Hubspot Integration
aiskillstore/marketplace
Expert patterns for HubSpot CRM integration including OAuth authentication, CRM objects, associations, batch operations, webhooks, and custom objects.
Authenticate production HubSpot integrations and survive the auth-side failures — 30-min token expiry storms, 500K daily rate-limit burnout, scope drift, token leakage in commits, multi-portal…
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill hubspot-auth -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace hubspot-auth --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/hubspot-auth .claude/skills/hubspot-auth && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "hubspot-auth" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/hubspot-auth into .claude/skills/hubspot-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hubspot-auth", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/hubspot-authType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill hubspot-auth -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace hubspot-auth --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/.curated/hubspot-auth .agents/skills/hubspot-auth && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "hubspot-auth" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/hubspot-auth into .agents/skills/hubspot-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hubspot-auth", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill hubspot-auth -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace hubspot-auth --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/.curated/hubspot-auth .cursor/skills/hubspot-auth && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "hubspot-auth" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/hubspot-auth into .cursor/skills/hubspot-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hubspot-auth", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/jeremylongshore/tons-of-skills-marketplace.git --path skills/.curated/hubspot-auth--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill hubspot-auth -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace hubspot-auth --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/.curated/hubspot-auth .gemini/skills/hubspot-auth && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "hubspot-auth" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/hubspot-auth into .gemini/skills/hubspot-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hubspot-auth", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install jeremylongshore/tons-of-skills-marketplace hubspot-authInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill hubspot-auth -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/.curated/hubspot-auth .github/skills/hubspot-auth && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "hubspot-auth" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/hubspot-auth into .github/skills/hubspot-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hubspot-auth", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill hubspot-auth -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace hubspot-auth --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/.curated/hubspot-auth .opencode/skills/hubspot-auth && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "hubspot-auth" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/hubspot-auth into .opencode/skills/hubspot-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hubspot-auth", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
hubspot-authAuthenticate production HubSpot integrations and survive the auth-side failures — 30-min token expiry storms, 500K daily rate-limit burnout, scope drift, token leakage in commits, multi-portal…
Hubspot Auth is an agent skill from jeremylongshore/tons-of-skills-marketplace. Authenticate production HubSpot integrations and survive the auth-side failures — 30-min token expiry storms, 500K daily rate-limit burnout, scope drift, token leakage in commits, multi-portal credential routing, OAuth refresh-token decay. Use when hardening token caching, rotating private app credentials, building a multi-portal credential router, or recovering from 429/403 auth cascades. Trigger with "hubspot auth", "hubspot token cache", "hubspot rate limit", "hubspot scope drift", "hubspot multi-portal"…
Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/API_REFERENCE.md` and `references/implementation-guide.md`). Compatibility notes: Designed for Claude Code
It sits in Sales & Support, covering CRM management, Rate limiting and OAuth and OpenID Connect. It works with HubSpot. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadWriteEditBash(curl:*)Bash(jq:*)Bash(openssl:*)GrepFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitcurljqFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
api.hubapi.comAlso links to:
developers.hubspot.comnpmjs.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
HUBSPOT_ACCESS_TOKENHUBSPOT_CLIENT_SECRETFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Designed for Claude Code
From compatibility in the SKILL.md frontmatter.
Hubspot Auth loads about 3.4k tokens when it runs, and up to ~6.8k if it reads all its reference files. Until then it costs about 138 tokens; SKILL.md has 805 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
**Never put tokens in source code, `.env` files committed to git, or log output.**.env.env.local.env.*.localit log --all --full-history --oneline -- .envAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 805 words, ~3,388 tokens.
.claude/skills/hubspot-auth/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Authenticate a service to HubSpot and operate the auth layer in production. This is not a setup walkthrough — it is the auth code your integration runs at 3am when an OAuth token expires mid-batch, when a portal admin removes a scope, when an agency credential router sends a request to the wrong portal, and when on-call needs to rotate a leaked private-app token without dropping in-flight requests.
The six production failures this skill prevents:
403. Retrying does not help.pat-na1-* private-app tokens are wide-scope and not auto-expiring. A single leaked commit exposes the entire portal.HUBSPOT_ACCESS_TOKEN. Requests sent to the wrong portal silently operate on the wrong data.Build in this order. Each section neutralizes one production failure mode.
Reactive refresh on 401 is wrong. It doubles latency on the failing request and creates a thundering herd when all concurrent requests notice expiry at the same millisecond. Cache the token in-process and refresh proactively at 80% of TTL, behind a single-flight gate so concurrent callers serialize on one refresh.
This pattern applies to OAuth access tokens only — private-app tokens do not expire.
type Cached = { value: string; expiresAt: number };
let cached: Cached | null = null;
let inflight: Promise<string> | null = null;
export async function getToken(): Promise<string> {
// Refresh at 80% of TTL (1800s → refresh at 1440s elapsed, i.e. 360s before expiry)
if (cached && Date.now() < cached.expiresAt - 360_000) return cached.value;
if (inflight) return inflight;
inflight = (async () => {
const res = await fetch("https://api.hubapi.com/oauth/v1/token", {
method: "POST",
headers: { "Content-Type": "application/x-www-form-urlencoded" },
body: new URLSearchParams({
grant_type: "refresh_token",
client_id: process.env.HUBSPOT_CLIENT_ID!,
client_secret: process.env.HUBSPOT_CLIENT_SECRET!,
redirect_uri: process.env.HUBSPOT_REDIRECT_URI!,
refresh_token: await loadRefreshToken(), // read from secret store
}),
});
if (!res.ok) throw new HubSpotAuthError(res.status, await res.text());
const { access_token, expires_in } = await res.json();
cached = {
value: access_token,
expiresAt: Date.now() + expires_in * 1000,
};
return access_token;
})().finally(() => { inflight = null; });
return inflight;
}
class HubSpotAuthError extends Error {
constructor(public status: number, public body: string) {
super(`HubSpot auth failed ${status}: ${body}`);
}
}HubSpot enforces 10 auth calls/10s on the token endpoint and 100 API calls/10s per private app. Naive retry on failure burns both budgets instantly.
async function withRetry<T>(
fn: () => Promise<T>,
maxAttempts = 4,
baseDelayMs = 500,
): Promise<T> {
for (let attempt = 1; attempt <= maxAttempts; attempt++) {
try {
return await fn();
} catch (err: any) {
const isRetryable =
err.status === 429 ||
(err.status >= 500 && err.status < 600);
if (!isRetryable || attempt === maxAttempts) throw err;
// Full jitter: random delay in [0, min(cap, base * 2^attempt)]
const cap = 30_000;
const expDelay = Math.min(cap, baseDelayMs * 2 ** attempt);
const jittered = Math.random() * expDelay;
// Respect Retry-After if present
const retryAfterMs = err.retryAfterSeconds
? err.retryAfterSeconds * 1000
: jittered;
await new Promise((r) => setTimeout(r, retryAfterMs));
}
}
throw new Error("unreachable");
}
// Usage
const token = await withRetry(() => getToken());When a portal admin edits scopes, your next token refresh silently returns a token with the new (reduced) scope set. Requests fail with 403 and no retry will help. Validate scopes immediately after each refresh:
const REQUIRED_SCOPES = new Set([
"crm.objects.contacts.read",
"crm.objects.contacts.write",
"crm.objects.deals.read",
]);
function validateScopes(tokenBody: any): void {
const granted = new Set((tokenBody.scope as string).split(" "));
const missing = [...REQUIRED_SCOPES].filter((s) => !granted.has(s));
if (missing.length > 0) {
throw new Error(`Scope drift detected — missing: ${missing.join(", ")}. ` +
"A portal admin must re-grant these scopes in Private Apps settings.");
}
}
// Call inside the token refresh:
const body = await res.json();
validateScopes(body);
cached = { value: body.access_token, expiresAt: Date.now() + body.expires_in * 1000 };Private-app tokens (pat-na1-*) are wide-scope and do not auto-expire. A leaked token can read and write the entire portal until manually rotated.
Never put tokens in source code, .env files committed to git, or log output.
# .gitignore — add these if not present
.env
.env.local
.env.*.local
*.pat
hubspot-credentials.json
# Verify no token is already committed
git log --all --full-history --oneline -- .env
git grep -r "pat-na1" -- '*.ts' '*.js' '*.py' '*.json'
git grep -r "HUBSPOT_ACCESS_TOKEN\s*=" -- '*.ts' '*.js'For rotation without downtime:
// Health check — cheap read to verify token is live
async function verifyToken(token: string): Promise<boolean> {
const res = await fetch("https://api.hubapi.com/crm/v3/objects/contacts?limit=1", {
headers: { Authorization: `Bearer ${token}` },
});
return res.status === 200 || res.status === 204;
}Agencies and ISVs managing multiple HubSpot portals need per-portal token caches, not a single env var. Requests sent to the wrong portal silently operate on the wrong data with no error.
// credentials.json (in secret store, NOT in git)
// { "portals": { "acme-corp": "pat-na1-...", "beta-inc": "pat-na1-..." } }
class HubSpotRouter {
private caches = new Map<string, { value: string; expiresAt: number }>();
private credentials: Record<string, string>;
constructor(credentials: Record<string, string>) {
this.credentials = credentials;
}
async getClient(portalSlug: string): Promise<{ token: string }> {
const cached = this.caches.get(portalSlug);
// Private-app tokens don't expire — still cache to avoid repeated lookups
if (cached) return { token: cached.value };
const token = this.credentials[portalSlug];
if (!token) throw new Error(`No credential for portal: ${portalSlug}`);
// Verify the token is live before caching
const ok = await verifyToken(token);
if (!ok) throw new Error(`Token for portal ${portalSlug} is invalid or revoked`);
this.caches.set(portalSlug, { value: token, expiresAt: Infinity });
return { token };
}
}
// Load credentials from secret store at startup
const creds = JSON.parse(await readSecret("hubspot/portal-credentials"));
const router = new HubSpotRouter(creds.portals);
// Usage
const { token } = await router.getClient("acme-corp");HubSpot refresh tokens expire after 525,600 minutes (1 year) of non-use. Integrations with seasonal usage patterns or paused automations will silently lose access.
// Store last-used timestamp alongside the refresh token
interface RefreshTokenRecord {
token: string;
lastUsed: number; // Unix ms
}
const REFRESH_TOKEN_WARN_DAYS = 300; // warn at 300d, expire at 365d
async function loadRefreshToken(): Promise<string> {
const record: RefreshTokenRecord = JSON.parse(
await readSecret("hubspot/refresh-token")
);
const ageDays = (Date.now() - record.lastUsed) / 86_400_000;
if (ageDays > REFRESH_TOKEN_WARN_DAYS) {
console.warn(
`HubSpot refresh token unused for ${ageDays.toFixed(0)} days — ` +
"reconnect the OAuth app before day 365 or access will be lost."
);
}
// Update last-used timestamp
await writeSecret("hubspot/refresh-token", JSON.stringify({
...record,
lastUsed: Date.now(),
}));
return record.token;
}| HTTP Status | HubSpot Error | Root Cause | Action |
|---|---|---|---|
401 UNAUTHORIZED | INVALID_AUTHENTICATION | Token expired, revoked, or malformed | Refresh or re-rotate token |
403 FORBIDDEN | MISSING_SCOPES | Scope removed from private app | Portal admin re-grants scopes |
429 TOO_MANY_REQUESTS | RATE_LIMIT | Auth or API quota exhausted | Back off with Retry-After header |
400 BAD_REQUEST | INVALID_CLIENT | Wrong client ID/secret on token request | Verify credentials in dev portal |
400 BAD_REQUEST | REFRESH_TOKEN_NOT_FOUND | Refresh token expired or revoked | User must reconnect OAuth app |
.gitignore verified for token leakage patternsimport * as hubspot from "@hubspot/api-client";
const client = new hubspot.Client({
accessToken: process.env.HUBSPOT_ACCESS_TOKEN!,
numberOfApiCallRetries: 3,
});
const contacts = await client.crm.contacts.basicApi.getPage(10);// Every outbound call goes through getToken() — cache handles the rest
async function hubspotFetch(path: string, init?: RequestInit) {
const token = await getToken();
return fetch(`https://api.hubapi.com${path}`, {
...init,
headers: { Authorization: `Bearer ${token}`, ...init?.headers },
});
}curl -s "https://api.hubapi.com/oauth/v1/access-tokens/$HUBSPOT_ACCESS_TOKEN" | jq '{hub_id, user, scopes}'© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in skills/.curated/hubspot-auth of jeremylongshore/tons-of-skills-marketplace.
Open the folder on GitHubat commit cfae287
Hubspot Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Hubspot Auth this skilljeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~3.4k | Automated safety check: Notes | MIT | |
| Hubspot Integrationaiskillstore/marketplace | 433 | 3 repos | ~5k | Automated safety check: Pass | None | |
| Google Maps Exportgmapsscraper/google-maps-agent-skills | 132 | — | ~1.2k | Automated safety check: Pass | MIT | |
| API GatewayCraftOS-dev/CraftBot | 392 | 3 repos | ~7.1k | Automated safety check: Pass | MIT | |
| Lost Deal Revival AgentOthmane-Khadri/YALC-the-GTM-operating-system | 318 | — | ~3k | Automated safety check: Pass | MIT | |
| HubspotOpenClaudia/openclaudia-skills | 713 | — | ~1.8k | Automated safety check: Notes | MIT |
aiskillstore/marketplace
Expert patterns for HubSpot CRM integration including OAuth authentication, CRM objects, associations, batch operations, webhooks, and custom objects.
gmapsscraper/google-maps-agent-skills
Export Google Maps business data to CSV, JSON, or CRM format (HubSpot, Pipedrive, Salesforce).
CraftOS-dev/CraftBot
Connect to 100+ APIs (Google Workspace, Microsoft 365, Notion, Slack, Airtable, HubSpot, etc.) with managed OAuth.
Othmane-Khadri/YALC-the-GTM-operating-system
Drafts revival messages for closed-lost deals when a public company signal contradicts the original objection.
OpenClaudia/openclaudia-skills
Manage HubSpot CRM contacts, companies, deals, and CMS content via API.
aai-labs/agent-barn
Use aai-cli to inspect HubSpot CRM records, files, events, conversations, visitor identification, and custom channels.
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.
jeremylongshore/tons-of-skills-marketplace
Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.
jeremylongshore/tons-of-skills-marketplace
Execute proactive auto-loading: automatically detects and loads agents.md files.
jeremylongshore/tons-of-skills-marketplace
Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.
jeremylongshore/tons-of-skills-marketplace
Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.
Works with
Categories
Authenticate production HubSpot integrations and survive the auth-side failures — 30-min token expiry storms, 500K daily rate-limit burnout, scope drift, token leakage in commits, multi-portal…. Hubspot Auth is an agent skill from jeremylongshore/tons-of-skills-marketplace. Authenticate production HubSpot integrations and survive the auth-side failures — 30-min token expiry storms, 500K daily rate-limit burnout, scope drift, token leakage in commits, multi-portal credential routing, OAuth refresh-token decay.
Hubspot Auth fits situations like: hardening token caching; rotating private app credentials; building a multi-portal credential router; recovering from 429/403 auth cascades.
Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill hubspot-auth -a claude-code`. Or copy the skill folder (skills/.curated/hubspot-auth in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/hubspot-auth in your project. Claude Code loads it when a task matches its description.
Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill hubspot-auth -a codex`. Or copy the skill folder (skills/.curated/hubspot-auth in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/hubspot-auth in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill hubspot-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hubspot-auth, .gemini/skills/hubspot-auth, .github/skills/hubspot-auth and .opencode/skills/hubspot-auth in your project.
Going by SKILL.md and its folder, Hubspot Auth needs the command-line tools its instructions call (git, curl and jq) and credentials named HUBSPOT_ACCESS_TOKEN and HUBSPOT_CLIENT_SECRET. Our summary lists: Python 3; Node.js; A credential in HUBSPOT_ACCESS_TOKEN; A credential in HUBSPOT_CLIENT_SECRET. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash(curl:*), Bash(jq:*), Bash(openssl:*), Grep. Compatibility (from SKILL.md): Designed for Claude Code.
SKILL.md names 3 domains. In commands or code: api.hubapi.com; the agent is likely to contact it when it follows the instructions. As links in the text: developers.hubspot.com and npmjs.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Hubspot Auth is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Hubspot Auth: Hubspot Integration (aiskillstore/marketplace, 433 stars), Google Maps Export (gmapsscraper/google-maps-agent-skills, 132 stars), API Gateway (CraftOS-dev/CraftBot, 392 stars) and Lost Deal Revival Agent (Othmane-Khadri/YALC-the-GTM-operating-system, 318 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.
Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.