MCP Directory

HubSpot MCP Setup: Create a PKCE App and Protect CRM Writes

Use HubSpot's remote CRM MCP server only after you create an MCP Auth App, register the client's exact redirect URL, and use a PKCE-capable client. Start with contact or company reads, confirm the installing user's permissions and granted scopes, and add deal, engagement, or other CRM writes only after the read path works.

MCPtrove·October 1, 2026·6 min read
Professional customer service team working in a modern office setting with headsets and laptops.
Photo by MART PRODUCTION on Pexels

Use HubSpot's remote CRM MCP server only after you create an MCP Auth App, register the client's exact redirect URL, and use a PKCE-capable client. Start with contact or company reads, confirm the installing user's permissions and granted scopes, and add deal, engagement, or other CRM writes only after the read path works.

Table of contents

Which HubSpot MCP server do you need?

Use HubSpot's remote CRM MCP server at https://mcp.hubspot.com for CRM access from an MCP client. It is separate from HubSpot's local Developer MCP server, so identify the intended server before configuring authentication.

The remote CRM path has three practical requirements:

  • An MCP Auth App in HubSpot.
  • OAuth authentication with PKCE.
  • A client configured with the app's client ID, client secret, and exact redirect URL.

Access follows the installing user's HubSpot permissions and the scopes granted to the app. That means a successful connection does not automatically provide unrestricted CRM access. The account, user, app scopes, and server endpoint must all align. HubSpot's remote MCP documentation distinguishes this integration from other HubSpot developer tooling.

As a practical next step, open MCPtrove's HubSpot MCP server directory entry while you collect the endpoint and client settings. Keep the remote endpoint visible during setup so it is not confused with a local developer server.

How do you create an MCP Auth App?

Create an MCP Auth App in HubSpot's developer platform, then configure its OAuth details with the exact redirect URL your client will use. Do this before starting the MCP connection.

  1. Open HubSpot's app-development area and create the MCP Auth App.
  2. Copy the app's client ID and client secret for the client configuration.
  3. Add the redirect URL supplied by the client, preserving it exactly.
  4. Select the scopes required for the intended CRM operations.
  5. Confirm that the HubSpot user who will install the app has the permissions needed for those operations.

The redirect URL is an exact-match value. A different path, host, port, or URL form can prevent authorization from completing, so copy the client value rather than rewriting it manually.

Use only the scopes needed for the first verification. If Sensitive Data is enabled, activity objects including calls, emails, meetings, notes, and tasks are blocked from MCP access. Account permissions and app scopes therefore need to be considered together. See HubSpot's OAuth documentation and the MCP OAuth explainer for the authorization concepts behind this setup.

Diverse group of call center agents wearing headsets, smiling at the camera.
Photo by Mikhail Nilov on Pexels

How do you connect a PKCE-capable client?

Configure a PKCE-capable MCP client with https://mcp.hubspot.com, the MCP Auth App credentials, and the exact registered redirect URL. Then complete OAuth authorization using the intended HubSpot account.

Use this sequence:

  1. Choose a client that supports MCP authorization with PKCE.
  2. Add the remote CRM endpoint: https://mcp.hubspot.com.
  3. Enter the app's client ID and client secret.
  4. Enter the exact redirect URL registered in the MCP Auth App.
  5. Enable the client's PKCE-capable authorization flow.
  6. Authorize the installing user's HubSpot account.
  7. Return to the client and confirm that the connection is available.

For a Cursor workflow, use the Cursor client setup page as the practical configuration starting point. Do not invent a configuration format or paste credentials into a prompt when the client provides dedicated fields.

MCP authorization separates the client, authorization server, and protected resource. Keeping those roles clear helps explain why the endpoint, app registration, redirect URL, and user authorization must agree. The MCP authorization specification and MCP architecture guide provide the relevant protocol context.

How do you verify CRM reads first?

Verify the connection with a contact or company read before exposing deal, engagement, or other CRM writes. A successful read confirms that the endpoint, authorization, account, permissions, and initial scopes are aligned for at least one CRM operation.

Use a small read-first checklist:

  1. Confirm that the authorized user is signed in to the intended HubSpot account.
  2. Request a contact read.
  3. Request a company read.
  4. Check that the returned records belong to the expected account.
  5. Record which read worked and which scopes were granted.
  6. Stop and correct the connection if either read fails.

A read result should not be treated as proof that every CRM object or write is available. Deals, contacts, and engagements can be affected by different permissions, scopes, or Sensitive Data restrictions.

Before changing several settings at once, use MCPtrove's configuration validator to inspect the endpoint, credentials, redirect URL, and selected options. Then repeat one read. This creates a clear checkpoint before any write-capable configuration is introduced. HubSpot's MCP overview is the reference for the available integration context.

How do you contain deals, contacts, and engagement writes?

Contain CRM writes by starting with reads, granting only the scopes required for the next operation, and expanding one object family at a time. Keep deal, contact, and engagement changes behind an explicit authorization checkpoint.

Use this progression:

  1. Verify contact and company reads.
  2. Decide whether the workflow needs contact writes, deal writes, or engagement access.
  3. Add only the scopes and HubSpot permissions required for that object family.
  4. Test the smallest intended operation.
  5. Review the result before enabling another write category.
SituationDecision
Contact or company readUse as the first verification step.
Contact writeAdd only after the corresponding read works and the user has permission.
Deal writeTreat as a separate expansion; verify it independently.
Engagement accessCheck Sensitive Data status first.
Calls, emails, meetings, notes, or tasks with Sensitive Data enabledExpect these activity objects to be blocked from MCP access.

This sequence limits the number of unknowns in each test. It also keeps a working read connection from being mistaken for blanket permission to modify CRM records. The MCP security best practices support keeping authorization and permission boundaries explicit.

How do you fix redirects, PKCE, refresh, scope, and account failures?

Fix failures by comparing the endpoint, exact redirect URL, PKCE capability, app credentials, authorization state, scopes, and HubSpot account permissions in that order. Keep TLS, authentication, and permission checks enabled while troubleshooting.

SymptomCheck
Redirect errorCompare the client redirect URL with the exact URL registered in the MCP Auth App.
PKCE errorConfirm that the selected client supports PKCE, then start authorization again.
Refresh or reconnect failureInspect the client's authorization state and reauthorize through the configured app.
Scope failureCompare the app's granted scopes with the requested CRM operation.
Account or permission failureConfirm the installing user and intended HubSpot account.
Activity objects unavailableCheck whether Sensitive Data is enabled; listed activity objects may be blocked.

If the client points to a local Developer MCP server, replace it with https://mcp.hubspot.com for the remote CRM integration. If the redirect is wrong, update the app or client so both values match exactly, then repeat authorization.

For a scope or account failure, do not compensate by removing permission checks. Compare the installing user's HubSpot permissions with the app's granted scopes, reduce the test to a contact or company read, and expand only after that read succeeds. The MCP authorization specification is the reference for the authorization layer.

FAQ

Is the remote CRM server the same as HubSpot's Developer MCP server?

No. The remote CRM endpoint is https://mcp.hubspot.com, and it is separate from HubSpot's local Developer MCP server.

Does MCP access ignore HubSpot permissions?

No. Access follows the installing user's HubSpot permissions and the scopes granted to the MCP Auth App.

Can I start with CRM writes?

Start with contact or company reads. Add deal, engagement, or other writes only after the read path works and the required permissions and scopes are confirmed.

What happens to activity objects when Sensitive Data is enabled?

Calls, emails, meetings, notes, and tasks are blocked from MCP access when Sensitive Data is enabled.

Put this into practice

Browse MCP servers by capability, or check your own setup's tool budget and security.

More in Integrations

Browse all integrations articles.