HubSpot MCP server
Last verified: 2026-09
Contacts and deals in HubSpot.
Community Chat, mail & docs Needs a secret Claude Desktop, Cursor, Windsurf, Claude Code
What it does
HubSpot CRM contacts and companies: create, get, update. Needs a private app token.
It sits in Chat, mail & docs: These servers act as the bot or the integration you install.
Good for
- Get a contact you already know the id or email of.
- Create a contact in a sandbox portal with duplicate checking.
- Update a test record, not the production pipeline.
- Skip it if Salesforce is the CRM of record.
Tools
- hubspot_create_contact — Create a contact (duplicate-aware).
- get / update contact or company — By id. Confirm exact names after connect.
Config (Claude Desktop / Cursor / Windsurf)
Paste the JSON below. Same mcpServers shape. Replace placeholder paths and secrets.
Windows paths look like C:\\Users\\you\\project, not /path/to.
Host-side steps →
Claude Desktop
| OS | Config file |
|---|---|
| macOS | ~/Library/Application Support/Claude/claude_desktop_config.json |
| Windows | %APPDATA%\Claude\claude_desktop_config.json
(usually C:\Users\<you>\AppData\Roaming\Claude\) |
| Linux | ~/.config/Claude/claude_desktop_config.json |
Cursor
| Scope | macOS / Linux | Windows |
|---|---|---|
| This project | .cursor/mcp.json in the repo root | |
| This user | ~/.cursor/mcp.json |
%USERPROFILE%\.cursor\mcp.json |
Windsurf
| OS | Config file |
|---|---|
| macOS / Linux | ~/.codeium/windsurf/mcp_config.json |
| Windows | %USERPROFILE%\.codeium\windsurf\mcp_config.json |
{
"mcpServers": {
"hubspot": {
"command": "npx",
"args": [
"-y",
"hubspot-mcp"
],
"env": {
"HUBSPOT_ACCESS_TOKEN": "pat-..."
}
}
}
}
Windsurf remote MCP: use serverUrl instead of url if the block below is HTTP.
One-liner: npx -y hubspot-mcp
Secrets it wants: HUBSPOT_ACCESS_TOKEN
How to get started
- Create a HubSpot private app with crm.objects.contacts read. Add write only if you want creates.
- Set HUBSPOT_ACCESS_TOKEN. Get one contact you know.
- Do not connect a production portal with create enabled on day one.
Access risk
CRM write + GDPR. A token can export your pipeline.
When to skip it
Skip it for Salesforce or for a store that already lives in Shopify.
Instead: Salesforce, Shopify, Airtable.
Vs alternatives
| Server | Official? | Needs a secret? | Best for |
|---|---|---|---|
| HubSpot | No | Yes | Contacts and deals in HubSpot. |
| Salesforce | No | Yes | SOQL and sObjects. |
| Shopify | No | Yes | Catalog and orders on a Shopify store. |
| Airtable | No | Yes | Read and write Airtable bases. |
More in Chat, mail & docs
FAQ
Which token?
A private app token with crm.objects.contacts read. Add write only for creates.
HubSpot or Salesforce?
Match the CRM. Two write tokens will fork the pipeline.
Can it export the funnel?
A wide token can. That is a GDPR incident if it lands in a log.
Official HubSpot?
Community package. Confirm the repo before a production portal token.