Skip to main content

Overview

OneCLI connects AI agents to HubSpot through OAuth. Agents can read and manage CRM records including contacts, companies, deals, and tickets. The gateway injects OAuth credentials into requests to the HubSpot API automatically.
On self-hosted OneCLI, HubSpot needs your own HubSpot app first. See Self-hosted.

Setup

1

Go to Connections

Open the OneCLI dashboard and navigate to Connections > HubSpot.
2

Authorize

Click Connect HubSpot. You’ll be redirected to HubSpot to authorize OneCLI. Review the requested permissions and click Grant access.
OneCLI connect window for HubSpot on Cloud, showing the Connect to HubSpot button.

The HubSpot connect window on OneCLI Cloud.

OneCLI requests read access to contacts, companies, deals, owners, and tickets by default. Write access and additional scopes (line items, quotes, lists, schemas) are optional.
3

Verify

After authorization, you’ll be redirected back to the dashboard. The connection will show as Connected with your HubSpot portal domain.

Self-hosted: use your own HubSpot app

Skip this section on OneCLI Cloud. It’s only for self-hosted OneCLI without HUBSPOT_CLIENT_ID and HUBSPOT_CLIENT_SECRET set, or if you want your own company name on HubSpot’s consent screen.

1. Create the HubSpot app

Sign in to a HubSpot developer account (free). Open Apps > Create app, name it OneCLI, and open the Auth tab.
Under Scopes, add these as Required:crm.objects.contacts.read, crm.objects.companies.read, crm.objects.deals.read, crm.objects.owners.read, tickets
HubSpot app Scopes section with six required scopes: crm.objects.contacts.read, crm.objects.companies.read, crm.objects.deals.read, crm.objects.owners.read, tickets, and oauth.

The required scopes in HubSpot. HubSpot adds oauth on its own.

Add these as Optional, so agents can get write access when you grant it:crm.objects.contacts.write, crm.objects.companies.write, crm.objects.deals.write, crm.objects.line_items.read, crm.objects.quotes.read, crm.lists.read, crm.schemas.contacts.read, crm.schemas.companies.read, crm.schemas.deals.read
In OneCLI, open Connections > HubSpot > Custom credentials and copy the Redirect URI. In HubSpot, paste it into Redirect URLs on the Auth tab, and save.
HubSpot Redirect URLs section with one entry: https://onecli.example.com/v1/apps/hubspot/callback.

The OneCLI Redirect URI in HubSpot's Redirect URLs.

OneCLI Custom credentials card for HubSpot with the setup guide link, the Redirect URI and its copy button, and the client ID and secret fields.

Copy the Redirect URI from Custom credentials in OneCLI.

On the Auth tab, copy the Client ID and Client secret. Paste both into Connections > HubSpot > Custom credentials, select Save & Connect, and grant access in HubSpot.

What agents can do

Use cases

  • CRM enrichment agents that update contact records with data from other sources
  • Sales pipeline agents that track deals and update stages
  • Support agents that create and triage tickets
  • Reporting agents that pull CRM data for analysis

Controlling access

Access is per agent: grant the connection to each agent that needs it, choosing per tool what runs freely, what needs human approval, and what stays blocked — a read-only agent is a single grant. Organization rules add guardrails on top, like rate limits and blanket blocks. Everything is checked before credential injection, so a blocked request never reaches the HubSpot API.