---
title: "HubSpot MCP Goes GA: What Marketers Need to Know"
description: "HubSpot's Model Context Protocol (MCP) is now generally available. Learn the security requirements, remote vs."
canonical: https://epinium.com/en/blog/hubspot-mcp-goes-ga-what-marketers-need-to-know/
lang: en
date: 2026-10-08T06:25:30
---

**Executive summary**
- HubSpot has officially moved its Model Context Protocol (MCP) capabilities from experimental to General Availability (GA), with the remote hosted server reaching GA status on April 13, 2026.
- The remote MCP server now supports full read and write operations for CRM records and activities, but strictly requires OAuth 2.1 with PKCE for authentication, making it significantly more secure than previous API key methods.
- If your HubSpot account has "Sensitive Data" features enabled, access to activity objects (calls, emails, notes) via MCP is automatically blocked, creating a blind spot for AI agents trying to analyze customer interactions.
- The local Developer MCP Server is distinct from the remote one; it requires the official HubSpot CLI version 8.2.0 or higher and is designed specifically for developers building CMS extensions, not for general business data querying.
- As of September 2026, HubSpot expanded MCP support to include read and write capabilities for Custom Objects (types 2-*) and the Leads object, unlocking deeper automation potential for complex B2B workflows.

## Why "Just Connect the API" Is No Longer Enough for Your CRM Data

You know the feeling. You’re staring at your dashboard, trying to figure out why a specific segment of leads is stalling. You’ve got the data, but pulling it, cleaning it, and cross-referencing it takes hours of manual work. Or worse, you’re relying on a brittle Zapier or Make connection that breaks every time HubSpot updates a field name.

Here is where most teams get it wrong. They treat their CRM as a static database to be queried via standard REST APIs. That approach worked in 2020. It does not work in 2026. The shift to Model Context Protocol (MCP) changes the dynamic entirely. It stops being about "sending a request to an endpoint" and starts being about giving an AI agent direct, contextual access to your business logic.

The misconception is that MCP is just a "better API." It isn’t. It’s a different paradigm. When you use a standard API, you have to define every single parameter, filter, and pagination rule before the call happens. With MCP, the AI model can inspect the schema, understand the relationships between objects, and decide on the fly how to retrieve the data it needs. This fluidity is what allows AI tools to move from being "chatbots that guess" to "agents that act."

For brand managers and COOs, this means the gap between "asking for a report" and "getting a live, verified insight" shrinks to seconds. But it also introduces complexity. You aren’t just installing a plugin; you are opening a door to your most sensitive customer data. If you haven’t thought about who is holding the keys to that door, you are exposed.

## The Two Servers: Where Most Developers and Marketers Get Confused

HubSpot currently offers two distinct MCP servers. Confusing them is the fastest way to waste a sprint cycle.

**1. The Remote Hosted Server**
This is the one you care about if you want to connect AI tools to your production CRM data. It is hosted by HubSpot, which means you don’t have to run it locally. The official endpoint is `mcp.hubspot.com`. This server reached General Availability (GA) on April 13, 2026. Since then, it has incorporated full read and write capabilities for CRM records and activities. [HubSpot Developer Platform](https://developers.hubspot.com/mcp)

**2. The Local Developer Server**
This is a tool for developers. It runs on your machine. If you are trying to build a new app or extension for the HubSpot CMS, this is your friend. It requires the official HubSpot CLI, specifically version 8.2.0 or higher. You install it, run the command `hs mcp setup`, and it spins up a local instance for your development environment. [HubSpot Docs](https://developers.hubspot.com/docs/developer-tooling/local-development/hubspot-cli/install-the-cli)

Here is the contrarian take: Most companies should ignore the Local Developer Server unless they are actively building custom HubSpot applications. For 95% of businesses, the Remote Hosted Server is the only relevant option. Trying to run a local server in a production environment is a security nightmare and a maintenance burden you don’t need. The remote server is managed, updated, and secured by HubSpot. Use that.

If you are wondering about the broader context of what MCP actually is and how it differs from traditional integration methods, it’s worth understanding the underlying architecture before you dive into configuration. You can read more about the fundamentals in our guide on [What is MCP](/en/blog/what-is-mcp/). Understanding the protocol helps you avoid the trap of thinking it’s just another web service.

## Security Is Not a Feature, It’s the Foundation

Let’s talk about authentication, because this is where the rubber meets the road.

The remote MCP server for HubSpot mandates the use of **OAuth 2.1 with PKCE (Proof Key for Code Exchange)**. This is not optional. You cannot use a simple API token. You cannot use a basic API key. The system requires this specific, modern authentication flow. [HubSpot Docs](https://developers.hubspot.com/docs/apps/developer-platform/build-apps/integrate-with-the-remote-hubspot-mcp-server)

Why does this matter to you? Because PKCE adds a layer of security that prevents interception attacks. In the past, if you passed an API token through a URL or an insecure channel, it was compromised. With PKCE, the authorization code is bound to a specific request, making it much harder for malicious actors to hijack the session.

However, security also means restrictions. This is a critical detail that many teams overlook until it’s too late: **If your HubSpot account has "Sensitive Data" features enabled, access to activity objects is automatically blocked via the MCP server.** [HubSpot Developer Changelog](https://developers.hubspot.com/docs/apps/developer-platform/build-apps/integrate-with-the-remote-hubspot-mcp-server)

What are "activity objects"? Calls, emails, meetings, notes, and tasks.

If your compliance team has flagged your data as sensitive (common in healthcare, finance, or enterprise B2B), your AI agents will be blind to the very interactions that drive your sales pipeline. They can see that a deal exists. They can see the deal value. But they cannot read the email threads or the call notes that explain *why* the deal is stalled.

This is a trade-off. You gain the power of AI automation, but you lose visibility into unstructured communication data if you prioritize data privacy controls. You need to make this decision consciously. Do you want the AI to have full context, or do you want to keep the most sensitive communication data siloed? There is no default "best" answer; it depends on your risk tolerance.

## What Changed in September 2026? The Custom Object Breakthrough

For a long time, the MCP capabilities for HubSpot were limited to the standard CRM objects: Contacts, Companies, Deals, and Tickets. If your business runs on custom workflows, you were stuck.

That changed with the **Spotlight Fall 2026** update in September 2026. HubSpot enabled support for read and write operations in the MCP server for **Custom Objects (types 2-*)** and for the **Leads object**. [HubSpot Developers Spotlight](https://developers.hubspot.com/docs/apps/developer-platform/build-apps/integrate-with-the-remote-hubspot-mcp-server)

This is a massive unlock.

Think about your sales process. You probably have custom objects for "Products," "Subscriptions," "Support Contracts," or "Marketing Campaigns." Previously, an AI agent couldn’t natively interact with these via MCP. Now, it can.

Imagine a scenario: An AI agent detects a drop in usage for a specific custom "Subscription Tier" object. It can now query the MCP server to find all customers on that tier, check their associated Deals, and even draft a personalized retention email based on the context. It can write back to the CRM to log the action.

This moves AI from being a passive analyst to an active participant in your business operations. The ability to write to Custom Objects means you can automate complex multi-step workflows that were previously impossible without custom coding.

If you are working with databases that aren’t native to HubSpot, you might be looking at how to bridge these gaps. For instance, if you store some of your product data in a separate database, you might be interested in how MCP connects to other systems, as discussed in our guide on [Supabase MCP AI Database](/en/blog/supabase-mcp-ai-database/). The principles are similar: give the AI a context window, let it retrieve and manipulate data safely.

FREE SESSION
[See Epinium’s AI services →](https://epinium.com/en/ai-consulting/)
free 30-min diagnostic

## Comparing MCP to Traditional Integration Methods

To really understand the value, you have to look at how MCP compares to the tools you are already using. Here is a breakdown:

| Feature | Standard REST API | Zapier/Make (iPaaS) | HubSpot MCP Server |
| :--- | :--- | :--- | :--- |
| **Data Access** | Manual query construction | Pre-built or custom triggers | AI-driven, contextual retrieval |
| **Authentication** | API Keys / OAuth | OAuth / API Keys | OAuth 2.1 + PKCE (Mandatory) |
| **Flexibility** | High (if you code) | Low (limited to app templates) | High (AI decides path) |
| **Write Capabilities** | Yes (full CRUD) | Yes (limited by triggers) | Yes (GA for records/activities) |
| **Custom Objects** | Yes | Yes (if supported) | Yes (Since Sept 2026) |
| **Security Model** | Static tokens common | Varies by app | Dynamic, PKCE-enhanced |
| **Learning Curve** | High (Developer) | Low (Marketer) | Medium (Hybrid) |

The key difference is **context**. With a REST API, you must tell the system *exactly* what to fetch. With MCP, the AI model can look at the schema, see that `Deal` is linked to `Company`, and decide to fetch both in a single logical step. This reduces the number of API calls and, more importantly, reduces the cognitive load on the user asking for the data.

Another angle is the integration with other AI tools. MCP is becoming the standard way for AI assistants to talk to data. If you are using tools like Zapier to automate your workflows, you might be curious about how these two technologies intersect. Our article on the [MCP Zapier Integration Guide](/en/blog/mcp-zapier-integration-guide/) explores how you can use MCP servers within automation platforms, allowing you to combine the flexibility of AI with the reliability of established iPaaS tools.

## Connecting Epinium’s MCP to Your Workflow

You don’t need to be a developer to benefit from this. At Epinium, we build the bridge between your existing tech stack and these new AI capabilities. We don’t just hand you a set of instructions and say "good luck." We integrate.

For example, our platform uses the [Epinium MCP connection](/en/platform/connections/epinium-mcp/) to allow AI agents to read and interact with your data securely. This means if you are using Epinium to manage your e-commerce or brand analytics, you can extend those capabilities into your CRM without building a custom bridge.

The difference between using an API and using MCP in a real-world business context is often misunderstood. Many marketers think MCP is just a technical detail. It isn’t. It’s the interface between your business intelligence and your AI tools. To understand the fundamental differences in capability and architecture, you can read our comparison of [MCP vs API](/en/blog/mcp-vs-api/). It breaks down why the "protocol" matters more than the "endpoint."

The goal is simple: your AI should know your business. It should know who your customers are, what they bought, and why they are buying. But it needs to do it safely. It needs to do it without breaking your compliance rules. And it needs to do it without you spending six months writing code.

## What to Expect in 2026 and Beyond

We are currently in the early adoption phase of MCP for major CRM platforms. HubSpot’s move to GA in April 2026 and the expansion to Custom Objects in September 2026 signal that this is not a fad. It is becoming infrastructure.

What does this mean for the next 6-12 months?

1.  **Standardization of Security:** More platforms will likely adopt the OAuth 2.1 + PKCE standard for MCP endpoints. Expect stricter security requirements for any AI tool that wants to touch your data.
2.  **Granular Permissions:** We expect HubSpot to release more granular permission scopes for MCP. Currently, it’s somewhat all-or-nothing regarding Sensitive Data. In the future, you might be able to allow AI to read call notes but not write to them, or vice versa.
3.  **Cross-Platform Context:** The real power of MCP isn’t just connecting to one CRM. It’s connecting to *everything*. Imagine an AI agent that reads your HubSpot CRM via MCP, checks your inventory via a Shopify MCP server, and analyzes your ad spend via an Ads platform. That is the future. It is the "Full Commerce" view where every channel is connected in a single context.

If you are a brand manager or CTO, this is your signal to start experimenting. You don’t need to overhaul your entire stack. Start with one use case. Maybe it’s automating the tagging of new leads. Maybe it’s generating a weekly summary of high-value deals. Use the MCP server to let your AI tools touch the data.

The barrier to entry is lower than you think. You don’t need to build a custom server. You just need to configure the authentication and define the permissions. The hard part isn’t the technical setup; it’s the strategic decision of what data you are comfortable letting the AI see.

## Frequently Asked Questions

### Does HubSpot MCP support all CRM objects?
As of September 2026, the remote MCP server supports standard objects (Contacts, Companies, Deals, Tickets, Leads) and Custom Objects (types 2-*). However, support for "activity objects" (calls, emails, notes) is conditional. If your account has Sensitive Data features enabled, access to these activity objects is blocked automatically via the MCP server. You must check your account settings to see if this restriction applies to you.

### What is the difference between the local and remote HubSpot MCP servers?
The remote server is hosted by HubSpot and is intended for production use, allowing AI tools to access live CRM data. The local server is a development tool that runs on your machine. It requires the HubSpot CLI (version 8.2.0+) and is used by developers to build new applications or extensions for the HubSpot CMS. Most business users should only interact with the remote server.

### Is OAuth 2.1 with PKCE mandatory for the remote server?
Yes. The official documentation states that authentication for the remote hosted MCP server requires the use of OAuth 2.1 with PKCE (Proof Key for Code Exchange). Traditional API keys or simple tokens are not supported for this specific endpoint. This is a security measure to ensure that the connection between the AI tool and your CRM is secure and authenticated.

### Can I use HubSpot MCP with third-party AI tools?
Yes. The MCP server is designed to be a standard interface. Any AI tool that supports the Model Context Protocol can connect to the `mcp.hubspot.com` endpoint, provided it can handle the OAuth 2.1 + PKCE authentication flow. This includes general-purpose AI assistants, specialized CRM AI agents, and custom-built internal tools.

### What happened with the "Spotlight Fall 2026" update?
The Spotlight Fall 2026 update, released in September 2026, was a significant milestone. It added read and write support for Custom Objects (types 2-*) and the Leads object to the remote MCP server. This expansion allows AI agents to interact with more complex, non-standard data structures that are common in B2B workflows.

### Does enabling Sensitive Data in HubSpot block MCP access?
It blocks specific parts of the access. If Sensitive Data features are active, access to activity objects (calls, emails, meetings, notes, tasks) is blocked via the MCP server. Access to other objects (like Contacts and Deals) may still be available, depending on your specific permission scopes. This is a compliance-driven restriction, not a technical limitation of the MCP protocol itself.

### How does MCP differ from a standard HubSpot API?
The primary difference is context and agency. A standard API requires you to define exact queries. MCP allows an AI model to inspect the data schema and decide how to retrieve information dynamically. This makes MCP more suitable for AI-driven automation and natural language queries, while standard APIs are better for rigid, predictable system-to-system integrations.

### Do I need to upgrade my HubSpot plan to use MCP?
The availability of MCP features depends on your HubSpot subscription tier and the specific features enabled on your account. While the MCP server itself is a platform feature, access to certain objects or write capabilities may be restricted based on your plan. You should consult HubSpot’s pricing and feature matrix to confirm which objects are accessible under your current subscription.

### Can I write data back to HubSpot via MCP?
Yes. Since the General Availability release in April 2026, the remote MCP server has incorporated full read and write capabilities for CRM records and activities. This means AI agents can not only query data but also update records, create new tasks, or modify deal stages, provided the authentication and permission scopes allow it.

### What is the role of the HubSpot CLI in MCP?
The HubSpot CLI is required only for the *local* Developer MCP Server. It is used to set up the local environment for developers. For the *remote* hosted server, which is the one most businesses use, you do not need to install or run the CLI. The CLI is a developer tool, not a business user tool.

## The Next Step Is Clarity, Not Complexity

The technology is ready. The security models are in place. The data structures are open. What’s missing is the strategy.

You have a choice. You can keep doing things the way you did last year: manual reports, brittle integrations, and AI tools that hallucinate because they don’t have real data. Or you can start building a data-first AI strategy.

But you don’t have to do it alone. And you definitely don’t have to guess.

At Epinium, we’ve been in the retail and brand space for over a decade. We’ve seen the shift from "digital marketing" to "full commerce." We know what it takes to connect your CRM to your e-commerce, your ads, and your AI. We don’t just sell you a tool; we build the system.

If you’re not sure where to start, or if you’re worried about the security implications of opening your CRM to AI agents, let’s talk. We can look at your current setup, identify the gaps, and map out a safe, effective path forward.

SERVICES BY EPINIUM
**Stop guessing. Start connecting.** We’ve helped over 50 brands turn their data into automated growth engines. [Book free diagnostic →](https://epinium.com/en/contact/)
free 30-min diagnostic

<script type="application/ld+json">
{
  "@context": "https://schema.org",
  "@type": "FAQPage",
  "mainEntity": [
    {
      "@type": "Question",
      "name": "Does HubSpot MCP support all CRM objects?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "As of September 2026, the remote MCP server supports standard objects (Contacts, Companies, Deals, Tickets, Leads) and Custom Objects (types 2-*). However, support for 'activity objects' (calls, emails, notes) is conditional. If your account has Sensitive Data features enabled, access to these activity objects is blocked automatically via the MCP server. You must check your account settings to see if this restriction applies to you."
      }
    },
    {
      "@type": "Question",
      "name": "What is the difference between the local and remote HubSpot MCP servers?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "The remote server is hosted by HubSpot and is intended for production use, allowing AI tools to access live CRM data. The local server is a development tool that runs on your machine. It requires the HubSpot CLI (version 8.2.0+) and is used by developers to build new applications or extensions for the HubSpot CMS. Most business users should only interact with the remote server."
      }
    },
    {
      "@type": "Question",
      "name": "Is OAuth 2.1 with PKCE mandatory for the remote server?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Yes. The official documentation states that authentication for the remote hosted MCP server requires the use of OAuth 2.1 with PKCE (Proof Key for Code Exchange). Traditional API keys or simple tokens are not supported for this specific endpoint. This is a security measure to ensure that the connection between the AI tool and your CRM is secure and authenticated."
      }
    },
    {
      "@type": "Question",
      "name": "Can I use HubSpot MCP with third-party AI tools?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Yes. The MCP server is designed to be a standard interface. Any AI tool that supports the Model Context Protocol can connect to the mcp.hubspot.com endpoint, provided it can handle the OAuth 2.1 + PKCE authentication flow. This includes general-purpose AI assistants, specialized CRM AI agents, and custom-built internal tools."
      }
    },
    {
      "@type": "Question",
      "name": "What happened with the 'Spotlight Fall 2026' update?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "The Spotlight Fall 2026 update, released in September 2026, was a significant milestone. It added read and write support for Custom Objects (types 2-*) and the Leads object to the remote MCP server. This expansion allows AI agents to interact with more complex, non-standard data structures that are common in B2B workflows."
      }
    },
    {
      "@type": "Question",
      "name": "Does enabling Sensitive Data in HubSpot block MCP access?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "It blocks specific parts of the access. If Sensitive Data features are active, access to activity objects (calls, emails, meetings, notes, tasks) is blocked via the MCP server. Access to other objects (like Contacts and Deals) may still be available, depending on your specific permission scopes. This is a compliance-driven restriction, not a technical limitation of the MCP protocol itself."
      }
    },
    {
      "@type": "Question",
      "name": "How does MCP differ from a standard HubSpot API?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "The primary difference is context and agency. A standard API requires you to define exact queries. MCP allows an AI model to inspect the data schema and decide how to retrieve information dynamically. This makes MCP more suitable for AI-driven automation and natural language queries, while standard APIs are better for rigid, predictable system-to-system integrations."
      }
    },
    {
      "@type": "Question",
      "name": "Do I need to upgrade my HubSpot plan to use MCP?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "The availability of MCP features depends on your HubSpot subscription tier and the specific features enabled on your account. While the MCP server itself is a platform feature, access to certain objects or write capabilities may be restricted based on your plan. You should consult HubSpot’s pricing and feature matrix to confirm which objects are accessible under your current subscription."
      }
    },
    {
      "@type": "Question",
      "name": "Can I write data back to HubSpot via MCP?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Yes. Since the General Availability release in April 2026, the remote MCP server has incorporated full read and write capabilities for CRM records and activities. This means AI agents can not only query data but also update records, create new tasks, or modify deal stages, provided the authentication and permission scopes allow it."
      }
    },
    {
      "@type": "Question",
      "name": "What is the role of the HubSpot CLI in MCP?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "The HubSpot CLI is required only for the local Developer MCP Server. It is used to set up the local environment for developers. For the remote hosted server, which is the one most businesses use, you do not need to install or run the CLI. The CLI is a developer tool, not a business user tool."
      }
    }
  ]
}
</script>