enterprise-application-connectors · prepared

HubSpot CRM API connector boundary

Official-source OAuth, single-account static-token, CRM read/write scope, token-lifecycle, and distribution boundaries for HubSpot connectors.

version 1.0.0freshness currentobserved 2026-08-27T01:30:00Z

resource.connector.hubspot-crm-api
sha256:f718981a470b047cd52f3dcd5a8c8aba267bca1f2779cc58c20aa9b14676377b

Open canonical machine JSON →

Evidence-backed facts

  1. HubSpot API access is limited by configured scopes, such as CRM object read scopes, and by the account that installed or authorized the app. informative
  2. Creating CRM records requires the corresponding write scope; read access or token possession does not imply write permission. informative
  3. Multi-account distribution requires OAuth, while static auth is limited to one authorized account at a time; requests carry a bearer access token. informative
  4. Client secrets and access or refresh tokens require secure lifecycle management and rotation and must never enter public connector metadata. informative