Skip to content
Last updated

HubSpot integration

HubSpot is a CRM platform that helps businesses manage contacts, companies, deals, and customer interactions.

It can be connected to Agen.co two ways, matching the Official / In-house filter in the connector picker:

  • Official — Agen.co connects through HubSpot's own hosted MCP server (https://mcp.hubspot.com), so your AI agents use the same CRM tools HubSpot exposes to MCP clients like Claude. Authorization uses an MCP connector that you create in your HubSpot account.
  • In-house — Agen.co wraps the HubSpot REST API directly through its own integration layer, using a legacy OAuth app you register in the HubSpot developer portal.

Pick Official if the built-in MCP tools cover what your agents need. Fall back to In-house if you need workflows, ticket pipelines, or property schemas beyond what the MCP server offers.


Connect via the official MCP server

Prerequisites

  • A HubSpot account where you can create apps.
  • A HubSpot account admin. HubSpot requires the account admin to connect first, before other users in the account can connect.

Get the callback URLs from Agen.co

HubSpot does not support dynamic client registration for its MCP server, so you create the MCP connector yourself and give Agen.co its Client ID and Client Secret. The app needs Agen.co's callback URLs, so start in Agen.co.

  1. In the Agen.co portal, go to Connectors → My connectors and click Add connector.
  2. Find HubSpot and select it.
  3. In the Add HubSpot panel, keep the Official tab selected. The panel shows two read-only URLs at the bottom — copy both:
    • Callback URL — completes the initial OAuth handshake between Agen.co and your HubSpot app.
    • Gateway callback URL — used by the Agen.co MCP gateway for per-user authorization at runtime.

Leave this panel open — you return to it after creating the connector in HubSpot.

Create the MCP connector in HubSpot

  1. In HubSpot, open More → Development and select MCP Connectors.
  2. Click Create MCP connector and enter a recognizable name, for example Agen.co.
  3. Enter the first callback URL in the dialog. On the connector page, click Add redirect URL for the second one, then click Save changes. A URL that is added to the list but not saved is lost when the page reloads.
  4. Copy the Client ID, and click Show next to Client secret to copy it.

Agen.co does not request scopes itself. HubSpot applies the scopes preconfigured for MCP connectors, and agents can only reach CRM data that the connecting user can access in HubSpot. HubSpot MCP connectors use OAuth 2.1 and require PKCE.

Connect HubSpot in Agen.co

Return to the open Add HubSpot panel and fill in the fields:

FieldRequiredDescription
Instance SlugYesNamespaces this instance — it prefixes each imported tool as slug__tool, so several instances of the same MCP can coexist. Use lowercase kebab-case. You can change it later from the connector's settings.
Client IDYesThe OAuth client ID from your HubSpot app.
Client SecretYesThe OAuth client secret from your HubSpot app.
Callback URL—Read-only. Add it as a redirect URL in your HubSpot app.
Gateway callback URL—Read-only. Also add it as a redirect URL — the MCP gateway uses it for per-user authorization at runtime.
  1. Click Connect. You are redirected to HubSpot to sign in and approve access.
  2. After you approve, the panel switches to Select the tools to import from HubSpot. Every tool is on by default; turn off any you do not want your agents to see.
  3. Click Add. The connector is created and the selected tools are imported only when you click Add — if you close the panel first, nothing is saved, even if the HubSpot callback page reported success.

What it covers

AreaWhat it covers
CRM objectsRead and write contacts, companies, deals, and tickets
CommerceProducts, orders, line items, invoices, quotes, and subscriptions
EngagementsCalls, emails, meetings, notes, and tasks
SegmentsRead and write segments
Account contextRead users, teams, and organizational context
Marketing contentRead campaigns, landing pages, website pages, and blog posts

The HubSpot MCP server does not give access to custom Sensitive Data properties, including Personal Health Information. The list above follows HubSpot's MCP documentation (checked 2026-10-05) and can change.

Enabling the HubSpot connector isn't enough on its own. Tool calls remain denied until you create a policy that grants access to the specific tools you want to expose.

Connect via the in-house integration

Prerequisites

  • A HubSpot account with developer access

Connect HubSpot

Step 1: Open the developer portal

Go to developers.hubspot.com and sign in with your HubSpot account.

HubSpot developer portal homepage

Step 2: Go to Legacy Apps

Once signed in, you will be in your HubSpot developer account. In the left sidebar, navigate to Development → Legacy Apps. This page lists all existing applications in your account.

HubSpot Legacy Apps list

Step 3: Create a new app

Click Create legacy app in the top right corner.

In the dialog that appears, select Public (for apps that can be installed by any HubSpot account) and click Next.

HubSpot Create Legacy App dialog

Step 4: Fill in the app name

On the App Info tab, enter a name for your application in the Public app name field (for example, "Frontegg Integration"). This name appears in HubSpot tools when users install your app.

HubSpot app name form

Step 5: Configure auth settings

Click the Auth tab to open the authentication configuration page.

HubSpot Auth settings tab

Step 6: Add redirect URLs

Scroll down to the Redirect URLs section. Enter the following redirect URLs, adding each one separately by typing the URL and clicking + Add redirect URL:

  • https://YOUR_MCP_GATEWAY_URL/integration-callback

HubSpot redirect URLs configuration

Step 7: Add OAuth scopes

Scroll down to the Scopes section and click Add new scope. Select the required scopes from the list:

ScopeDescription
crm.objects.contacts.readRead contact records
crm.objects.contacts.writeCreate and update contact records
crm.objects.companies.readRead company records
crm.objects.companies.writeCreate and update company records
crm.objects.deals.readRead deal records
crm.objects.deals.writeCreate and update deal records
crm.objects.owners.readRead owner (user) records
ticketsRead and write ticket records, search tickets, and list ticket pipelines and properties
crm.schemas.contacts.readRead contact property schemas
crm.schemas.companies.readRead company property schemas
crm.schemas.deals.readRead deal property schemas
automationList and read workflows, and enroll or unenroll contacts in workflows

Minimum required scopes

For basic CRM functionality, you need: crm.objects.contacts.read, crm.objects.companies.read, crm.objects.deals.read. Add tickets if you work with the ticketing pipeline, and automation if you enroll contacts in workflows.

HubSpot scope selection dialog

After selecting all required scopes, click Update.

HubSpot scopes selected

Step 8: Create the app

Once all required details are set, click Create app at the bottom of the page.

HubSpot Create app button enabled

Step 9: Copy your credentials

After the app is created, the Auth settings page displays your app credentials:

  • Client ID — Your app's unique identifier used to initiate OAuth.
  • Client secret — Click Show to reveal the secret. Used to exchange authorization codes for access tokens.

Copy both values and store them securely.

Keep your credentials secure

Never share or commit your Client secret to version control.

HubSpot app credentials page

Configure the Frontegg portal

Once you have obtained your Client ID and Client secret from the steps above, enter them in the integration configuration page of the Frontegg portal:

  1. Open the Frontegg portal and navigate to [ENVIRONMENT] → Integrations → HubSpot.
  2. Enter the Client ID and Client secret in the corresponding fields.
  3. Select the required scopes.
  4. Click Save.

Additional resources