Protect the build
Start from established catalogue, order, refund, customer, and payment behavior.
Commerce
Intelligence
Infrastructure
Why institutions choose Box
Keep the brand, records, rails, and merchant relationship.
Start here
By merchant activity
By deployment
See it running
OlivePay licensed Box. The tills are already in the field.
Engine only
For institutions with product and engineering teams ready to own every merchant and customer-facing surface, use the domain model behind Box without taking a prebuilt interface.
Run it locally
Why Engine Only
Start from established catalogue, order, refund, customer, and payment behavior.
Generate against the exact installed package set, with unavailable endpoints absent from the contract.
Own every interface and bind external providers through explicit ports.
How it works
The deployment generates its contract from what is installed. Your team builds against that contract, then connects the providers it has approved.
Start with the model
Products, websites, checkouts, payments, orders, customers, and transactions form one consistent model.

Describe the deployment
The contract reflects what is actually installed rather than every capability the platform could provide.

Build the interface
Your developers work from the contract produced by the deployment they are integrating with.

Operate safely
Payment, messaging, and settlement ports do nothing until an operator supplies an approved implementation.

Bring up the stack and exercise workflows before connecting production services.
Read the guide →Understand the commerce resources and operations exposed by your deployment.
Read the guide →Create typed clients from the OpenAPI document served by your own box.
Read the guide →Bind the engine to the institution’s identity boundary.
Read the guide →Operate Box in the environment and region you choose.
Explore →Review boundaries, data ownership, identity, and provider connections.
Explore →Yes. The engine binds to the institution’s authentication guard.
Yes. Payment capability is connected through an implementation supplied by the operator.
They are absent from the deployed API rather than exposed and rejected at runtime.
Yes. Embedded components and full surfaces are packages added to the same deployment.
Inside the infrastructure and region operated by the institution.
The institution chooses when to install licensed package updates.
Run the platform locally, inspect its API description, and decide how much of the experience your team wants to build.
Start locally