Dome Systems

HubSpot MCP server and Dome

Let agents update your CRM. Keep them off your website and your schema.

Connect HubSpot's MCP server to Dome through a HubSpot MCP connector. Each rep consents once, and calls made for them run with their HubSpot permissions. Rules decide which HubSpot tools each agent can call.

SalesAgentsDomeHubSpotCallersSalesAgentsdeal-updaterAgentsaccount-researcherAgentscampaign-reporterGatewaysrevenue-gatewayCRMContacts, companies, dealsContentPages and blogModel poolAny providerRulesGuardsAuditsaudit-trail
deal-updater→hubspot/search_crm_objects· as s.patelAllowed

How Dome helps

Dome provides a tool gateway and authorization for HubSpot

Records yes, schema no

manage_crm_objects stays open for record updates. New properties and pipelines are refused.

Nothing goes live

Landing pages, website pages, and blog posts are refused at the Gateway. An agent can't publish to your site.

Their HubSpot permissions

With per-user OAuth, each rep consents once. An agent acting for them reaches only the records they can.

Get started

HubSpot behind the Gateway in three steps

Create an MCP connector in HubSpot, add the server to Dome with its client credentials, and apply the rule. Agents reach HubSpot through the Gateway's single MCP endpoint.

  1. 01

    Add the HubSpot MCP server

    In HubSpot, create an MCP connector with https://api.domesystems.ai/oauth/callback as its redirect URL. Dome runs the OAuth flow with PKCE and holds each rep's tokens.

    $ dome tools add --name hubspot \
    --url https://mcp.hubspot.com \
    --auth-method oauth --credential-type per-user \
    --oauth-authorize-url https://mcp.hubspot.com/oauth/authorize/user \
    --oauth-token-url https://mcp.hubspot.com/oauth/v3/token \
    --oauth-token-endpoint-auth client_secret_post \
    --oauth-client-id "$HUBSPOT_CLIENT_ID" \
    --oauth-client-secret "$HUBSPOT_CLIENT_SECRET" \
    --gateway revenue-gateway
  2. 02

    Sync the catalog

    Run it once your own HubSpot consent is attached. HubSpot's tools vary by subscription and permissions, so the sync lists what your account has.

    $ dome tools catalog sync hubspot
  3. 03

    Apply the rule

    Scope it to one agent while you try it. Simulate before you deploy.

    $ dome rules apply hubspot-crm-only.cedar \
    --agent deal-updater --name hubspot-crm-only

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about HubSpot itself, see HubSpot's documentation.

Rules

Update records, leave the rest

The permit opens HubSpot to the agent. The forbid refuses the tools that change your schema or publish content.

permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when { resource.connection_name == "hubspot" };
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "hubspot" &&
["manage_custom_properties", "manage_custom_pipelines", "manage_landing_page",
"manage_website_page", "manage_blog_post"].contains(resource.tool_name)
};

Example agents

Three agents on HubSpot

From our template library. Each one reads broadly and writes narrowly.

deal-updater

Keep deals current

Reads call notes and email threads, then updates deal stage and next steps on the record.

  • hubspot/search_crm_objects
  • hubspot/get_crm_objects
  • hubspot/manage_crm_objects

account-researcher

Brief reps before a call

Pulls the company, its contacts, and open deals into a one-page brief. It changes nothing in HubSpot.

  • hubspot/search_crm_objects
  • hubspot/search_owners
  • hubspot/query_crm_data

campaign-reporter

Report on campaigns

Reads campaign and marketing email results and writes the weekly summary. Pages stay with marketing.

  • hubspot/read_campaign_data
  • hubspot/get_campaign_attribution_reports
  • hubspot/get_marketing_email_analytics

Agent workflow

Bringing it together

Connecting HubSpot to registered agents, models, and identity in Dome completes a governed agent application.

Dome

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

Tools

MCP server

HubSpot

This page

FAQ

Common questions

Does Dome work with HubSpot's remote MCP server?

Yes. Create an MCP connector in HubSpot, then add https://mcp.hubspot.com to Dome with its client ID and secret.

Can an AI agent update HubSpot records but not publish pages?

Yes. A rule allows manage_crm_objects and refuses manage_landing_page, manage_website_page, and manage_blog_post.

Whose HubSpot permissions does an agent use?

With per-user OAuth, the permissions of the rep it acts for. Dome picks their token from their verified identity.

What redirect URL does the HubSpot MCP connector need?

https://api.domesystems.ai/oauth/callback. Dome sends it on every authorization request.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.