Evidence
observed · not disputed
Coverage
complete · 16/16 graded0/5 barrier checks verified
Freshness
fresh
Last tested
Revision
sha256:986780b22e79…

Agent report card

Can an agent use HubSpot CRM API through API integration lifecycle?

Grade B+: Safe failure handling is documented only partially.

HubSpot / active

Agent ReadinessB+Limited

Five-stage assessment

Where agent autonomy holds and where it breaks

Five states · each from its own evidence · lifecycle order, not a journey
  1. EvaluateReady
  2. Sign upReady
  3. PayReady
  4. ProvisionReady
  5. OperateLimited
  1. 01

    Evaluate

    Ready

    The exact service and stable evaluation or access entrypoints are publicly discoverable.

    Applicable terms are stable, readable, retrievable, and materially complete.

    Eligibility conditions and required inputs are explicit and decidable.

    Price or no-charge status, variables, currency, and material conditions are explicit.

    Evidence and actions6 signals

    Can an agent decide every material eligibility condition before commitment?

    supported: fresh

    Eligibility conditions and required inputs are explicit and decidable.

    HubSpot's Developer Terms explicitly define eligibility and authority requirements for using Developer Tools, including authority to accept terms on behalf of an entity, legal age capacity, compliance with platform policies, and not being barred by applicable laws.

    eligibility_decidability: Ready: tested 20 Aug

    Method public-http-semantic-assessment 2026-08-20

    Can an agent estimate cost or confirm no-charge status before commitment?

    supported: fresh

    Price or no-charge status, variables, currency, and material conditions are explicit.

    HubSpot explicitly declares that its CRM product is 100% free with no expiration date and no credit card required.

    pricing_decidability: Ready: tested 20 Aug

    Method public-http-semantic-assessment 2026-08-20

    Can an agent find the exact service and its stable entrypoints?

    supported: fresh

    The exact service and stable evaluation or access entrypoints are publicly discoverable.

    HubSpot provides stable public discovery for its date-versioned 2026-03 API endpoints using the root URL https://api.hubapi.com/ and structured resource paths such as GET /crm/objects/2026-03/contacts.

    service_discovery: Ready: tested 20 Aug

    Method public-http-semantic-assessment 2026-08-20

    Are verified structured discovery artifacts available?

    missing: unknown

    Current admissible evidence does not resolve this finding.

    structured_evaluation_discovery: Unknown

    Can an agent retrieve and understand the applicable commitment terms?

    supported: fresh

    Applicable terms are stable, readable, retrievable, and materially complete.

    HubSpot provides retrievable, readable, and publicly accessible Customer Terms of Service and Developer Terms outlining the governing agreements for customer and developer service use.

    terms_access: Ready: tested 20 Aug

    Method public-http-semantic-assessment 2026-08-20

    Does the vendor deliberately describe access for web agents?

    missing: unknown

    Current admissible evidence does not resolve this finding.

    verified_web_agent_access: Unknown

  2. 02

    Sign up

    Ready

    A stable canonical route begins the required access bootstrap.

    Scoped revocable credentials or delegated authorization have explicit consent and resumption boundaries.

    Evidence and actions5 signals

    Can an agent operate the access controls and safe handoffs deterministically?

    supported: fresh

    Current admissible evidence does not resolve this finding.

    The retained page fragment for the CRM signup endpoint displays 'Get started with HubSpot' without providing detectable access controls, form fields, validation logic, or redirect handoffs.

    access_control_operability: Unknown: tested 20 Aug

    Method bounded-headless-semantic-assessment 2026-08-20

    Is there a stable route to begin obtaining service access?

    supported: fresh

    A stable canonical route begins the required access bootstrap.

    A stable canonical route to begin obtaining service access exists at https://app.hubspot.com/signup-hubspot/crm, presenting the 'Get started with HubSpot' entrypoint.

    access_entrypoint_stability: Ready: tested 20 Aug

    Method bounded-headless-semantic-assessment 2026-08-20

    Can an agent obtain access without an unsupported CAPTCHA boundary?

    supported: fresh

    Current admissible evidence does not resolve this finding.

    The captured evidence across both evaluated surfaces shows 'Get started with HubSpot' but contains no explicit text or rendered CAPTCHA challenge confirming its presence or absence.

    captcha_compatible_access: Unknown: tested 20 Aug

    Method bounded-headless-semantic-assessment 2026-08-20

    Can an agent obtain scoped, revocable authority for this service?

    supported: fresh

    Scoped revocable credentials or delegated authorization have explicit consent and resumption boundaries.

    HubSpot explicitly documents delegated OAuth authentication via authorization URLs, redirect_uri callback, and an API exchange at /oauth/v3/token to obtain access_token and refresh_token scoped to requested permissions.

    delegated_identity_access: Ready: tested 20 Aug

    Method public-http-semantic-assessment 2026-08-20

    Can required phone verification be completed through a supported boundary?

    supported: fresh

    Current admissible evidence does not resolve this finding.

    The retained evidence for the CRM signup resource does not mention phone verification or SMS requirements.

    phone_verification_compatible: Unknown: tested 20 Aug

    Method bounded-headless-semantic-assessment 2026-08-20

  3. 03

    Pay

    Ready

    Charge or no-charge status, currency, recurrence, and material conditions are disclosed.

    A documented direct purchase path reaches paid access without a vendor decision point.

    Evidence and actions4 signals

    Can an agent construct checkout, hand off approval safely, and resume?

    supported: fresh

    Current admissible evidence does not resolve this finding.

    While documentation references clicking Buy now to begin checkout and managing subscriptions in account settings, the retained evidence does not document deterministic checkout construction, approval handoff, and resumption.

    checkout_operability: Unknown: tested 20 Aug

    Method public-http-semantic-assessment 2026-08-20

    Is the exact commercial commitment disclosed before authorization?

    supported: fresh

    Charge or no-charge status, currency, recurrence, and material conditions are disclosed.

    The assessed free CRM is explicitly 100% free, requires no credit card, and has no expiration date.

    commitment_disclosure: Ready: tested 20 Aug

    Method public-http-semantic-assessment 2026-08-20

    Can payment be authorized within scoped agent or explicit human authority?

    supported: fresh

    Current admissible evidence does not resolve this finding.

    The evidence requires Billing admin permissions to make billing changes and mentions credit card charges during subscription terms, but does not document a delegated payment authorization rail or explicit human-confirmed authorization with receipts.

    payment_authorization: Unknown: tested 20 Aug

    Method public-http-semantic-assessment 2026-08-20

    Is a direct self-service path to paid access documented?

    supported: fresh

    A documented direct purchase path reaches paid access without a vendor decision point.

    Documentation explicitly states that users can visit Pricing & Features in their account, click Buy now to begin checkout, and complete a purchase to upgrade their subscription directly.

    self_service_purchase: Ready: tested 20 Aug

    Method public-http-semantic-assessment 2026-08-20

  4. 04

    Provision

    Ready

    Provisioning is machine-triggerable or follows deterministically from an allowed handoff.

    Credentials, grants, or configuration are delivered through a documented agent-usable flow.

    A synchronous success response returns a usable created resource or access material; otherwise asynchronous work exposes progress, terminal state, reconciliation, and a documented bound.

    Evidence and actions3 signals

    Can usable access material be delivered securely to an authorized agent?

    supported: fresh

    Credentials, grants, or configuration are delivered through a documented agent-usable flow.

    HubSpot OAuth tokens are delivered through a documented programmatic exchange endpoint (`/oauth/v3/token`), which returns an `access_token` and `refresh_token` after exchanging the authorization code.

    access_material_delivery: Ready: tested 20 Aug

    Method public-http-semantic-assessment 2026-08-20

    Can an agent determine successful provisioning completion and reconcile asynchronous failure?

    supported: fresh

    A synchronous success response returns a usable created resource or access material; otherwise asynchronous work exposes progress, terminal state, reconciliation, and a documented bound.

    A synchronous POST request to create a CRM object directly returns HTTP status code 201 with the created public object, including its unique ID, timestamps (createdAt, updatedAt), and property key-value pairs.

    provisioning_completion: Ready: tested 20 Aug

    Method public-http-semantic-assessment 2026-08-20

    Can provisioning be initiated within supported agent authority?

    supported: fresh

    Provisioning is machine-triggerable or follows deterministically from an allowed handoff.

    Provisioning of CRM objects is triggerable programmatically via a direct POST request to /crm/v3/objects/{objectType}. Additionally, OAuth app installation follows deterministically from user access authorization.

    provisioning_operability: Ready: tested 20 Aug

    Method public-http-semantic-assessment 2026-08-20

  5. 05

    Operate

    Limited

    Safe failure handling is documented only partially.

    Only part of the credential lifecycle is agent-operable.

    Every essential target has a stable documented agent-usable interface alternative.

    Request-time authentication is documented and usable under scoped agent authority.

    Essential operations have stable readable request, response, and effect semantics.

    Evidence and actions6 signals

    Is an agent-native protocol interface verified against the essential targets?

    missing: unknown

    Current admissible evidence does not resolve this finding.

    agent_protocol_interface: Unknown

    Can an agent manage credential expiry, rotation, revocation, compromise, and recovery?

    supported: fresh

    Only part of the credential lifecycle is agent-operable.

    HubSpot documents that access tokens can be refreshed using a refresh token when expired, and private app access tokens can be rotated (either immediately or scheduled for 7 days) or revoked by deleting the app, but recovery or full agent-executable lifecycle without human intervention is not established.

    credential_lifecycle: Limited: tested 20 Aug

    Method public-http-semantic-assessment 2026-08-20

    Can an agent handle applicable failure modes safely?

    supported: fresh

    Safe failure handling is documented only partially.

    HubSpot documents rate limit errors (429), timeouts (502/504), service temporary errors (503), SSL issues (525/526), and retry guidance including Retry-After headers, but full idempotency, cancellation, and reconciliation semantics are not completely established.

    failure_contract: Limited: tested 20 Aug

    Method public-http-semantic-assessment 2026-08-20

    Can an agent authenticate service operations with scoped authority?

    supported: fresh

    Request-time authentication is documented and usable under scoped agent authority.

    HubSpot documents request-time authentication using Bearer access tokens generated via OAuth or private apps with scope-restricted permissions.

    operation_authentication: Ready: tested 20 Aug

    Method public-http-semantic-assessment 2026-08-20

    Are essential operation inputs, outputs, and effects stable and decidable?

    supported: fresh

    Essential operations have stable readable request, response, and effect semantics.

    HubSpot documents stable operational contracts, endpoints, request schemas, parameters, and response structures across error handling, usage guidelines, date-versioned API reference overview, and CRM object creation operations.

    operation_contract: Ready: tested 20 Aug

    • crm-api

    Method public-http-semantic-assessment 2026-08-20

    Can an agent perform every essential assessment target through a usable interface?

    supported: fresh

    Every essential target has a stable documented agent-usable interface alternative.

    HubSpot provides machine-operable HTTP API endpoints across error handling, platform usage limits, date-versioned API overview, and CRM object creation operations.

    target_interface_access: Ready: tested 20 Aug

    • crm-api

    Method public-http-semantic-assessment 2026-08-20

    What would improve this stage

    • Document applicable structured errors, retry, cancellation, and reconciliation semantics.
    • Provide scoped expiry, rotation, revocation, compromise, and recovery operations.

What works

  • Evaluate: The exact service and stable evaluation or access entrypoints are publicly discoverable.
  • Sign up: A stable canonical route begins the required access bootstrap.
  • Pay: Charge or no-charge status, currency, recurrence, and material conditions are disclosed.
  • Provision: Provisioning is machine-triggerable or follows deterministically from an allowed handoff.

What blocks agents

  • Operate: Safe failure handling is documented only partially.

Startup offers

HubSpot on the startup-offers board

catalog record →

Improve the report

Correct it, rerun it, or improve the funnel.

Profile
arp_01kzf0m4xa1m8yr7cf5q2b9vn6
Projection
sha256:84d418ca7f69282903be7bc9169615e2e84d9c809e83c5626f3d702ada104859
Policy
service-use-2026-08-20-public-evidence-r9 · sha256:57bf95fd6d0fe6fe9173a68b60e8d8dc2179b357c88ff4349675a72d0e1d4139