Skip to content
Agentic Workflowdocs
v0.8.2Install free

use the app / connections

Connect HubSpot

Create a HubSpot private app with only the CRM scopes you need and paste its access token.

≈ 4 min Extension Bearer Token
  • A HubSpot account where you are a Super Admin (needed to create private apps).
  • The AWFlow browser extension. These steps run in the extension (the web app hands them to it).
  1. Create a private app. In HubSpot, open Settings › Integrations › Private Apps and click Create a private app.

  2. Pick scopes. On the Scopes tab, add the scopes from the table below for the operations you use. Click Create app.

  3. Copy the access token (it starts with pat-).

  4. Save it in AWFlow. Open Credentials and click Add Credential (or + Add Credential in a node’s Credential field), then fill the New Credential form. In the browser side panel the form comes in two steps: tap HubSpot in the list, then fill the rest.

    The New Credential dialog with HubSpot picked under Integration App / Service: Name and Description fields, a Bearer Token field (no Auth Type menu: the app sets it), a note that the secret is saved locally and encrypted in this browser, and the Cancel and Create Credential buttons. The New Credential dialog with HubSpot picked under Integration App / Service: Name and Description fields, a Bearer Token field (no Auth Type menu: the app sets it), a note that the secret is saved locally and encrypted in this browser, and the Cancel and Create Credential buttons.

    Numbered areas in the screenshot: 1. Integration App / Service: HubSpot; 2. Name; 3. Bearer Token; 4. Where the secret is stored (here, locally in this browser); 5. Create Credential.

Operation Scope
Contact · Search crm.objects.contacts.read
Contact · Create or update, Update crm.objects.contacts.write (and .read)
Company · Search crm.objects.companies.read
Company · Create or update crm.objects.companies.write (and .read)
Deal · List crm.objects.deals.read
  • “403 Forbidden — the private app token is missing a required scope”. Add the scope to the private app, then run again (the token stays the same).
  • “401 Unauthorized”. The token is wrong or was rotated. Copy the current one and update the credential.
  • The run is blocked in the web app. HubSpot runs through the browser extension. Install the extension and allow HubSpot for this workflow when asked, or run the workflow from the extension. See Extension-only integrations in the web app.
Ask Aria