HubSpotSAFE
MCP Implementation for HubSpot
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
HubSpot MCP Server
A Model Context Protocol (MCP) server implementation for the HubSpot API, providing a standardized interface for accessing and managing CRM data.
Features
- Complete coverage of the HubSpot CRM API
- Support for all standard CRM objects (companies, contacts, deals, etc.)
- Advanced association management with CRM Associations v4
- Company-specific endpoints with property validation
- Batch operations for efficient data management
- Advanced search and filtering capabilities
- Type-safe parameter validation with Zod
Prerequisites
If you don't have an API key, follow the steps here to obtain an access token. OAuth support is planned as a future enhancement.
Client Configuration
There are several options to configure your MCP client wi
7405cc49a3b7OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add hubspot-mcp --env HUBSPOT_ACCESS_TOKEN=${HUBSPOT_ACCESS_TOKEN} -- npx -y @shinzolabs/[email protected]{
"mcpServers": {
"hubspot-mcp": {
"command": "npx",
"args": [
"-y",
"@shinzolabs/[email protected]"
],
"env": {
"HUBSPOT_ACCESS_TOKEN": "${HUBSPOT_ACCESS_TOKEN}"
}
}
}
}Exposed tools (112)
45 read · 51 write · 16 destructive. Blast radius: 16 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
calls_archive | destructive | Archive (delete) a call record |
calls_batch_archive | destructive | Archive (delete) multiple call records in a single request |
calls_batch_create | write | Create multiple call records in a single request |
calls_batch_read | read | Read multiple call records in a single request |
calls_batch_update | write | Update multiple call records in a single request |
calls_create | write | Create a new call record |
calls_get | read | Get details of a specific call |
calls_list | read | List all calls with optional filtering |
calls_search | read | Search calls with specific filters |
calls_update | write | Update an existing call record |
communications_get_preferences | read | Get communication preferences for a contact |
communications_get_subscription_definitions | read | Get all subscription definitions for the portal |
communications_get_subscription_status | read | Get subscription status for multiple contacts |
communications_subscribe_contact | read | Subscribe a contact to all email communications |
communications_unsubscribe_contact | read | Unsubscribe a contact from all email communications |
communications_update_preferences | write | Update communication preferences for a contact |
communications_update_subscription_status | write | Update subscription status for multiple contacts |
crm_archive_association | destructive | Archive (delete) an association between two objects |
crm_archive_object | destructive | Archive (delete) a CRM object |
crm_batch_archive_associations | destructive | Archive (delete) multiple associations in a single request |
crm_batch_archive_objects | destructive | Archive (delete) multiple CRM objects in a single request |
crm_batch_create_associations | write | Create multiple associations in a single request |
crm_batch_create_companies | write | Create multiple companies in a single request |
crm_batch_create_contacts | write | Create multiple contacts in a single request |
crm_batch_create_leads | write | Create multiple leads in a single request |
crm_batch_create_objects | write | Create multiple CRM objects in a single request |
crm_batch_read_objects | write | Create multiple CRM objects in a single request |
crm_batch_update_companies | write | Update multiple companies in a single request |
crm_batch_update_contacts | write | Update multiple contacts in a single request |
crm_batch_update_leads | write | Update multiple leads in a single request |
crm_batch_update_objects | write | Update multiple CRM objects in a single request |
crm_create_association | write | Create an association between two objects |
crm_create_company | write | Create a new company with validated properties |
crm_create_company_property | write | Create a new company property |
crm_create_contact | write | Create a new contact with validated properties |
crm_create_contact_property | write | Create a new contact property |
crm_create_lead | write | Create a new lead with validated properties |
crm_create_lead_property | write | Create a new lead property |
crm_create_object | write | Create a new CRM object |
crm_get_associations | read | Get all associations of a specific type between objects |
crm_get_company | read | Get a single company by ID with specific properties and associations |
crm_get_company_properties | read | Get all properties for companies |
crm_get_contact | read | Get a single contact by ID with specific properties and associations |
crm_get_contact_properties | read | Get all properties for contacts |
crm_get_lead | read | Get a single lead by ID with specific properties and associations |
crm_get_lead_properties | read | Get all properties for leads |
crm_get_object | read | Get a single CRM object by ID |
crm_list_association_types | read | List all available association types for a given object type pair |
crm_list_objects | read | List CRM objects of a specific type with optional filtering and pagination |
crm_search_companies | read | Search companies with company-specific filters |
crm_search_contacts | read | Search contacts with contact-specific filters |
crm_search_leads | read | Search leads with lead-specific filters |
crm_search_objects | read | Search CRM objects using filters |
crm_update_company | write | Update an existing company with validated properties |
crm_update_contact | write | Update an existing contact with validated properties |
crm_update_lead | write | Update an existing lead with validated properties |
crm_update_object | write | Update an existing CRM object |
emails_archive | destructive | Archive (delete) an email record |
emails_batch_archive | destructive | Archive (delete) multiple email records in a single request |
emails_batch_create | write | Create multiple email records in a single request |
emails_batch_read | read | Read multiple email records in a single request |
emails_batch_update | write | Update multiple email records in a single request |
emails_create | write | Create a new email record |
emails_get | read | Get details of a specific email |
emails_list | read | List all emails with optional filtering |
emails_search | read | Search emails with specific filters |
emails_update | write | Update an existing email record |
engagement_details_archive | destructive | Archive (delete) an engagement |
engagement_details_create | write | Create a new engagement with details |
engagement_details_get | read | Get details of a specific engagement |
engagement_details_get_associated | read | Get all engagements associated with an object |
engagement_details_list | read | List all engagements with optional filtering |
engagement_details_update | write | Update an existing engagement |
meetings_archive | destructive | Archive (delete) a meeting |
meetings_batch_archive | destructive | Archive (delete) multiple meetings in a single request |
meetings_batch_create | write | Create multiple meetings in a single request |
meetings_batch_update | write | Update multiple meetings in a single request |
meetings_create | write | Create a new meeting |
meetings_get | read | Get details of a specific meeting |
meetings_list | read | List all meetings with optional filtering |
meetings_search | read | Search meetings with specific filters |
meetings_update | write | Update an existing meeting |
notes_archive | destructive | Archive (delete) a note |
notes_batch_archive | destructive | Archive (delete) multiple notes in a single request |
notes_batch_create | write | Create multiple notes in a single request |
notes_batch_read | read | Read multiple notes in a single request |
notes_batch_update | write | Update multiple notes in a single request |
notes_create | write | Create a new note |
notes_get | read | Get details of a specific note |
notes_list | read | List all notes with optional filtering |
notes_search | read | Search notes with specific filters |
notes_update | write | Update an existing note |
products_archive | write | Move an Object identified by ID to the recycling bin. |
products_batch_archive | destructive | Archive (delete) a batch of products by ID |
products_batch_create | write | Create a batch of products |
products_batch_read | read | Read a batch of products by internal ID, or unique property values. Retrieve records by the |
products_batch_update | write | Update a batch of products by internal ID, or unique values specified by the |
products_create | write | Create a product with the given properties and return a copy of the object, including the ID. |
products_list | read | Read a page of products. Control what is returned via the |
products_read | read | Read an Object identified by ID |
products_search | read | Search products |
products_update | write | Perform a partial update of an Object identified by ID. Read-only and non-existent properties will result in an error. Properties values can be cleared by passing an empty string. |
tasks_archive | destructive | Archive (delete) a task |
tasks_batch_archive | destructive | Archive (delete) multiple tasks in a single request |
tasks_batch_create | write | Create multiple tasks in a single request |
tasks_batch_read | read | Read multiple tasks in a single request |
tasks_batch_update | write | Update multiple tasks in a single request |
tasks_create | write | Create a new task |
tasks_get | read | Get details of a specific task |
tasks_list | read | List all tasks with optional filtering |
tasks_search | read | Search tasks with specific filters |
tasks_update | write | Update an existing task |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
calls_archive, calls_batch_archive, crm_archive_association, crm_archive_object, crm_batch_archive_associations, crm_batch_archive_objects, emails_archive, emails_batch_archive, engagement_details_arc
@shinzolabs/instrumentation-mcp, @babel/core, @babel/preset-env, @babel/preset-typescript, @changesets/cli, @types/jest, @types/node, babel-jest
Gates applied: no_behavioural_pass.
7405cc49a3b7full audit observations/trust-audit/mcp-server/shinzo-labs__hubspot-4.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 7405cc49a3b7 | SAFE | B | 89 | first audit |
Questions
What is the HubSpot MCP server?
MCP Implementation for HubSpot
What tools does HubSpot expose?
112 in total: 45 read-only, 51 that write, and 16 that can delete or overwrite (calls_archive, calls_batch_archive, crm_archive_association, crm_archive_object, crm_batch_archive_associations). Every one is listed on this page with its risk.
Is HubSpot safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 16 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does HubSpot need?
It reads HUBSPOT_ACCESS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does HubSpot run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @shinzolabs/hubspot-mcp at 2.0.5.
How current is this page?
The grade is for one exact copy of the source (7405cc49a3b7), read on 2026-10-08. The repository is watched and re-audited when it changes.