# Box Won't Preview HTML Files — What to Do Instead (2026)

Canonical: https://commareports.com/box-html-preview
Published: 2026-09-06

> Box stores your HTML report and won't render it: viewers get a download or a blank preview. How to share an HTML report from Box so it opens as a page.

# Box won't preview HTML files

You put `q3-analysis.html` in Box because that is where company files go,
shared the link, and the reply came back: *"it just downloads."* Or worse,
it downloads and opens as source.

Box is not broken. It is doing what an enterprise content platform should.

## Why storage platforms refuse to render HTML

An HTML file is a program. Rendering an arbitrary uploaded one on
`box.com` would mean executing someone's JavaScript on a domain that holds
your session — the textbook setup for stealing it. Every serious content
platform draws the same line: Box, Google Drive, Dropbox, SharePoint and
OneDrive all store HTML happily and none of them render it as a live page.

So the file is safe and correctly permissioned, and completely unreadable.
Two symptoms follow:

- **The download doesn't open.** Managed machines block `.html`, or open it
  in a text editor, or throw a "downloaded from the internet" warning that
  a finance director will not click through.
- **The page arrives naked.** One file cannot carry the folder it came
  from. Stylesheets, fonts, images and chart JavaScript that sat in
  `assets/` are simply gone. See
  [why a shared HTML report loses its CSS](/html-report-broken-css).

## What actually works

Keep Box for the file. Publish the *report* somewhere built to render it.

Comma serves report HTML inside a sandboxed iframe — `allow-scripts` with
no `allow-same-origin` — so interactive charts run without getting any
access to anyone's session. That is the isolation that makes rendering
safe, and it is why a content platform can't do it inline.

**Drag and drop.** Open [/new](/login), drop the `.html` file in, get a
URL. If the report is a folder — `index.html` plus `assets/` — zip it and
drop the zip; relative paths resolve exactly as they did locally.

**Or from the job that made it:**

```bash
curl -X POST https://commareports.com/api/v1/reports \
  -H "Authorization: Bearer $COMMA_API_TOKEN" \
  -H "Content-Type: application/json" \
  -d "$(jq -n --arg h "$(cat q3-analysis.html)" \
        '{title:"Q3 analysis", html:$h, visibility:"domain"}')"
```

`visibility: "domain"` limits the report to your email domain — the closest
match to how the file was permissioned in Box. The other levels are
private, team, registered, and unlisted link for an external client.

## What you get past "it renders"

- **Comments where the number is.** A reader selects the cell they doubt
  and leaves a thread anchored to it. It survives the next publish. See
  [commenting on HTML](/comment-on-html).
- **One URL, many revisions.** `PATCH` the same report id next quarter; the
  link you already circulated shows the new version and any two revisions
  are diffable. No `-final-v3` in anyone's downloads.
- **It opens on a phone.** A rendered page works on iOS and Android, where
  a downloaded `.html` usually does not. See
  [opening an HTML file on iPhone](/open-html-file-on-iphone).

## Keep Box in the loop

Nothing here asks you to move off Box. The durable pattern for regulated
teams is: the artifact and its source data stay in Box under retention
policy; the readable, commentable copy lives at a report URL with
domain-gated access; the Box folder holds a text file with the report URL
so the record points at the conversation.

## Related

- [Dropbox HTML preview](/dropbox-html-preview) ·
  [SharePoint HTML preview](/sharepoint-html-preview)
- [Share an HTML file from Google Drive](/share-html-file-google-drive) ·
  [Google Docs, for HTML](/google-docs-for-html)
- [Share an HTML report](/share-html-report) ·
  [Share a report with a client](/share-html-file-with-client)
