Remote CRM MCP: contacts, companies, deals, tickets, users, carts, invoices, orders, line items, products, quotes, subscriptions, segments, calls, emails, meetings, notes, tasks, blog posts, landing and site pages, campaigns, and marketing events. Local Developer MCP: apps, CMS assets, serverless functions, and app analytics.
HubSpot
Included as a CRM and customer-platform system whose GA remote MCP can read broad CRM, activity, commerce, content, and marketing context and create or update selected records under user permissions, while a separate GA local Developer MCP serves app and CMS development rather than customer records.
Concrete capability record
Data, retrieval, actions, identity, and operating limits
A field-by-field summary of what the reviewed first-party references actually support. Publisher update dates and BYO-UI review dates are shown separately below.
The remote server reads the documented CRM, commerce, activity, content, and marketing objects using account access derived from the installed MCP auth app and authenticated user. The local Developer MCP reads developer documentation and project context for build work, not the account CRM catalog.
The remote server can create or update contacts, companies, deals, tickets, line items, products, calls, emails, meetings, notes, and tasks when granted. The audited documentation does not list remote MCP deletion. The local Developer MCP separately creates or manages app, CMS, and serverless development assets.
The remote server uses a HubSpot-generated MCP auth app and OAuth 2.1 with PKCE. Available scopes are determined by the server’s tools and the permissions the user grants during installation; actions also respect the authenticated user’s HubSpot record access. Tool-scope additions require installed users to reauthorize.
MCP auth apps define client credentials and exact redirect URLs; `get_user_details` reports the user, account, objects, and tools available from granted scopes and user permissions. Access-token refresh must be handled by the client, and scope changes can place an existing installation into reauthorization status.
The remote server is based on HubSpot CRM search and has no vector search. If Sensitive Data is enabled, calls, emails, meetings, notes, and tasks are blocked specifically through MCP. Tool changes may require reinstallation for new scopes, and clients must support PKCE and token refresh. Remote CRM and local Developer MCP capabilities are not interchangeable.
First-party MCP tool catalog
12 named MCP tools · Remote CRM-data server
The exact tool list published for HubSpot's remote account-data MCP server at mcp.hubspot.com; it does not describe HubSpot's separate local developer MCP server. Reviewed Jul 10, 2026. Available scopes depend on the installed tool set and the user's granted HubSpot permissions. Sensitive Data settings can block activity objects from this MCP surface.
Identity, records, properties, and owners7
get_user_detailsreadsearch_crm_objectsreadget_crm_objectsreadmanage_crm_objectswritesearch_propertiesreadget_propertiesreadsearch_ownersreadCampaign data and service feedback5
get_campaign_contacts_by_typereadget_campaign_analyticsreadget_campaign_asset_typesreadget_campaign_asset_metricsreadsubmit_feedbackwriteNo matching catalog items
Try a broader name, group, action, or availability term.
First-party MCP tool catalog
21 named MCP tools · Local Developer MCP server
The exact tools published for HubSpot's local Developer MCP used to research documentation, build and deploy HubSpot projects, inspect developer accounts and apps, and create CMS assets. This is separate from HubSpot's remote CRM-data MCP server. Reviewed Jul 10, 2026. Project upload and deployment can change a HubSpot account and require explicit user intent. list-cms-serverless-functions and list-cms-remote-contents are deprecated in the cited catalog.
Documentation and guided development3
guided-walkthrough-clireadsearch-docsreadfetch-docreadProjects, builds, and deployment9
get-feature-config-schemareadget-build-statusreadget-build-logsreadcreate-projectwriteadd-feature-to-projectwritevalidate-projectreadupload-projectconsequential writedeploy-projectconsequential writefind-projectsreadDeveloper accounts and apps3
create-test-accountwriteget-api-usage-patterns-by-app-idreadget-apps-inforeadCMS assets and serverless functions6
create-cms-templatewritecreate-cms-modulewritecreate-cms-functionwriteget-cms-serverless-function-logsreadlist-cms-serverless-functionsreadlist-cms-remote-contentsreadNo matching catalog items
Try a broader name, group, action, or availability term.
First-party connector catalog
6 named connectors · Selected named Marketplace integrations
A concise set of integrations named in the HubSpot Marketplace landing page's current featured sections. This selected sample is not the complete Marketplace and does not establish the exact permissions or data flow of any installation. Reviewed Jul 10, 2026. These are product integrations, not HubSpot MCP tools. Installation scopes, sync direction, plans, and write behavior must be checked on each current listing before use.
Meetings, collaboration, CRM, and prospecting6
No matching catalog items
Try a broader name, group, action, or availability term.
First-party access
Documented surfaces
Agent access
MCP support
Support: Official MCP server
Read scope: For CRM work, use only remote-server objects reported as available by `get_user_details` for the current account and user. Treat activities as unavailable when Sensitive Data is enabled, and do not expect semantic or vector search from the CRM-search-backed implementation.
Write scope: 10 of 33 reviewed named tools have a write, draft, or mixed action label, including manage_crm_objects, submit_feedback, create-project, add-feature-to-project, upload-project, and others. Read each catalog boundary before enabling them.
Authentication: OAuth 2.1 with S256 PKCE through a self-service MCP auth app, using client ID, client secret, and matching redirect URL; access tokens require refresh-token handling and full reauthorization if refresh state is invalid.
Approval boundary: Before any remote write, show HubSpot account, authenticated user, object type and record, changed properties or activity content, associations, and the tool reported by the current installation. Require confirmation for creates and updates; keep local developer asset changes on a separate approval path.
Confirm the current tool catalog, plan, region, scopes, rate limits, terms, and write behavior before implementation.
Editorial assessment
Access-maturity dimensions
A comparative architecture lens—not a quality score, market ranking, or buying recommendation. Scale: 1–5.
Proposed customer-shaped experiences
What customers could create on top.
The output could be an export, report, graph, artifact, application, agent, workflow, or downstream feed. These proposals are derived from documented access—not claims that HubSpot ships them.
Single-platform patterns
- Unified account, campaign, and service cockpit
- Account journey room
- Pipeline-quality debugger
- Customer expansion cockpit
Multi-platform compositions
- HubSpot + marketing or intent platform: account journey room
- HubSpot + conversation or support system + analytics or warehouse: cross-system decision workspace
Evidence and dates
First-party references, with publisher and review dates separated
“Publisher updated” is shown only when the page exposes an update date. “BYO-UI reviewed” records when this research checked the reference. A missing publisher date is reported as missing—not replaced with the review date.
9 recorded sources
HubSpot's remote server became GA in April 2026 and uses OAuth 2.1 with PKCE. Distinguish it from the local Developer MCP. Sensitive Data settings can block activity objects specifically through MCP.
- Publisher updated
- Apr 17, 2026
- BYO-UI reviewed
- Jul 12, 2026
Targeted first-party MCP/agent-role review; broader API inventory retained
First-party API reference or API overview recorded for this platform.
- Publisher updated
- Mar 31, 2026
- BYO-UI reviewed
- Jul 10, 2026
Inventory source: structurally normalized; content was not individually reopened in this pass.
First-party developer documentation or platform overview.
- Publisher updated
- Not stated by publisher
- BYO-UI reviewed
- Jul 10, 2026
Inventory source: structurally normalized; content was not individually reopened in this pass.
First-party product homepage used to confirm product identity and current positioning.
- Publisher updated
- Not stated by publisher
- BYO-UI reviewed
- Jul 10, 2026
Inventory source: structurally normalized; content was not individually reopened in this pass.
First-party MCP documentation or product announcement recorded for this platform.
- Publisher updated
- Not stated by publisher
- BYO-UI reviewed
- Jul 10, 2026
Inventory source: structurally normalized; content was not individually reopened in this pass.
First-party webhook, event, SDK, embedded-app, or extension documentation.
- Publisher updated
- Not stated by publisher
- BYO-UI reviewed
- Jul 10, 2026
Inventory source: structurally normalized; content was not individually reopened in this pass.
HubSpot documents GraphQL for data-driven Content Hub pages and eligible Sales or Service Enterprise UI extensions. This is not a universal GraphQL endpoint for every HubSpot account or product object.
- Publisher updated
- Not stated by publisher
- BYO-UI reviewed
- Jul 12, 2026
Targeted first-party access review
Named catalog evidence used on this profile.
- Publisher updated
- May 8, 2026
- BYO-UI reviewed
- Jul 10, 2026
Targeted first-party catalog review
Named catalog evidence used on this profile.
- Publisher updated
- Not stated by publisher
- BYO-UI reviewed
- Jul 10, 2026
Targeted first-party catalog review
Verified fact
Tied to cited first-party evidence reviewed for this profile.
Source inventory
Official links recorded for deeper research but not necessarily reopened endpoint by endpoint.
Editorial assessment
System role, maturity interpretation, and architectural boundary.
Proposed design
Interface patterns and compositions—not vendor product claims.