HubSpot MCP server icon

HubSpot

by HubSpot

HIPAA CompliantSOC2 ReadyISO 27001 Ready
Sales & CRM16 tools

Search contacts, companies, deals, tickets and conversations from your AI agent — and create or update them. HubSpot documents 16 tools including manage_crm_objects, despite Anthropic's directory labelling the connector Read. Six of the directory's 22 entries are display names, not callable identifiers.

Verified connector

Listed by Anthropic as a partner connector in its Connectors Directory.

Connection checked by Agentman on .

Anthropic states this reflects the level of review a connector received, not a security audit.

Connect HubSpot via MCP

https://mcp.hubspot.com/anthropic

Works in any MCP-compatible client. In Agentman Studio it is one click — no config file to edit.

Use in Agentman

Connect HubSpot once and your agents call these tools on their own — on a schedule, in a workflow, with nobody at the keyboard.

Open in Agentman Studio

HubSpot Tools & Capabilities (16)

search_crm_objects
get_user_details
get_properties
search_properties
get_crm_objects
render_landing_page_ui
show_feedback_form
Get campaign analytics
Get campaign asset metrics
Get campaign contacts by type
get_content_analytics
get_organization_details
query_crm_data
search_owners
Tool Guidance
manage_crm_objects
manage_landing_page
submit_feedback
read_landing_page_ui
Get campaign attribution reports
read_campaign_data
Search conversations

Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.

Limits

  • The Read permissions label is inaccurate, and self-evidently so. The same directory record carries manage_crm_objects and submit_feedback. HubSpot's matrix grants create and update across eleven object types plus five engagement types. Do not treat the label as a technical guarantee.
  • Neither tool listing is usable as an allowlist. Six of the directory's 22 entries and two of HubSpot's 16 are display names, not callable identifiers. Four of the directory's six recover to documented identifiers; two do not, and we did not invent names for them.
  • The two listings disagree by more than they agree. Eight directory identifiers are undocumented by HubSpot; six documented identifiers are missing from the directory. Only eight names appear in both.
  • We could not verify tool behaviour ourselves. The endpoint returns 401 to an anonymous handshake, so no safety annotations were readable and no schema-level detail is published here. The landing-page and feedback-form tools in particular are named but undocumented.
  • HubSpot's own two documents disagree about landing pages. The knowledge-base matrix shows landing pages as create-yes/update-no; the developer FAQ lists landing pages under read-only access. We report the conflict rather than picking a side.
  • No scopes are advertised, and none can be requested. Both metadata documents publish scopes_supported: []. HubSpot states you cannot explicitly define an MCP auth app's scopes — they are derived from installed tools plus granted permissions, and new tools force a reinstall.
  • Custom validation rules are bypassed on write. HubSpot says pipeline stage and association label validations are not applied to records created or updated through the connector. An agent can write what your UI would reject.
  • Bulk writes cap at 10 records. HubSpot states this plainly, so an agent updating a large set must batch.
  • Search is keyword, not semantic. HubSpot notes the server sits on the CRM search API, which currently has no vector search. Fuzzy questions get property filtering underneath.
  • Sensitive Data mode disables more than you might expect. With it on, HubSpot blocks all engagement objects *and* conversation data through MCP — a restriction HubSpot says applies to MCP specifically, not to its standard APIs.
  • Granting user access is irreversible. HubSpot states that once an admin gives users access it cannot be undone; users retain it until they uninstall individually.
  • One portal per Claude account. HubSpot says you can connect only one HubSpot account at a time, and switching means disconnecting and reconnecting.
  • Rate limits are HubSpot's API limits, not an MCP-specific budget. HubSpot states all functionality is subject to its API usage limits and guidelines, so a busy agent competes with every other integration on the portal.
  • Draft content is metadata-only. For website pages, landing pages and blog posts, HubSpot says only published items expose data; drafts expose metadata alone.
  • Prompts are unknown, not absent. Anthropic's directory snapshot records an empty prompt_names list, and the gated endpoint meant we could not run prompts/list to check whether the server serves any.

Frequently asked questions

It writes. HubSpot's own documentation lists `manage_crm_objects`, described as creating or updating CRM records or activities, and its knowledge base publishes a permission matrix granting create and update on contacts, companies, deals, tickets, custom objects, products, blog posts, marketing emails and five engagement types. Anthropic's directory labels the connector Read, which contradicts the tool list carried in that same record.

No. HubSpot states the connector supports view, create and update actions but not delete operations, and its object permission matrix shows an empty Delete column for all thirty-one object types listed. That is a genuine ceiling rather than a default. HubSpot notes you retain the ability to delete anything the connector added, working directly inside HubSpot.

Yes, and HubSpot says so explicitly rather than leaving it silent. Its documentation states the connector automatically respects permissions defined in HubSpot, so users only see the CRM data they can already access. Where an object's access is restricted to specific individuals or teams, HubSpot says Claude can view only those same records. Per-object and per-team granularity carries over.

HubSpot documents 16. Anthropic's directory snapshot lists 22 entries, but six of those are human display names rather than callable identifiers, and eight named identifiers appear nowhere in HubSpot's documentation. Only eight names appear in both sources. Treat HubSpot's developer documentation as authoritative, since it is the list the server's own maintainers publish.

Because both listings mix identifiers with display labels. Anthropic's snapshot carries six prose entries, including Tool Guidance and Search conversations. HubSpot's own documentation does the same for two entries, Get marketing email analytics and Manage marketing email. Four of the directory's six prose entries have documented snake_case equivalents, so the same tool is effectively listed twice under different naming.

No. HubSpot lists the connector as available across all products and plans, so a free portal qualifies. The paid requirement sits on the other side: HubSpot states you need a paid Anthropic subscription on the Pro, Max, Team or Enterprise tier. A Super Admin, or a user holding App Marketplace permissions, must connect it before anyone else can.

None are advertised over the wire. HubSpot's protected-resource metadata publishes an empty scopes_supported array, and so does its authorization-server metadata. HubSpot explains why: you never define an MCP auth app's scopes explicitly. They are derived from the tools present at install time plus whatever permissions the installing user grants, so new tools require reinstalling.

Sources

  • HubSpot knowledge base — Set up and use the HubSpot connector for Claude — https://knowledge.hubspot.com/integrations/set-up-and-use-the-hubspot-connector-for-claude (fetched 2026-08-19; page states last updated 10 August 2026). Source of the 31-row object permission matrix, plan gating, admin enablement, bulk limit, validation-rule caveat, audit-log attribution, and the user-permission statement. · retrieved 2026-08-19
  • HubSpot developer docs — Integrate AI tools with the HubSpot MCP server — https://developers.hubspot.com/docs/apps/developer-platform/build-apps/integrate-with-the-remote-hubspot-mcp-server (fetched 2026-08-19 as Markdown via the .md suffix). Source of the 16-tool list, the filter-group limits, the CRM-search-API and vector-search note, and the scope-derivation statement. · retrieved 2026-08-19
  • HubSpot AI tools overview — https://developers.hubspot.com/ai-tools/mcp (fetched 2026-08-19; https://developers.hubspot.com/mcp, the URL named in the RFC 9728 descriptor, redirects here). Source of the read-only landing-page claim that conflicts with the knowledge-base matrix. · retrieved 2026-08-19
  • HubSpot docs machine index — https://developers.hubspot.com/docs/llms.txt (fetched 2026-08-19; advertised on the docs pages themselves and used to locate the canonical MCP page). https://www.hubspot.com/llms.txt exists (fetched 2026-08-19) but mentions neither MCP nor the connector. knowledge.hubspot.com/llms.txt and developers.hubspot.com/llms.txt both 404 to the site's HTML shell. · retrieved 2026-08-19
  • Doc-order note: robots.txt first, then llms.txt, then the .md suffix. developers.hubspot.com/robots.txt disallows only /_hcms/preview, /_hcms/iplookup and preference-centre paths, and names two sitemaps (fetched 2026-08-19). knowledge.hubspot.com/robots.txt disallows preview and query-parameter paths and blocks Bytedance and Bytespider by name (fetched 2026-08-19). No Content-Signal axes are published on any of the three hosts — we checked knowledge., developers. and www.hubspot.com. The .md suffix works on developers.hubspot.com but 404s on knowledge.hubspot.com, so the knowledge-base article was read as HTML. · retrieved 2026-08-19
  • Live RFC 9728 probe — all three path forms tried 2026-08-19; root and path-insert return byte-identical 200s, path-append returns 401 with the authoritative www-authenticate header · retrieved 2026-08-19
  • Live RFC 8414 probe — https://mcp.hubspot.com/.well-known/oauth-authorization-server (fetched 2026-08-19; path-insert identical, path-append 401) · retrieved 2026-08-19
  • Live anonymous probe — 2026-08-19: an MCP POST to https://mcp.hubspot.com/anthropic returns HTTP 401 with a zero-byte body · retrieved 2026-08-19
  • Live per-client family probe — 2026-08-19: /anthropic and /openai return 401; /cursor, /windsurf, /vscode, /claude, /chatgpt, /mcp, /v1, /v3, /gemini, /copilot, /developer, /default and an invented control path all return a 33-byte JSON 404 · retrieved 2026-08-19
  • Anthropic connector directory — https://claude.ai/directory/875dee50-9b3f-452b-af8c-fbc839966273 (snapshot 2026-08-16; source of the 22-entry tool list, the Read permissions label, the empty prompt_names, the partner tier and the rank and popularity figures) · retrieved 2026-08-16
  • HubSpot support — https://help.hubspot.com/ · Privacy — https://legal.hubspot.com/privacy-policy

Server Info

Category
Sales & CRM
Developer
HubSpot
Tools
16
Domain
mcp.hubspot.com

Using Claude Desktop or another MCP client? Setup docs — the connection URL above works anywhere.

Ready to connect HubSpot?

Connect HubSpot once and your agents call these tools on their own — on a schedule, in a workflow, with nobody at the keyboard.