Dropbox's API at https://api.dropboxapi.com/2 is all POST requests, even for reads. Arguments go in the JSON body.
Create an app in the App Console and generate an access token on its settings page. Send it as Authorization: Bearer <token>. In the examples it's written {{DROPBOX_TOKEN}}.
Full reference: https://www.dropbox.com/developers/documentation/http/documentation
No body — the call takes no arguments.
curl -X POST https://api.dropboxapi.com/2/users/get_current_account \
-H "Authorization: Bearer {{DROPBOX_TOKEN}}"
An empty path is the root.
curl -X POST https://api.dropboxapi.com/2/files/list_folder \
-H "Authorization: Bearer {{DROPBOX_TOKEN}}" \
-H "Content-Type: application/json" \
-d '{"path": "", "limit": 10}'