OneCLI connects AI agents to HubSpot through OAuth. Agents can read and manage CRM records including contacts, companies, deals, and tickets. The gateway injects OAuth credentials into requests to the HubSpot API automatically.
On self-hosted OneCLI, HubSpot needs your own HubSpot app first. See Self-hosted.
Open the OneCLI dashboard and navigate to Connections > HubSpot.
2
Authorize
Click Connect HubSpot. You’ll be redirected to HubSpot to authorize OneCLI. Review the requested permissions and click Grant access.
The HubSpot connect window on OneCLI Cloud.
OneCLI requests read access to contacts, companies, deals, owners, and tickets by default. Write access and additional scopes (line items, quotes, lists, schemas) are optional.
3
Verify
After authorization, you’ll be redirected back to the dashboard. The connection will show as Connected with your HubSpot portal domain.
Skip this section on OneCLI Cloud. It’s only for self-hosted OneCLI without HUBSPOT_CLIENT_ID and HUBSPOT_CLIENT_SECRET set, or if you want your own company name on HubSpot’s consent screen.
1. Create the HubSpot app
Sign in to a HubSpot developer account (free). Open Apps > Create app, name it OneCLI, and open the Auth tab.
2. Add the scopes
Under Scopes, add these as Required:crm.objects.contacts.read, crm.objects.companies.read, crm.objects.deals.read, crm.objects.owners.read, tickets
The required scopes in HubSpot. HubSpot adds oauth on its own.
Add these as Optional, so agents can get write access when you grant it:crm.objects.contacts.write, crm.objects.companies.write, crm.objects.deals.write, crm.objects.line_items.read, crm.objects.quotes.read, crm.lists.read, crm.schemas.contacts.read, crm.schemas.companies.read, crm.schemas.deals.read
3. Add the redirect URL
In OneCLI, open Connections > HubSpot > Custom credentials and copy the Redirect URI. In HubSpot, paste it into Redirect URLs on the Auth tab, and save.
The OneCLI Redirect URI in HubSpot's Redirect URLs.
Copy the Redirect URI from Custom credentials in OneCLI.
4. Connect with your app
On the Auth tab, copy the Client ID and Client secret. Paste both into Connections > HubSpot > Custom credentials, select Save & Connect, and grant access in HubSpot.
Access is per agent: grant the connection to each agent that needs it, choosing per tool what runs freely, what needs human approval, and what stays blocked — a read-only agent is a single grant. Organization rules add guardrails on top, like rate limits and blanket blocks. Everything is checked before credential injection, so a blocked request never reaches the HubSpot API.