Set up HubSpot MCP Server

HubSpot’s official MCP Server connects AI clients to CRM data. This guide covers setup, OAuth, permissions, write access, and risks.

Published on 18.09.2026

The HubSpot MCP Server is, according to HubSpot, the official way to connect compatible AI clients to HubSpot CRM data. MCP stands for Model Context Protocol, a standard that lets an agent reach external tools and data sources. The key point for visitors is that the server can read data and, depending on permissions, change live CRM records. Setup should therefore be treated as a security-relevant integration, not merely a convenience feature.

Remote server, local variant, and prerequisites

HubSpot describes a Remote MCP Server for CRM access and a separate Developer MCP Server for development tasks on the HubSpot platform. This guide focuses on CRM access. For the remote server, you need a HubSpot account, an MCP-capable client, and OAuth consent with PKCE. PKCE is a protection mechanism in the OAuth flow that helps prevent an intercepted authorization code from being abused. Many users will not implement it themselves, but they should confirm that their client supports it.

For local or non-interactive setups, HubSpot provides an NPM package. That path requires Node.js and a HubSpot Private App Access Token. A token is a technical key and must not appear in repositories, chat logs, sample configuration, or screenshots. Where possible, the remote server with OAuth is preferable because user consent and permissions are easier to trace.

Set up with minimal risk

Start with a clearly limited test account or controlled environment when possible. Create the required HubSpot authentication context, connect the MCP client to the HubSpot endpoint, and complete OAuth consent. Do not immediately create or modify a record. Run a harmless read operation first, such as retrieving account information or a small contact list. This verifies connection, authentication, and output before any write action is considered.

Document which client was connected, which HubSpot account is affected, and who granted consent. In teams, this matters because later agent runs otherwise become hard to audit. If you use the local package, place the token in a secure client configuration or environment variable and restrict the Private App permissions to the actual purpose.

Tools and practical value

According to HubSpot, the MCP Server can access core CRM objects, including contacts, companies, deals, tickets, leads, activities, and marketing or content data. In practice, an agent can answer questions such as which open deals belong to a company, which tasks are overdue, or which contacts are associated with an account. With sufficient authorization, it can also create new records or update existing ones.

The value comes from natural language and reduced context switching. Sales, support, or marketing users do not need to know API endpoints to retrieve structured information. The same convenience creates risk. An ambiguous prompt, model hallucination, or manipulated CRM field can lead to wrong suggestions. For write operations, include a human review step before the change is applied.

Permissions, data, and prompt injection

HubSpot states that actions respect the user permissions configured in the HubSpot account. That is important, but it is not enough by itself. A user with broad permissions can still create broad impact through the MCP server. Apply least privilege, clear scopes, and separate roles for testing and production use. Review authorized apps regularly and remove old connections when they are no longer needed.

Prompt injection is a real risk with CRM data. A contact name, note, or ticket description can contain instructions intended to influence the agent. Such content is data, not a command. The agent may summarize or process it, but it should not treat it as a new system instruction. Require human confirmation before changes to customer data, deals, or marketing content.

Limits and day-to-day operation

The HubSpot MCP Server does not replace CRM governance, data stewardship, or business judgment. It makes access and automation easier, but it cannot magically correct false or incomplete data. Large changes, bulk updates, and confidential customer information require additional controls. Actual model processing also depends on the chosen AI client; HubSpot provides CRM connectivity, while the client may transmit data to its model provider.

A good rollout starts in three steps: test a safe read tool, review permissions, then perform one small approved write action and read it back. Only after that chain is traceable should the server be placed into recurring workflows.

Published on 18.09.2026

Categories

Frequently asked questions

Why are there product and repository links?

The product link points to the provider's official documentation. The repository verifies source code, setup details, and the exact GitHub star count.

Are GitHub stars a rating?

No. The number is a point-in-time snapshot collected through the GitHub API on 2026-09-08 and does not replace security or quality review.

How do I start without unnecessary risk?

Start with harmless read operations like listing contacts or retrieving account information. Store API tokens in environment variables and enable write operations only after review.