HubSpot MCP Server
Official HubSpot MCP server: read and write contacts, companies, deals, pipelines, and marketing data directly from your AI client — secured via OAuth.
- Skill Road
- HubSpot MCP Server
Categories
Description
The HubSpot MCP Server is the official Model Context Protocol server from HubSpot, Inc. for the eponymous Smart CRM. It gives compatible AI clients — including Claude, Cursor, Codex, and other MCP-capable tools — secure read and write access to CRM objects, marketing content, and conversation data without requiring users to understand the underlying HubSpot API. The direct product link is https://developers.hubspot.com/ai-tools/mcp; the open-source repository lives at https://github.com/HubSpot/mcp-server.
What is the HubSpot MCP Server?
According to the provider, HubSpot operates two separate MCP servers: the Remote MCP Server at https://mcp.hubspot.com, secured by OAuth 2.1 with PKCE and exposing CRM data from a HubSpot account, and the Developer MCP Server for local development tasks on the HubSpot developer platform. This catalog entry describes the remote server (with an optional local NPM package) for productive CRM access. The Model Context Protocol (MCP) is an open standard that connects AI applications to external tools and data sources: when an agent receives a HubSpot-relevant prompt, the MCP client delegates the request to the server, which calls the HubSpot API and returns structured results.
Prerequisites
Using the HubSpot MCP Server requires: an active HubSpot account (free or paid), a compatible MCP client (Claude Desktop, Cursor, Codex, or another MCP-capable client), and OAuth consent with PKCE for the remote server. For the local NPM package, Node.js is required along with a HubSpot Private App Access Token. PKCE (Proof Key for Code Exchange) is mandatory for authenticating with the remote server; some clients such as the MCP Inspector handle PKCE automatically. Custom integrations must explicitly support OAuth 2.1 with PKCE.
Features and Tools
The HubSpot MCP Server provides extensive read and write capabilities according to official documentation:
Contacts: Read, create, and update contact records including properties, associations, and activities. Typical prompts: "Show me the contact for John Smith" or "Create a new contact for jane@example.com at Acme Inc."
Companies: Access company profiles, properties, and associated contacts. Associations between objects can be created via natural language, e.g., "Associate John Smith with Acme Inc. as a company."
Deals: Retrieve and edit deals across pipeline stages, with filtering by deal value, stage, or owner. Example: "Summarize all deals in the Decision-Maker-Bought-In stage with a value over $1,000."
Pipelines: Overview of pipeline stages, deal distribution, and forecasting data via natural-language queries.
Tickets and Leads: Create and update support tickets and lead records for sales workflows.
Activities: Create and retrieve call, email, meeting, note, and task records. Examples: "Add a task to send jane@example.com a thank-you note" or "List my overdue HubSpot tasks."
Marketing and Content: Read and write access to blog posts, landing pages, site pages, campaigns, marketing events, and email analytics (sends, opens, clicks, bounces).
Conversations: Access to conversations from live chat, team email, WhatsApp, SMS, Facebook Messenger, and other connected channels (subject to inbox configuration and user permissions).
User and Account Data: Details about the authenticated user, account information, and organization-wide data such as teams, job titles, and seat counts.
Setup
For the remote server: create an MCP auth app in your HubSpot account under Developer Tools, note the OAuth credentials (client ID), then point your MCP client at https://mcp.hubspot.com. Authentication flows via OAuth 2.1 with PKCE; after granting consent, all tools available in the MCP server become accessible. Permissions are determined automatically by the tools available in the server and the scopes chosen during installation.
For the local NPM package (development variant): npm install -g @hubspot/mcp-server and set the HubSpot Private App Access Token in the client configuration. Claude Desktop adds the start command to claude_desktop_config.json; Cursor uses a JSON configuration at ~/.cursor/mcp.json.
Available scopes are not explicitly defined by the app configuration but are automatically determined by the tools present in the MCP server and the permissions the user chooses to grant during installation. When HubSpot updates scopes, already-installed apps must be reinstalled to grant any new scopes.
Security
The HubSpot MCP Server supports write access to live CRM data according to the provider: creating and updating contacts, companies, deals, tickets, line items, products, activities, and content assets. All actions respect the user permissions configured in the HubSpot account — a user can only view and modify records they have access to in the HubSpot UI. PKCE is mandatory for the remote server; API tokens for the local NPM package belong in environment variables or secure client configurations, not in public repositories. Prompt injection via manipulated CRM data (e.g., contact names or note content) is a known risk for MCP servers with CRM access; agent outputs should be reviewed before any productive write operations. HubSpot explicitly notes that LLMs are prone to hallucination and outputs should always be reviewed.
FAQ
Is the HubSpot MCP Server free? The NPM package is open source. Usage costs depend on the HubSpot account plan and AI client. Current pricing information is available at https://www.hubspot.com/pricing.
What HubSpot CRM data is accessible? According to the provider: contacts, companies, deals, tickets, leads, users, carts, invoices, orders, line items, products, quotes, subscriptions, custom objects, and segments (read access), plus write access to the main CRM objects and activities.
Is OAuth mandatory? For the remote server, yes — OAuth 2.1 with PKCE is required. The local NPM package accepts a HubSpot Private App Access Token.
What distinguishes the remote and developer MCP servers? The remote server at mcp.hubspot.com is intended for productive CRM access. The Developer MCP Server helps developers build HubSpot apps and CMS content locally on the HubSpot developer platform — it is a separate product.
How current are the GitHub stars? The GitHub API reported exactly 5 stars for the repository HubSpot/mcp-server on 2026-09-08. That number is a point-in-time snapshot and is not a quality or security promise.
Requirements
HubSpot account, MCP client (Claude Desktop, Cursor, Codex, or similar), and OAuth 2.1 with PKCE for the remote server or a HubSpot Private App Access Token for the local NPM package.
Installation instructions
Remote: create an MCP auth app in your HubSpot account, point your MCP client at https://mcp.hubspot.com, grant OAuth consent with PKCE. Local: npm install -g @hubspot/mcp-server and set the Private App Access Token in the client configuration.
npm install -g @hubspot/mcp-server
Authentication
OAuth 2.1 with PKCE (remote server, recommended) or HubSpot Private App Access Token (local NPM package).
Required access permissions
Permissions follow HubSpot user rights and the scopes chosen during OAuth consent; write access to live CRM data is possible.
Transmitted or stored data
Tool calls reach the HubSpot API and return structured results to the MCP client; data does not leave the HubSpot platform additionally.
Security risks
Write access to live CRM data, prompt injection via manipulated CRM content, API tokens in insecure configurations, LLM hallucinations.
License and costs
- License
- Not recorded yet.
- Cost
- free
The NPM package is open source. Costs depend on the HubSpot account plan and AI client. Current pricing at hubspot.com/pricing.
Alternatives
Not recorded yet.
At a glance
- Provider
- HubSpot
- Status
- Official server
- Deployment
- Local and remote
- Current version
- Not recorded yet.
- GitHub stars
- 6
- Last reviewed
- 08.09.2026
Repository and documentation
Categories
Supported clients
Related guides
Guides and background related to this entry.
Set up the Asana plugin for Claude Code
Create your own Asana OAuth app, install the Claude Code plugin, and connect to Asana's V2 MCP server via /asana-setup.
30.09.2026
Setting up the Zernio MCP Server
Connect the Zernio MCP Server via OAuth or an API key, link social accounts, and deliberately safeguard write access to posts, inboxes, and ad campaigns.
28.09.2026
Setting up the Intercom MCP Server
Connect the Intercom MCP Server via OAuth or a bearer token, choose the correct regional endpoint, and deliberately safeguard write access to articles and notes.
23.09.2026
Setting up the PayPal MCP Server
Connect the PayPal MCP Server locally via npx or as a hosted remote server via OAuth, and deliberately safeguard write access.
23.09.2026