Evidence-backed facts
- HubSpot API access is limited by configured scopes, such as CRM object read scopes, and by the account that installed or authorized the app. informative
- Creating CRM records requires the corresponding write scope; read access or token possession does not imply write permission. informative
- Multi-account distribution requires OAuth, while static auth is limited to one authorized account at a time; requests carry a bearer access token. informative
- Client secrets and access or refresh tokens require secure lifecycle management and rotation and must never enter public connector metadata. informative