/abc", "access": "open", "download_url": "https://share.example.net/d/abc.pdf"}} ] }支撑“全部文件”浏览页的分页条目行字段与文件列表及其排序菜单的渲染一致
文件元数据
GET
/v1/cloud/files/{file_id}opendata加载单个文件的元数据供预览/详情面板使用:size、sha1、版本、所有者、路径、权限与共享链接统计。
认证方式: Authorization: Bearer <access_token>,取自 POST /v1/identity/token。
- id
- type
- name
- size
- sha1
- etag
- created_at
- modified_at
- owned_by
- path_collection
- permissions
- shared_link
- file_version
- comment_count
- annotation_count
- version_number
- item_status
GET /v1/cloud/files/5000948880?fields=id,type,name,size,sha1,etag,created_at,modified_at,owned_by,path_collection,permissions,shared_link,file_version,comment_count HTTP/1.1 Authorization: Bearer c3FIOG9vZE5ob2VlOW1pZg{ "type": "file", "id": "5000948880", "name": "Q3-report.pdf", "size": 629644, "sha1": "134b65991ed521fcfe4724b7d1761c795645de57", "etag": "3", "created_at": "2026-08-12T09:00:00-07:00", "modified_at": "2026-09-12T11:04:02-07:00", "content_created_at": "2026-08-12T09:00:00-07:00", "content_modified_at": "2026-09-12T11:04:02-07:00", "comment_count": 4, "annotation_count": 1, "version_number": "3", "item_status": "active", "owned_by": {"type": "user", "id": "17738362", "name": "Jane Doe", "login": "[email protected]"}, "path_collection": {"total_count": 1, "entries": [{"type": "folder", "id": "0", "name": "All Files"}]}, "permissions": {"can_download": true, "can_preview": true, "can_comment": true}, "shared_link": {"url": "https://share.example.net/s/abc", "access": "open", "is_password_enabled": false, "download_count": 12, "preview_count": 40}, "file_version": {"type": "file_version", "id": "12345", "sha1": "134b65991ed521fcfe4724b7d1761c795645de57"} }填充单个文件的预览头部与详情面板权限与版本字段驱动分享面板和历史视图
下载文件内容
GET
/v1/cloud/files/{file_id}/downloadopendata流式返回文件字节(或重定向到短期有效的下载地址),供预览与“保存到设备”操作使用。
认证方式: Authorization: Bearer <access_token>,取自 POST /v1/identity/token。
- Location
GET /v1/cloud/files/5000948880/download HTTP/1.1 Authorization: Bearer c3FIOG9vZE5ob2VlOW1pZgHTTP/1.1 302 Found Location: https://cdn.example.net/d/1/a1b2c3.../download (binary PDF body after follow)依据预览与“保存到设备”操作重建Range 支持让传输管理器续传部分下载
简单 multipart 文件上传
POST
/v1/cloud/uploads/fileopendata通过 multipart 的 attributes 与 file 两部分把新文件上传进父文件夹——相机/扫描与分享到 Box 的小文件流程。
认证方式: Authorization: Bearer <access_token>,取自 POST /v1/identity/token。
- total_count
- entries
- id
- type
- name
- size
- sha1
- etag
- parent
POST /v1/cloud/uploads/file HTTP/1.1 Authorization: Bearer c3FIOG9vZE5ob2VlOW1pZg Content-Type: multipart/form-data; boundary=----ExampleBoundary ------ExampleBoundary Content-Disposition: form-data; name="attributes" {"name":"scan.jpg","parent":{"id":"192429761"}} ------ExampleBoundary Content-Disposition: form-data; name="file"; filename="scan.jpg" Content-Type: image/jpeg <binary> ------ExampleBoundary--{ "total_count": 1, "entries": [ {"type": "file", "id": "5000949001", "name": "scan.jpg", "size": 184320, "sha1": "aabbccdd", "etag": "0", "parent": {"type": "folder", "id": "192429761", "name": "Contracts"}} ] }依据相机/扫描与分享面板的上传流程重建小文件在单个 multipart 请求内完成
创建分片上传会话
POST
/v1/cloud/uploads/sessionopendata为大文件开启分片上传会话,返回 part_size 与 session_endpoints,供带进度条的上传器使用。
认证方式: Authorization: Bearer <access_token>,取自 POST /v1/identity/token。
- id
- type
- session_expires_at
- part_size
- total_parts
- num_parts_processed
- session_endpoints
POST /v1/cloud/uploads/session HTTP/1.1 Authorization: Bearer c3FIOG9vZE5ob2VlOW1pZg Content-Type: application/json {"folder_id": "192429761", "file_size": 104857600, "file_name": "archive.zip"}{ "id": "F9835", "type": "upload_session", "session_expires_at": "2026-09-29T18:00:00Z", "part_size": 8388608, "total_parts": 13, "num_parts_processed": 0, "session_endpoints": { "upload_part": "https://uploads.example.net/v1/cloud/uploads/session/F9835/parts", "commit": "https://uploads.example.net/v1/cloud/uploads/session/F9835/commit", "abort": "https://uploads.example.net/v1/cloud/uploads/session/F9835", "list_parts": "https://uploads.example.net/v1/cloud/uploads/session/F9835/parts", "status": "https://uploads.example.net/v1/cloud/uploads/session/F9835" } }与大文件上传器及其分片进度条一致part_size 与会话地址簿驱动可续传的传输循环
全文文件搜索
GET
/v1/cloud/searchopendata跨文件与文件夹执行全文搜索(可选展开最近的共享链接),支撑应用内搜索页。
认证方式: Authorization: Bearer <access_token>,取自 POST /v1/identity/token。
- total_count
- limit
- offset
- entries
- id
- type
- name
- size
- sha1
- modified_at
GET /v1/cloud/search?query=invoice&limit=25&offset=0&type=file&ancestor_folder_ids=0 HTTP/1.1 Authorization: Bearer c3FIOG9vZE5ob2VlOW1pZg{ "total_count": 1, "limit": 25, "offset": 0, "entries": [ {"type": "file", "id": "5000948880", "name": "Q3-invoice.pdf", "size": 120044, "sha1": "ddeeff", "modified_at": "2026-09-10T08:00:00-07:00"} ] }支撑应用内跨文件与文件夹的搜索页支持结果中展示的最近共享链接展开
解析共享链接
GET
/v1/cloud/shared/resolveopendata把共享链接 URL(可选密码/一次性验证码)解析为底层文件或文件夹及链接统计——对应从链接打开的流程。
认证方式: Authorization: Bearer <access_token>,取自 POST /v1/identity/token。共享链接 URL 经专用链接请求头传递,可附带链接密码;降权的仅链接令牌同样可用。
- id
- type
- name
- size
- shared_link
- url
- download_url
- access
- effective_permission
- is_password_enabled
- download_count
- preview_count
- permissions
GET /v1/cloud/shared/resolve HTTP/1.1 Authorization: Bearer c3FIOG9vZE5ob2VlOW1pZg X-Shared-Link: https://share.example.net/s/abc123; password=secret{ "type": "file", "id": "5000948880", "name": "Q3-report.pdf", "size": 629644, "shared_link": { "url": "https://share.example.net/s/abc123", "download_url": "https://share.example.net/d/abc123.pdf", "vanity_url": null, "access": "open", "effective_access": "open", "effective_permission": "can_download", "is_password_enabled": true, "download_count": 12, "preview_count": 40, "unshared_at": null, "permissions": {"can_preview": true, "can_download": true, "can_edit": false} } }依据粘贴分享链接后的打开流程重建返回文件打开前展示的链接统计横幅
列出文件夹协作关系
GET
/v1/cloud/folders/{folder_id}/collaboratorsopendata列出文件夹上的协作者(invite_email 与 accessible_by 用户),供“共享/邀请成员”页面使用;文件级变体暴露单个文件的相同名单。
认证方式: Authorization: Bearer <access_token>,取自 POST /v1/identity/token。
- total_count
- entries
- id
- type
- invite_email
- accessible_by
- login
- name
GET /v1/cloud/folders/192429761/collaborators?limit=100 HTTP/1.1 Authorization: Bearer c3FIOG9vZE5ob2VlOW1pZg{ "total_count": 2, "entries": [ {"type": "collaboration", "id": "791293", "invite_email": null, "accessible_by": {"type": "user", "id": "8702724", "name": "Sam Lee", "login": "[email protected]"}}, {"type": "collaboration", "id": "791294", "invite_email": "[email protected]", "accessible_by": null} ] }支撑“邀请成员”面板与协作者头像行待接受的邀请在被接受前携带 invite_email
最近项目
GET
/v1/cloud/recentsopendata返回最近预览或编辑过的项目,供“最近”标签页使用;客户端也会把新打开的项目回报到同一 feed。
认证方式: Authorization: Bearer <access_token>,取自 POST /v1/identity/token。
- total_count
- limit
- entries
- type
- interaction_type
- interacted_at
- item
GET /v1/cloud/recents?limit=50 HTTP/1.1 Authorization: Bearer c3FIOG9vZE5ob2VlOW1pZg{ "total_count": 1, "limit": 50, "entries": [ {"type": "recent_item", "interaction_type": "item_preview", "interacted_at": "2026-09-28T16:02:11-07:00", "item": {"type": "file", "id": "5000948880", "name": "Q3-report.pdf", "size": 629644}} ] }以预览和编辑过的项目填充“最近”标签页interaction_type 反映项目最近一次的触碰方式
用户事件流
GET
/v1/cloud/eventsopendata轮询用户(或企业)事件流,驱动最近项目同步与长轮询变更通知。
认证方式: Authorization: Bearer <access_token>,取自 POST /v1/identity/token。
- chunk_size
- next_stream_position
- entries
- event_id
- event_type
- created_at
- created_by
- source
GET /v1/cloud/events?stream_type=all&stream_position=now&limit=100 HTTP/1.1 Authorization: Bearer c3FIOG9vZE5ob2VlOW1pZg{ "chunk_size": 1, "next_stream_position": "1152922976252290886", "entries": [ {"type": "event", "event_id": "f82c3ba03e41f7e8a7608363cc6c39ac", "event_type": "ITEM_PREVIEW", "created_at": "2026-09-28T16:02:11-07:00", "created_by": {"type": "user", "id": "17738362", "name": "Jane Doe", "login": "[email protected]"}, "source": {"type": "file", "id": "5000948880", "name": "Q3-report.pdf"}} ] }驱动最近项目同步与长轮询变更通知stream_position 分页与客户端的追赶循环一致
列出收藏集(Favorites)
GET
/v1/cloud/collectionsopendata列出用户的收藏集(默认为 Favorites),供星标/收藏操作与“收藏”标签页读取;每个收藏集的条目以与文件夹相同的分页结构加载。
认证方式: Authorization: Bearer <access_token>,取自 POST /v1/identity/token。
- total_count
- limit
- entries
- id
- type
- name
- collection_type
GET /v1/cloud/collections?limit=100 HTTP/1.1 Authorization: Bearer c3FIOG9vZE5ob2VlOW1pZg{ "total_count": 1, "limit": 100, "entries": [ {"type": "collection", "id": "405105", "name": "Favorites", "collection_type": "favorites"} ] }支撑“收藏”标签页与文件上的星标开关收藏集内容按分页文件夹列表方式加载
创建文件评论
POST
/v1/cloud/commentsopendata在文件上发表评论(回复、编辑与删除使用同一评论资源),对应预览页的评论串。
认证方式: Authorization: Bearer <access_token>,取自 POST /v1/identity/token。
- id
- type
- message
- tagged_message
- created_at
- created_by
- modified_at
- item
- permissions
POST /v1/cloud/comments?fields=item,tagged_message,message,created_at,created_by,modified_at,permissions HTTP/1.1 Authorization: Bearer c3FIOG9vZE5ob2VlOW1pZg Content-Type: application/json {"item": {"type": "file", "id": "5000948880"}, "message": "Please review section 3."}{ "type": "comment", "id": "191969", "message": "Please review section 3.", "tagged_message": "Please review section 3.", "created_at": "2026-09-28T16:10:00-07:00", "modified_at": "2026-09-28T16:10:00-07:00", "created_by": {"type": "user", "id": "17738362", "name": "Jane Doe", "login": "[email protected]"}, "item": {"type": "file", "id": "5000948880"}, "permissions": {"can_edit": true, "can_delete": true} }依据预览页的评论串重建tagged_message 携带编辑器中的 @ 提及标记
列出文件元数据实例
GET
/v1/cloud/files/{file_id}/propertiesopendata列出文件上的元数据模板实例(企业或全局范围),在文件信息/密级分类面板展示。
认证方式: Authorization: Bearer <access_token>,取自 POST /v1/identity/token。
- entries
- $id
- $type
- $scope
- $template
- $parent
- $version
- $typeVersion
GET /v1/cloud/files/5000948880/properties HTTP/1.1 Authorization: Bearer c3FIOG9vZE5ob2VlOW1pZg{ "entries": [ {"$id": "01234500-12f1-1234-aa12-b1d234cb567e", "$type": "properties", "$scope": "global", "$template": "properties", "$parent": "file_5000948880", "$typeVersion": 2, "$version": 1, "source": "legal-review"} ] }与文件详情的密级分类和属性面板一致scope 与 template 字段遵循企业元数据模型
内部用户功能开关
GET
/v1/cloud/account/featuresopendata返回已登录用户的功能开关,用于在客户端门控 AI 助手、hubs、notes 与水印。
认证方式: Authorization: Bearer <access_token>,取自 POST /v1/identity/token。
- features
- box_ai
- hubs
- notes
- watermarking
- metadata
GET /v1/cloud/account/features HTTP/1.1 Authorization: Bearer c3FIOG9vZE5ob2VlOW1pZg{ "features": { "box_ai": true, "hubs": true, "notes": true, "watermarking": true, "metadata": true } }登录时读取以配置首页门控 AI、hubs、notes 与水印入口
应用 GraphQL 网关(hubs 与搜索)
POST
/v1/cloud/gateway/graphqlopendatahubs、hub 条目、统一搜索与 AI 代理列表使用的 GraphQL 风格网关——每个功能对应一份类型化文档。
认证方式: Authorization: Bearer <access_token>,取自 POST /v1/identity/token。
- data
- hubs
- edges
- node
- id
- title
POST /v1/cloud/gateway/graphql HTTP/1.1 Authorization: Bearer c3FIOG9vZE5ob2VlOW1pZg Content-Type: application/json {"operationName":"GetHubs","query":"query GetHubs($limit:Int){ hubs(first:$limit){ edges { node { id title } } } }","variables":{"limit":20}}{ "data": { "hubs": { "edges": [ {"node": {"id": "hub_01HXYZ", "title": "Q3 Deal Room"}} ] } } }支撑 hubs 浏览器与统一结果视图单一网关承载多份类型化文档查询
创建 Box AI 会话
POST
/v1/cloud/ai/sessionopendata针对选中的文件创建 AI 会话,让应用内 AI 助手能够流式返回答案;后续调用会为该会话流式输出答案。
认证方式: Authorization: Bearer <access_token>,取自 POST /v1/identity/token。
- metadata
- encoded_session
- session_id
- mode
- item_count
POST /v1/cloud/ai/session HTTP/1.1 Authorization: Bearer c3FIOG9vZE5ob2VlOW1pZg Content-Type: application/json {"items": [{"id": "5000948880", "type": "file"}], "mode": "ask"}{ "metadata": {"session_id": "ais_01H9", "mode": "ask", "item_count": 1}, "encoded_session": "eyJzZXNzaW9uX2lkIjoiYWlzXzAxSDkifQ" }依据在选定文档上打开的 AI 助手面板重建编码后的会话锚定后续的流式答案
数据类别
- 身份
- 存储配额
- 文件与文件夹
- 上传
- 搜索
- 共享链接
- 协作
- 评论
- 元数据
- 事件
- 收藏集
- AI 会话
数据使用场景与案例
企业存储配额看板
夜间任务调用 GET /v1/cloud/account,按每个 Box 登录账户绘制 space_used 相对 space_amount 与 max_upload_size 的曲线,在大文件上传预检失败之前标记接近配额的账户。
文件夹清单与 DLP 扫描
合规机器人从根文件夹开始分页拉取 GET /v1/cloud/folders/{folder_id}/items,再调用 GET /v1/cloud/files/{file_id} 获取 sha1、owned_by.login、密级分类与 shared_link 下载次数,找出被过度共享的文档。
共享链接访问审计
安全工具通过 GET /v1/cloud/shared/resolve 解析收到的 Box 分享链接(链接经专用请求头发送),记录 access、is_password_enabled、effective_permission 与 preview_count,全程无需下载文件。
协作名单同步
IT 部门把 GET /v1/cloud/folders/{folder_id}/collaborators 同步进 HRIS 系统,比对 accessible_by.login 与待接受的 invite_email,让离职员工及时失去文件夹访问权限。
常见问题
Box Android 应用如何认证 API 调用?
客户端在 POST /v1/identity/token 用 authorization_code 或 refresh_token(配合 PKCE code_verifier;企业也可用 JWT-bearer 登录)换取令牌,之后每次内容调用都附带 Authorization: Bearer。共享链接另经一个专用链接请求头携带 URL 与可选密码。
哪个接口返回存储配额?
GET /v1/cloud/account 返回 space_amount、space_used 与 max_upload_size,以及 login 和所属 enterprise——正是账户页面与大文件上传前预检所用的数字。
“全部文件”页面如何加载文件夹内容?
GET /v1/cloud/folders/{folder_id}/items 分页返回 file 或 folder 类型的条目,含 id、name、size、sha1、owned_by 与可选的 shared_link;folder_id 为 0 即“全部文件”。单个文件的详情来自 GET /v1/cloud/files/{file_id}。
上传与 Box AI 走哪些接口?
小文件以单个 multipart 请求体上传到 POST /v1/cloud/uploads/file;大文件先在 POST /v1/cloud/uploads/session 创建会话,获取 part_size 与各分片的上传地址。Hubs 与 AI 助手则复用同一 Bearer 令牌,走 POST /v1/cloud/gateway/graphql 与 POST /v1/cloud/ai/session。
与 Box 相似的应用
- Dropbox — Dropbox 提供云端文件存储、同步与共享,界面简洁、第三方应用集成丰富,是企业评估 Box 时最常见的替代选择之一。
- Google Drive — Google Drive 是 Google Workspace 的文件存储组件,将云存储与实时文档协作结合在一起,适合已在使用 Google 办公套件的团队。
- Microsoft OneDrive for Business — OneDrive for Business 提供企业级云存储,与 Microsoft 365 深度集成,组织可在现有微软环境中存储并协同编辑 Office 文档。
- Egnyte — Egnyte 采用云端与本地混合架构,提供内容治理和数据防泄漏工具,适合管理 CAD、媒体等大文件的企业。
- Citrix ShareFile — Citrix ShareFile 是面向企业的文件共享服务,具备高级加密和访问控制,主要面向金融、医疗等受监管行业。
- Tresorit — Tresorit 采用零知识安全模型提供端到端加密云存储,面向处理敏感文件的法律、医疗和金融团队。
- pCloud Business — pCloud Business 为企业提供加密云存储,不限制单文件大小,并提供灵活的定价(含买断式终身套餐)。
相关主题
- Box 数据 API
- Box Android API
- Box API 认证
- Box 存储配额 API
- Box 文件夹列表 API
- Box 文件下载 API
- Box 断点续传上传
- Box 共享链接解析
- Box 协作者 API
- Box AI 会话 API
需要集成这个 App 的数据 API?
我们可为任意指定 App 交付定制集成——源码交付 USD 500 起,或托管 API 按调用计费。告诉我们您需要的数据即可。
- 每个项目均签 NDA 与 SOW
- 3–7 天交付
- 验收通过后才付款
- 仅在授权范围内作业