HubSpot MCP server and Dome
Let agents update your CRM. Keep them off your website and your schema.
Connect HubSpot's MCP server to Dome through a HubSpot MCP connector. Each rep consents once, and calls made for them run with their HubSpot permissions. Rules decide which HubSpot tools each agent can call.
How Dome helps
Dome provides a tool gateway and authorization for HubSpot
Records yes, schema no
manage_crm_objects stays open for record updates. New properties and pipelines are refused.
Nothing goes live
Landing pages, website pages, and blog posts are refused at the Gateway. An agent can't publish to your site.
Their HubSpot permissions
With per-user OAuth, each rep consents once. An agent acting for them reaches only the records they can.
Get started
HubSpot behind the Gateway in three steps
Create an MCP connector in HubSpot, add the server to Dome with its client credentials, and apply the rule. Agents reach HubSpot through the Gateway's single MCP endpoint.
01
Add the HubSpot MCP server
In HubSpot, create an MCP connector with https://api.domesystems.ai/oauth/callback as its redirect URL. Dome runs the OAuth flow with PKCE and holds each rep's tokens.
$ dome tools add --name hubspot \--url https://mcp.hubspot.com \--auth-method oauth --credential-type per-user \--oauth-authorize-url https://mcp.hubspot.com/oauth/authorize/user \--oauth-token-url https://mcp.hubspot.com/oauth/v3/token \--oauth-token-endpoint-auth client_secret_post \--oauth-client-id "$HUBSPOT_CLIENT_ID" \--oauth-client-secret "$HUBSPOT_CLIENT_SECRET" \--gateway revenue-gateway02
Sync the catalog
Run it once your own HubSpot consent is attached. HubSpot's tools vary by subscription and permissions, so the sync lists what your account has.
$ dome tools catalog sync hubspot03
Apply the rule
Scope it to one agent while you try it. Simulate before you deploy.
$ dome rules apply hubspot-crm-only.cedar \--agent deal-updater --name hubspot-crm-only
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about HubSpot itself, see HubSpot's documentation.
Rules
Update records, leave the rest
The permit opens HubSpot to the agent. The forbid refuses the tools that change your schema or publish content.
permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "hubspot" }; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "hubspot" && ["manage_custom_properties", "manage_custom_pipelines", "manage_landing_page", "manage_website_page", "manage_blog_post"].contains(resource.tool_name)};Example agents
Three agents on HubSpot
From our template library. Each one reads broadly and writes narrowly.
deal-updater
Keep deals current
Reads call notes and email threads, then updates deal stage and next steps on the record.
- hubspot/search_crm_objects
- hubspot/get_crm_objects
- hubspot/manage_crm_objects
account-researcher
Brief reps before a call
Pulls the company, its contacts, and open deals into a one-page brief. It changes nothing in HubSpot.
- hubspot/search_crm_objects
- hubspot/search_owners
- hubspot/query_crm_data
campaign-reporter
Report on campaigns
Reads campaign and marketing email results and writes the weekly summary. Pages stay with marketing.
- hubspot/read_campaign_data
- hubspot/get_campaign_attribution_reports
- hubspot/get_marketing_email_analytics
Agent workflow
Bringing it together
Connecting HubSpot to registered agents, models, and identity in Dome completes a governed agent application.
Acting for
Agent
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Tools
MCP server
HubSpot
This page
FAQ
Common questions
Does Dome work with HubSpot's remote MCP server?
Yes. Create an MCP connector in HubSpot, then add https://mcp.hubspot.com to Dome with its client ID and secret.
Can an AI agent update HubSpot records but not publish pages?
Yes. A rule allows manage_crm_objects and refuses manage_landing_page, manage_website_page, and manage_blog_post.
Whose HubSpot permissions does an agent use?
With per-user OAuth, the permissions of the rep it acts for. Dome picks their token from their verified identity.
What redirect URL does the HubSpot MCP connector need?
https://api.domesystems.ai/oauth/callback. Dome sends it on every authorization request.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreProvider
Anthropic
The Claude API behind the Model Broker: the key held in Dome, every call authorized, metered and audited.
Read moreIdentity
Okta
Okta tokens verified on every agent call, so rules and audit name the person each agent acted for.
Read moreRuntime
LangGraph
LangGraph agents with their model calls on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreAgent service
TinyFish
TinyFish's web agents behind the Tool Gateway, with rules that decide each run on the site it targets.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
MCP servers for AI agents: per-argument rules on every call
Put any remote MCP server behind the Tool Gateway. Agents reach it through one governed endpoint, and rules decide each call on its arguments.
See them all