Last modified: August 22, 2025
There are two ways to authenticate calls to HubSpot’s APIs: OAuth, and private app access tokens. Below, learn more about each method and how to include it in your code for authorization.
OAuth
To make a request using OAuth when building a public app, include the OAuth access token in the authorization header:Private app access tokens
Similar to OAuth, to make a request using a private app access token, include the token in the authorization header:Automatic token deactivation
To protect developers from potential security incidents, HubSpot leverages the monitoring and secret scanning capabilities provided by GitHub to detect any HubSpot authentication tokens that are publicly exposed in GitHub repositories. Any detected tokens will automatically be deactivated, and you will be notified via email and in-app notification so you can generate a new token and update your integrations to replace the revoked token.
- Developer API keys created within your app developer account.
- Personal Access Keys used to authenticate commands in the HubSpot CLI.
- Private access tokens used to authenticate requests in a private app.
- SMTP tokens used for sending transactional emails.