> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cloudthinker.io/llms.txt
> Use this file to discover all available pages before exploring further.

# HubSpot

> Connect HubSpot to CloudThinker with OAuth to search contacts, companies, deals, and tickets, and review sales pipelines

Connect your HubSpot account to let CloudThinker agents search contacts, companies, deals, and tickets, follow the links between them, and summarize a sales pipeline.

HubSpot authenticates with **OAuth** through its hosted server, so you do not create an API key or paste a credential into CloudThinker.

## Prerequisites

* A **HubSpot account** you can sign in to, with access to the records you want agents to read.
* Permission to authorize CloudThinker during HubSpot's OAuth flow.
* A browser that allows popups from CloudThinker, because HubSpot opens in a new window.

<Info>
  HubSpot states that the admin of the HubSpot account needs to connect first, to allow other users in the account to connect afterwards. If authorization is blocked, ask an account admin to connect first.
</Info>

## Setup

<Steps>
  <Step title="Open the connection">
    Navigate to **Connections → HubSpot** in your CloudThinker workspace and click **Connect**.
  </Step>

  <Step title="Open HubSpot">
    In the **Connect HubSpot** dialog, click **Open HubSpot**. CloudThinker opens HubSpot in a new window.
  </Step>

  <Step title="Select the account and grant access">
    Select the HubSpot account to connect, review the permissions, and authorize. HubSpot bases those permissions on your own user permissions.
  </Step>

  <Step title="Return to CloudThinker">
    Once HubSpot confirms, the dialog closes on its own. CloudThinker stores the tokens and shows a **Connected** status.
  </Step>
</Steps>

## Connection details

HubSpot uses OAuth, so there are no fields to fill in. CloudThinker keeps the access and refresh tokens and renews them without asking you again.

| Field | Description |
| - | - |
| **OAuth tokens** | Issued by HubSpot and stored automatically; no manual entry required |

## Required permissions

CloudThinker inherits what you grant during authorization. HubSpot does not let you define the scopes by hand: they follow the tools available when you install and the permissions you choose to grant.

* **Your user permissions apply.** HubSpot states that you can only view and modify records you already have access to, so agents never see more than the authorizing user.
* **Sensitive data stays out.** HubSpot does not expose custom Sensitive Data properties through this connection. If your account has Sensitive Data turned on, HubSpot also blocks calls, emails, meetings, notes, tasks, and conversation data.
* **Changes need approval.** HubSpot offers tools that change records. CloudThinker treats any tool that is not read-only as a change and pauses for your [approval](/guide/approval) first.

<Tip>
  Follow least privilege: authorize with a HubSpot user whose permissions cover only the records agents should see. CloudThinker cannot narrow the grant below what that user already has.
</Tip>

## Agent capabilities

Once connected, agents can:

| Capability | Description |
| - | - |
| **Account details** | Show the connected HubSpot user, the account, and which objects and tools are available |
| **Contacts and companies** | Search by query and open a record with the properties you ask for |
| **Deals** | Search deals and report amount, stage, and close date |
| **Tickets** | Search support tickets and open one by ID |
| **Associations** | Follow links, such as a contact's company |

### Verify the connection

```text theme={null}
Show which HubSpot account CloudThinker is connected to and which CRM objects I can read
```

### Example prompts

```text theme={null}
List open HubSpot deals with amount, stage, and close date
Find the HubSpot contact for buyer@example.com and the company they belong to
Summarize the last five HubSpot tickets for Example Corp
```

<Note>
  Ask for the properties you need, such as amount or stage. A narrow request returns faster and keeps the answer focused.
</Note>

## Troubleshooting

<Accordion title="Popup blocked. Please allow popups for this site.">
  Your browser blocked the HubSpot window. Allow popups for CloudThinker, then click **Open HubSpot** again.
</Accordion>

<Accordion title="Connection is taking longer than expected. Refresh to check its status.">
  CloudThinker did not see the connection finish. Refresh the page and check the status under **Connections → HubSpot**. If it is not **Connected**, start the connection again.
</Accordion>

<Accordion title="The provider rejected these credentials. Update them, then connect again.">
  HubSpot refused the stored authorization, for example because it expired or you revoked access. Start the connection again from **Connections → HubSpot** and authorize again.
</Accordion>

<Accordion title="This connection did not respond in time. Try connecting again.">
  HubSpot did not answer in time. Try connecting again.
</Accordion>

<Accordion title="Agents cannot see a record or a type of data">
  Your HubSpot user permissions decide what is visible, and some tools depend on your HubSpot subscription. Check that the authorizing user can open the record in HubSpot. HubSpot states that users must reinstall to grant new scopes, so reconnect if a newer capability is missing.
</Accordion>

## Security

* **Least privilege** — grant only the permissions the agents need for your use case; start read-only and widen later.
* **Read-only by default** — use read-only credentials unless you want agents to make changes through this connection.
* **Rotate credentials** — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
* **Revoke on offboarding** — remove the credential at the provider when you delete a connection or a teammate leaves.

- **Authorize as the right user** — the connection acts with that user's permissions, so use an account that only reaches what agents need.

## Related

<CardGroup cols={2}>
  <Card title="Approvals" icon="shield-check" href="/guide/approval">
    How CloudThinker holds a change for your confirmation
  </Card>

  <Card title="Connections" icon="plug" href="/guide/connections/overview">
    Every service you can connect to CloudThinker
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.