Supported products
Supported products
Project structure
To add serverless function support to an existing project, run the following command:Function configuration
Thesrc/app/functions/private-function-hsmeta.json file provides the main configuration for your serverless functions, while the code for your serverless function is defined in the NewFunction.js file. These boilerplate files are meant as a starting point for your app, which can be adapted to fit your app’s needs.
- private-function-hsmeta.json
- NewFunction.js
function-hsmeta.json file:
Manage multiple serverless functions
2026.03 apps support multiple serverless functions, added via sets of.js and *-hsmeta.json files.
For example, to define another serverless function, you could create two new files, ‘SecondFunction.js’ and second-function-hsmeta.json in the src/app/functions/ directory:
second-private-function-hsmeta.json file references the path to SecondFunction.js, and it has a uid that’s distinct from the uid of any other function.
- second-private-function-hsmeta.json
Managing and referencing secrets
Secrets provide secure storage for any API keys, tokens, or other sensitive data your serverless function might need to use when making an external request. By default, a reserved secret namedPRIVATE_APP_ACCESS_TOKEN is accessible by default in every private serverless function to make HubSpot API requests on behalf of your app, but you can add new secrets if your serverless function needs to make other external requests.
To add a secret, use the hs secret add command. The example below would add a secret with a name of THIRD_PARTY_ACCESS_TOKEN:
secretKeys array in the corresponding private-function-hsmeta.json file:
Calling serverless functions
The way you invoke your serverless function depends on whether you configured a private function to run in a UI extension or whether you configured a publicly accessible endpoint.Private functions in UI extensions
To execute your serverless function from one of your UI extensions (e.g., an app card, app pages, or app settings page), use thehubspot.serverless() API, as demonstrated in the code block below:
Endpoint functions via public HTTP request
If you configured a public endpoint, you can make HTTP requests to the endpoint that you specified by theconfig.endpoint.path property in your function-hsmeta.json file.
The cURL example below demonstrates how to make a request to a function with a path of https://your-domain.com/hs/serverless/api/app_function_endpoint:
Function context
Serverless functions are passed acontext object, which contains metadata based on whether you configure your function to be private or public.
Private function
When your function is called from a UI extension (e.g., an app card, app home, or app settings page), thecontext object can be deconstructed to reference the properties shown below:
context in the UI extensions SDK reference.
Public function
If your serverless function is a publicly accessible endpoint, thecontext object contains the following fields:
Add NPM packages
Serverless functions support custom NPM dependencies. You can add them by runningnpm install <package-name> in the src/app/functions/ directory.
For example, if you wanted to add axios as a dependency, you’d run npm install axios in the src/app/functions/ directory, which would install axios and update the package.json file in the functions/ directory automatically:
Limitations
Keep the following limits in mind as you develop and test your function:- Functions have a 15 second execution timeout
- Functions may experience “cold starts” after periods of inactivity.
- Only privately distributed apps with static auth are currently supported. Apps using OAuth for authentication cannot use 2026.03 serverless functions.