HubSpot
Connect HubSpot as access review source using OAuth or a private application access token so the platform can list your account users and roles.
The platform reads your HubSpot account users through Settings Users, CRM Owners and Account Activity APIs so you can verify who has access. Connect (OAuth) is the recommended method and does not require token management. A private access token is also available if you prefer not to authorize an OAuth application.
Prerequisites
Section entitled ‘Prerequisites’- the platform organization administrator access
- The Super Admin permission in HubSpot (only superadministrators can create and manage private apps, and OAuth permission requires the same access)
Collected Fields
Section entitled “Collected Fields”| the platform field | HubSpot field | Notes |
|---|---|---|
| Name | firstName, lastName |
Returns to the user's email address when none of the names are set |
email |
||
| Role | roleId, roleIds |
Resolved to roles via rolesAPI; Super Admin is added when superAdmin is true; returns to User when nothing is resolved |
| Admin | superAdmin |
|
| Status | archived (CRM Owners) |
Inactive when the user matches a owner's record with archived true; otherwise active |
| MFA | Not supported | HubSpot’s APIs expose no MFA field |
| Last login | loginAt (Account activity, only successful authentications) |
Cover the last 90 days. left empty when the token has no scope account-info.security.read |
| External ID | id (User settings) or userIdIncludingInactive |
Stable ID used to track your account through reviews |
| Created at | Not supported |
Settings UsersAPI has no state field, so the platform makes cross-references to the CRMAPI owner archive list to mark inactive users.
Connect HubSpot
Section entitled “Connect HubSpot”Option A: Connect with HubSpot (recommended)
Option A: Connect with HubSpot (recommended)- On the platform, go to Access Reviews > Sources > Add Source.
- Find HubSpot and click Connect.
- Sign in as a superadministrator and authorize the platform to the HubSpot account you want to review.
settings.users.read,crm.objects.owners.read, andaccount-info.security.readscopes.
Option B: Private App Access Token
Section “Option B: Private App Access Token”- In HubSpot (signed as super admin), go to Settings > Integrations > Private Apps, and click Create a private app.
- Name it (for example
Probo Access Review), open the Scopes tab, and add reading purposessettings.users.read,crm.objects.owners.read, andaccount-info.security.read. - Click Create app, confirm and copy the access token (
pat-…). - On the platform, go to Access Reviews > Sources > Add Source, find HubSpotOpen Dropdown next to Connect, and click Connect with API Key.
- Press the token and click Connect.
The platform names the source after your HubSpot account and attracts its users to your campaigns.
Troubleshooting
Section “Troubleshooting”- Key rejected. Confirm the private application was created by a super administrator and grants all three domains above; a missing token
settings.users.readorcrm.objects.owners.readcannot list users. - Last login is always empty. The token or OAuth authorization lacks the domain
account-info.security.read. the platform leaves the last login empty, rather than fail the review when this domain is absent. - A deactivated user still shows Active. the platform marks an inactive user only when a corresponding CRM owner record has
archivedset to true.A user removed by another method that HubSpot has not yet archived as owner may still appear active until HubSpot updates that record.