Box's API lives at https://api.box.com/2.0. Folder 0 is always the root.
For testing, generate a developer token on your app's Configuration page in the Developer Console (it lasts an hour). Send it as Authorization: Bearer <token>. In the examples it's written {{BOX_TOKEN}}.
Full reference: https://developer.box.com/reference/
curl https://api.box.com/2.0/users/me \
-H "Authorization: Bearer {{BOX_TOKEN}}"
curl "https://api.box.com/2.0/folders/0/items?limit=10" \
-H "Authorization: Bearer {{BOX_TOKEN}}"
curl "https://api.box.com/2.0/search?query=invoice&limit=5" \
-H "Authorization: Bearer {{BOX_TOKEN}}"