{
  "api_contract": "sourcey.catalog-api/v1",
  "release_id": "sha256:f94358e3c57b6e575ca58c8031b9b7552cbfdb411f937b8ecdc3b042c4980a77",
  "artifact_sha256": "sha256:7472396c2449279d33e7a0fb2426f02a89991501262d1db8c04c81d57bdf9021",
  "data": {
    "revision_contract": "sourcey.agent-readiness-revision/v1alpha1",
    "agent_readiness_profile_id": "arp_01kzf0m4xa1m8yr7cf5q2b9vn6",
    "entity_id": "ent_01kyh8fpe3new9gxd18qs3bskh",
    "scope": {
      "product": {
        "key": "hubspot-crm-api",
        "name": "HubSpot CRM API"
      },
      "funnel": {
        "key": "api-integration-lifecycle",
        "name": "API integration lifecycle"
      }
    },
    "catalog_binding": {
      "base_release_id": "sha256:cad9f851ab1bb553246eb2fb2b2803a4741814a33ccf28997014247439b9013d",
      "entity_revision_digest": "sha256:d834f446f341ff50dd565416a3b8489b405fe189c597bcfa66ca67249314dd03"
    },
    "declaration_revision_digest": "sha256:2538ff7b69270e0b651ecd3add7601bd2e6619766e25ce9b137579cdd014d881",
    "declaration": {
      "declaration_id": "declaration_hubspot_crm_api_integration_lifecycle",
      "provenance": {
        "repository": "sourcey/agent-ready-services",
        "commit": "62b512f0c49352e55a399ba53866a5effa431d71",
        "path": "vendors/hu/hubspot.yaml",
        "git_blob_oid": "b54a3f8811835ed618569a25989a0f26802e868e",
        "blob_digest": "sha256:7e1172cc7a94c2b0c4f1e9431fcdd97d3d75d9b4ffdb7f87bc8b7aeb82edda58"
      },
      "status": "community_declared"
    },
    "lifecycle": "active",
    "effective_from": "2026-08-20T14:33:24.000Z",
    "signals": [
      {
        "stage": "evaluate",
        "signal_code": "eligibility_decidability",
        "selector_group_id": "eligibility_decidability-primary",
        "value": "yes",
        "observed_at": "2026-08-20T15:56:59.567Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "readiness-237735cc5ba6ecc44afc3287e10b76ffb4c73481fb6a5a1f2ca6e1fa98a8ee41"
          }
        ],
        "assessment_method": {
          "name": "public-http-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:b3fdfb627d1549220451735876a1771d80388d549f510f67b4a2e85af8aff2bb",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:7db22c6e2df73a618ca8347b6565646dec559b2650829d79218411fbca60a8e8",
              "sha256:99fd1b046adf6343e784896f072f605bd857206f24eeb79c3ea4f27024fe31bc",
              "sha256:d8730816192d92830addb228ffaa41f60d6e9855b7732db2b1ecb05e3651159d",
              "sha256:de08d98f15dfc37d351f412524ea3d8647480d12620de9de7114072ce36719bd"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "readiness-237735cc5ba6ecc44afc3287e10b76ffb4c73481fb6a5a1f2ca6e1fa98a8ee41"
            },
            "locators": [
              {
                "artifact_digest": "sha256:de08d98f15dfc37d351f412524ea3d8647480d12620de9de7114072ce36719bd",
                "start_byte": 20548,
                "end_byte": 21356,
                "value_digest": "sha256:6053b30b7f5644557b47aedaf40450c9c1452978e8052c2a3e2371204456598b"
              }
            ]
          }
        ],
        "note": "HubSpot's Developer Terms explicitly define eligibility and authority requirements for using Developer Tools, including authority to accept terms on behalf of an entity, legal age capacity, compliance with platform policies, and not being barred by applicable laws."
      },
      {
        "stage": "evaluate",
        "signal_code": "pricing_decidability",
        "selector_group_id": "pricing_decidability-primary",
        "value": "yes",
        "observed_at": "2026-08-20T15:56:28.788Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "crm-commitment"
          },
          {
            "node_kind": "resource",
            "node_id": "pricing"
          }
        ],
        "assessment_method": {
          "name": "public-http-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:d07fb8ac66f957cb82b9334cba97a140e5edf5d702d876ee4fa9689367e2f301",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:145d630ad16738193266f7660738e713a6dfeea2177063105cc9c9125699fd39",
              "sha256:499ee0b63345ad1a6599d6dc00901c32d0e53203e28d02f1df2b5844f7021029",
              "sha256:4b08fa552bc4472c41dd38ad89da2b690121b3a7f51f20369f40917f68aae3f4",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "crm-commitment"
            },
            "locators": [
              {
                "artifact_digest": "sha256:4b08fa552bc4472c41dd38ad89da2b690121b3a7f51f20369f40917f68aae3f4",
                "start_byte": 28361,
                "end_byte": 29163,
                "value_digest": "sha256:43da9dbff6076010b8a8e63aa4a681d0b0f8108edb06cb723a3f72133a9eb76e"
              }
            ]
          },
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:fc69a1b7dfa8c40de80da446f083ec2a9a42347088bd23929e8978e766f4e0a9",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:1ff6b7762a8bae9a99ee9a77e6a2dc3624a59188323b019c40716c4664f20bdf",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:989b02723791648ebe3ae7369e6266fdb9bee0c10470a4bf834333215ebb21d2",
              "sha256:bf3c0d695fd07c6ca799a0412971ebe9d1e7aa55554fd5134d6a7d267954b138"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "pricing"
            },
            "locators": [
              {
                "artifact_digest": "sha256:1ff6b7762a8bae9a99ee9a77e6a2dc3624a59188323b019c40716c4664f20bdf",
                "start_byte": 0,
                "end_byte": 796,
                "value_digest": "sha256:0347e27d309bc7222defc72b4b18f0d66d7993b921b8f8275dae3cc4f6726e70"
              }
            ]
          }
        ],
        "note": "HubSpot explicitly declares that its CRM product is 100% free with no expiration date and no credit card required."
      },
      {
        "stage": "evaluate",
        "signal_code": "service_discovery",
        "selector_group_id": "service_discovery-primary",
        "value": "yes",
        "observed_at": "2026-08-20T15:56:33.602Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "api-overview"
          }
        ],
        "assessment_method": {
          "name": "public-http-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:911c3b49ca3920d9bb0bd5481f58d3e3a1b7df092e574f4f25eb07438815660e",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:0bab3a8f1d92bb78b3f478d5ad47cebd2b5c6d0b2143ec9ed77d66413cf97763",
              "sha256:3af3b1d1eee7b5a2da7be1a31f0a42364e780bf145a9907d9e41401a271e36e0",
              "sha256:443ea5e4dae9ce65309ae94ab389a756fa97367ab67a21eaf94c4da588483be9",
              "sha256:62b090664baddee217f0ee6cb396d836067021a2d06fda285d27439dc5ef620b"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "api-overview"
            },
            "locators": [
              {
                "artifact_digest": "sha256:0bab3a8f1d92bb78b3f478d5ad47cebd2b5c6d0b2143ec9ed77d66413cf97763",
                "start_byte": 5058,
                "end_byte": 5859,
                "value_digest": "sha256:865ab74db06c08d141be658a7b17838f9fef55f94fd5dac4eccc7ebfac90ba6c"
              }
            ]
          }
        ],
        "note": "HubSpot provides stable public discovery for its date-versioned 2026-03 API endpoints using the root URL https://api.hubapi.com/ and structured resource paths such as GET /crm/objects/2026-03/contacts."
      },
      {
        "stage": "evaluate",
        "signal_code": "terms_access",
        "selector_group_id": "terms_access-primary",
        "value": "yes",
        "observed_at": "2026-08-20T15:56:46.600Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "readiness-fedf565215bcde83431a45666a9a0edc7be9032ca5dbd43956ab753094c89a09"
          },
          {
            "node_kind": "resource",
            "node_id": "service-terms"
          }
        ],
        "assessment_method": {
          "name": "public-http-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:e7b7c0ed84f43f4abba7b11a38fb0b85a1705114b298b037e9fd3892189735c3",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:119f8508e6e418f4880bb646eafce7b18a802da8be724d949fb43033f744aa06",
              "sha256:be57a24b0bbf23344585061801b78bbfdc215deea6a5262e34a48b9a991aacc8",
              "sha256:d704813e50f7d73032bf4bdba060a36ed280379a56221b7afb65ccb818ba6751",
              "sha256:f3285072323833a7e0afd7c8204668b52a34ae03beb63ba612700ed127b9cf4c"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "service-terms"
            },
            "locators": [
              {
                "artifact_digest": "sha256:be57a24b0bbf23344585061801b78bbfdc215deea6a5262e34a48b9a991aacc8",
                "start_byte": 19605,
                "end_byte": 20403,
                "value_digest": "sha256:44df1a28ddf6333d3e07e29bc90a89eb9e9128352d2625fb13bcea2686eb0d05"
              }
            ]
          },
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:39a065f846b76d45e7d2dd9f0bf5ec530e25c44f7e06252eb6c3c9ab2ad425c9",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:0fc0a09217c6e5d8485de0bf78812a83ab7b9982425c905c420032fe5169c809",
              "sha256:2a2a4386207db28a785de60672f6150ba8842156766b8a89a73dafcf32dfe718",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:5692bfc90aaf3305976759a5c72724d07a71ffa6b65e91eb511c8138ab41f828"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "readiness-fedf565215bcde83431a45666a9a0edc7be9032ca5dbd43956ab753094c89a09"
            },
            "locators": [
              {
                "artifact_digest": "sha256:2a2a4386207db28a785de60672f6150ba8842156766b8a89a73dafcf32dfe718",
                "start_byte": 0,
                "end_byte": 515,
                "value_digest": "sha256:e66ea6a310519485d3411f67aae70bc09079147c9a4fece6da653f7db800083d"
              }
            ]
          }
        ],
        "note": "HubSpot provides retrievable, readable, and publicly accessible Customer Terms of Service and Developer Terms outlining the governing agreements for customer and developer service use."
      },
      {
        "stage": "sign_up",
        "signal_code": "access_control_operability",
        "selector_group_id": "access_control_operability-primary",
        "value": "unknown",
        "observed_at": "2026-08-20T15:56:36.686Z",
        "tested_surfaces": [
          {
            "node_kind": "endpoint",
            "node_id": "registration"
          }
        ],
        "assessment_method": {
          "name": "bounded-headless-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
        },
        "determination_bases": [],
        "note": "The retained page fragment for the CRM signup endpoint displays 'Get started with HubSpot' without providing detectable access controls, form fields, validation logic, or redirect handoffs."
      },
      {
        "stage": "sign_up",
        "signal_code": "access_entrypoint_stability",
        "selector_group_id": "access_entrypoint_stability-primary",
        "value": "yes",
        "observed_at": "2026-08-20T15:56:36.686Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "crm-signup"
          }
        ],
        "assessment_method": {
          "name": "bounded-headless-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
        },
        "determination_bases": [
          {
            "kind": "direct_observation",
            "captures": [
              {
                "retained_capture_digest": "sha256:69797ac3540bb84bb53ba6296bc79af51ef0a56053f2c986bd381c2084c839ab",
                "capture_rung": "headless"
              }
            ],
            "artifact_digests": [
              "sha256:3878570f4a62a0d65f57cf1754e0269e56ec797f4e36e26b44c172eb6e800401",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:c4c643d6f75b2ac2f863d0385d4007236bd9fbebb500cd58a97d305d5a002042",
              "sha256:cabf4205701d6716c681f3bde84da998667c8f6f2bb9d41ac3a6fa4a37a33810",
              "sha256:ee2c2181ae03a57bd827bb6023c934e39afcfdc542f40fafb9df519a2443c0da",
              "sha256:f4948ca55dd2f4c9150a94dec70f218ba74a1f5949c5e67dd92fe4856916dd29"
            ],
            "locators": [
              {
                "artifact_digest": "sha256:f4948ca55dd2f4c9150a94dec70f218ba74a1f5949c5e67dd92fe4856916dd29",
                "start_byte": 303,
                "end_byte": 337,
                "value_digest": "sha256:a43aea4e70ffbd2578366bd4c5e24ac6c4529d30065d12322d84d1f932cbefd6"
              }
            ]
          }
        ],
        "note": "A stable canonical route to begin obtaining service access exists at https://app.hubspot.com/signup-hubspot/crm, presenting the 'Get started with HubSpot' entrypoint."
      },
      {
        "stage": "sign_up",
        "signal_code": "captcha_compatible_access",
        "selector_group_id": "captcha_compatible_access-primary",
        "value": "unknown",
        "observed_at": "2026-08-20T15:56:36.686Z",
        "tested_surfaces": [
          {
            "node_kind": "endpoint",
            "node_id": "registration"
          },
          {
            "node_kind": "resource",
            "node_id": "crm-signup"
          }
        ],
        "assessment_method": {
          "name": "bounded-headless-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
        },
        "determination_bases": [],
        "note": "The captured evidence across both evaluated surfaces shows 'Get started with HubSpot' but contains no explicit text or rendered CAPTCHA challenge confirming its presence or absence."
      },
      {
        "stage": "sign_up",
        "signal_code": "delegated_identity_access",
        "selector_group_id": "delegated_identity_access-primary",
        "value": "yes",
        "observed_at": "2026-08-20T15:56:20.089Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "oauth"
          },
          {
            "node_kind": "resource",
            "node_id": "readiness-ae84fdbaa51b9b88febbd2301b4157e03f052892fed3e42d69d878696fe3944c"
          }
        ],
        "assessment_method": {
          "name": "public-http-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:28bb59668fc92f487c4e98f0d73302afb969b8cd9d4f6b0071b02820fac3b41c",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:30fe6bd22b235ea6806168eee9baf17257db336128b901cacbb402c315212fed",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:5a7ec41132e54a4541dab0f3897a1362e623fd428294b9f56312b7160f4e8690",
              "sha256:8c010825c11303feeffc271614b00d9ca73434a442fdf4f47eb2b342285e65b4"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "oauth"
            },
            "locators": [
              {
                "artifact_digest": "sha256:5a7ec41132e54a4541dab0f3897a1362e623fd428294b9f56312b7160f4e8690",
                "start_byte": 10252,
                "end_byte": 11044,
                "value_digest": "sha256:c2cf9661a9ebeb4f5ee59a9b0b35fce1f0636af723d6c49bbdf8308804f20048"
              },
              {
                "artifact_digest": "sha256:5a7ec41132e54a4541dab0f3897a1362e623fd428294b9f56312b7160f4e8690",
                "start_byte": 11045,
                "end_byte": 11836,
                "value_digest": "sha256:8d339c6a623686702506daa90ef3921fc5dc016efb33b357924e275c2d5aef09"
              }
            ]
          }
        ],
        "note": "HubSpot explicitly documents delegated OAuth authentication via authorization URLs, redirect_uri callback, and an API exchange at /oauth/v3/token to obtain access_token and refresh_token scoped to requested permissions."
      },
      {
        "stage": "sign_up",
        "signal_code": "phone_verification_compatible",
        "selector_group_id": "phone_verification_compatible-primary",
        "value": "unknown",
        "observed_at": "2026-08-20T15:56:36.686Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "crm-signup"
          }
        ],
        "assessment_method": {
          "name": "bounded-headless-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
        },
        "determination_bases": [],
        "note": "The retained evidence for the CRM signup resource does not mention phone verification or SMS requirements."
      },
      {
        "stage": "pay",
        "signal_code": "checkout_operability",
        "selector_group_id": "checkout_operability-primary",
        "value": "unknown",
        "observed_at": "2026-08-20T15:56:10.312Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "billing-checkout"
          },
          {
            "node_kind": "resource",
            "node_id": "subscription-upgrade"
          }
        ],
        "assessment_method": {
          "name": "public-http-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
        },
        "determination_bases": [],
        "note": "While documentation references clicking Buy now to begin checkout and managing subscriptions in account settings, the retained evidence does not document deterministic checkout construction, approval handoff, and resumption."
      },
      {
        "stage": "pay",
        "signal_code": "commitment_disclosure",
        "selector_group_id": "commitment_disclosure-primary",
        "value": "yes",
        "observed_at": "2026-08-20T15:56:28.788Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "crm-commitment"
          },
          {
            "node_kind": "resource",
            "node_id": "pricing"
          }
        ],
        "assessment_method": {
          "name": "public-http-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:d07fb8ac66f957cb82b9334cba97a140e5edf5d702d876ee4fa9689367e2f301",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:145d630ad16738193266f7660738e713a6dfeea2177063105cc9c9125699fd39",
              "sha256:499ee0b63345ad1a6599d6dc00901c32d0e53203e28d02f1df2b5844f7021029",
              "sha256:4b08fa552bc4472c41dd38ad89da2b690121b3a7f51f20369f40917f68aae3f4",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "crm-commitment"
            },
            "locators": [
              {
                "artifact_digest": "sha256:4b08fa552bc4472c41dd38ad89da2b690121b3a7f51f20369f40917f68aae3f4",
                "start_byte": 28361,
                "end_byte": 29163,
                "value_digest": "sha256:43da9dbff6076010b8a8e63aa4a681d0b0f8108edb06cb723a3f72133a9eb76e"
              }
            ]
          },
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:fc69a1b7dfa8c40de80da446f083ec2a9a42347088bd23929e8978e766f4e0a9",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:1ff6b7762a8bae9a99ee9a77e6a2dc3624a59188323b019c40716c4664f20bdf",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:6394bd7f5d8caebca0abb55bbadcdc67f42a2bea6a38c44f2cca79ec75c1f517",
              "sha256:989b02723791648ebe3ae7369e6266fdb9bee0c10470a4bf834333215ebb21d2"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "pricing"
            },
            "locators": [
              {
                "artifact_digest": "sha256:1ff6b7762a8bae9a99ee9a77e6a2dc3624a59188323b019c40716c4664f20bdf",
                "start_byte": 1058,
                "end_byte": 1088,
                "value_digest": "sha256:d6d18fc6ea297008f5be102ae6097459575b159d8b29bdea0f122b73e188026d"
              }
            ]
          }
        ],
        "note": "The assessed free CRM is explicitly 100% free, requires no credit card, and has no expiration date."
      },
      {
        "stage": "pay",
        "signal_code": "payment_authorization",
        "selector_group_id": "payment_authorization-primary",
        "value": "unknown",
        "observed_at": "2026-08-20T15:56:10.312Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "billing-checkout"
          },
          {
            "node_kind": "resource",
            "node_id": "subscription-upgrade"
          }
        ],
        "assessment_method": {
          "name": "public-http-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
        },
        "determination_bases": [],
        "note": "The evidence requires Billing admin permissions to make billing changes and mentions credit card charges during subscription terms, but does not document a delegated payment authorization rail or explicit human-confirmed authorization with receipts."
      },
      {
        "stage": "pay",
        "signal_code": "self_service_purchase",
        "selector_group_id": "self_service_purchase-primary",
        "value": "yes",
        "observed_at": "2026-08-20T15:56:10.312Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "billing-checkout"
          },
          {
            "node_kind": "resource",
            "node_id": "subscription-upgrade"
          }
        ],
        "assessment_method": {
          "name": "public-http-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:c3a6e6d0223d1ac9826569e405149d9654093fa07e62000f7af3d27f364db931",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:179b8d0083ce35a8d7fcc56d714a81d7b795a7fa584d941d12c74ff3ce0b48a2",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:661ff4e83b9a796b322b4741bd1edaae3b6826a5443dc43d68620efb29d93db0",
              "sha256:b495bef7ea5ee94139f7ec76362585f7f2657d19611fcf34491fb7602917563b"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "subscription-upgrade"
            },
            "locators": [
              {
                "artifact_digest": "sha256:179b8d0083ce35a8d7fcc56d714a81d7b795a7fa584d941d12c74ff3ce0b48a2",
                "start_byte": 7580,
                "end_byte": 8372,
                "value_digest": "sha256:e9412b74d985aae8bd9ce0b5f0d7c2fae8825e041e207e545d5c3db2279cb237"
              },
              {
                "artifact_digest": "sha256:179b8d0083ce35a8d7fcc56d714a81d7b795a7fa584d941d12c74ff3ce0b48a2",
                "start_byte": 8373,
                "end_byte": 9163,
                "value_digest": "sha256:f0fb122626ecad0dd12bdd314999c268ded69c1217dfc61307c9829639af4ffa"
              }
            ]
          }
        ],
        "note": "Documentation explicitly states that users can visit Pricing & Features in their account, click Buy now to begin checkout, and complete a purchase to upgrade their subscription directly."
      },
      {
        "stage": "provision",
        "signal_code": "access_material_delivery",
        "selector_group_id": "access_material_delivery-primary",
        "value": "yes",
        "observed_at": "2026-08-20T15:56:21.795Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "oauth"
          },
          {
            "node_kind": "resource",
            "node_id": "readiness-ae84fdbaa51b9b88febbd2301b4157e03f052892fed3e42d69d878696fe3944c"
          }
        ],
        "assessment_method": {
          "name": "public-http-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:28bb59668fc92f487c4e98f0d73302afb969b8cd9d4f6b0071b02820fac3b41c",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:5a7ec41132e54a4541dab0f3897a1362e623fd428294b9f56312b7160f4e8690",
              "sha256:6ed666e282dcffb1e568f09ada5c2e91e5bdfea05cd8b4a9cd2d33c0c57c77ca",
              "sha256:8c010825c11303feeffc271614b00d9ca73434a442fdf4f47eb2b342285e65b4"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "oauth"
            },
            "locators": [
              {
                "artifact_digest": "sha256:5a7ec41132e54a4541dab0f3897a1362e623fd428294b9f56312b7160f4e8690",
                "start_byte": 9452,
                "end_byte": 10251,
                "value_digest": "sha256:c14641ad7b925d7a59c570c7345ef8561353d22a1876a00ee5aa8996c095014d"
              },
              {
                "artifact_digest": "sha256:5a7ec41132e54a4541dab0f3897a1362e623fd428294b9f56312b7160f4e8690",
                "start_byte": 10252,
                "end_byte": 11044,
                "value_digest": "sha256:c2cf9661a9ebeb4f5ee59a9b0b35fce1f0636af723d6c49bbdf8308804f20048"
              }
            ]
          }
        ],
        "note": "HubSpot OAuth tokens are delivered through a documented programmatic exchange endpoint (`/oauth/v3/token`), which returns an `access_token` and `refresh_token` after exchanging the authorization code."
      },
      {
        "stage": "provision",
        "signal_code": "provisioning_completion",
        "selector_group_id": "provisioning_completion-primary",
        "value": "yes",
        "observed_at": "2026-08-20T15:57:53.221Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "crm-operations"
          }
        ],
        "assessment_method": {
          "name": "public-http-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
        },
        "determination_bases": [
          {
            "kind": "direct_observation",
            "captures": [
              {
                "retained_capture_digest": "sha256:7c809aa42fd15dc3cada7b52c48957996bc3bcee06fcd2eb825d74d0cc916ac2",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:1c1bdd3601dbd46b11c5451ca50b6bb521d17b982acf3af7f73dab9ef53eb50d",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:73935ff9f38573c67ccce49508e523f35b57edfbd838c3cfa0c6ed5df298cb5c",
              "sha256:929d49a1c440333888c5d6738393daacd64d7f548717a0bc7996db44be9de8a5"
            ],
            "locators": [
              {
                "artifact_digest": "sha256:1c1bdd3601dbd46b11c5451ca50b6bb521d17b982acf3af7f73dab9ef53eb50d",
                "start_byte": 9455,
                "end_byte": 10255,
                "value_digest": "sha256:24133138d75db762d8a551b8c4d358ebf7bf9d5344204d20d12dc5f31e3808cf"
              },
              {
                "artifact_digest": "sha256:1c1bdd3601dbd46b11c5451ca50b6bb521d17b982acf3af7f73dab9ef53eb50d",
                "start_byte": 16246,
                "end_byte": 17059,
                "value_digest": "sha256:f36b7933ec2251b2966945bcca313d317a5709c50e30516da7bfb31530186eb7"
              }
            ]
          }
        ],
        "note": "A synchronous POST request to create a CRM object directly returns HTTP status code 201 with the created public object, including its unique ID, timestamps (createdAt, updatedAt), and property key-value pairs."
      },
      {
        "stage": "provision",
        "signal_code": "provisioning_operability",
        "selector_group_id": "provisioning_operability-primary",
        "value": "yes",
        "observed_at": "2026-08-20T15:57:53.221Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "crm-operations"
          },
          {
            "node_kind": "resource",
            "node_id": "oauth"
          }
        ],
        "assessment_method": {
          "name": "public-http-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
        },
        "determination_bases": [
          {
            "kind": "direct_observation",
            "captures": [
              {
                "retained_capture_digest": "sha256:28bb59668fc92f487c4e98f0d73302afb969b8cd9d4f6b0071b02820fac3b41c",
                "capture_rung": "http"
              },
              {
                "retained_capture_digest": "sha256:7c809aa42fd15dc3cada7b52c48957996bc3bcee06fcd2eb825d74d0cc916ac2",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:1c1bdd3601dbd46b11c5451ca50b6bb521d17b982acf3af7f73dab9ef53eb50d",
              "sha256:2ea829f005414a1e93b2cdc6ff239305d4a2061d09d8eec77904ee121dc79372",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:5a7ec41132e54a4541dab0f3897a1362e623fd428294b9f56312b7160f4e8690",
              "sha256:73935ff9f38573c67ccce49508e523f35b57edfbd838c3cfa0c6ed5df298cb5c",
              "sha256:8c010825c11303feeffc271614b00d9ca73434a442fdf4f47eb2b342285e65b4",
              "sha256:f0f4e982de78090268e4a3f78eecb631705526a1ad52cd42de9fcde37c0c9f01"
            ],
            "locators": [
              {
                "artifact_digest": "sha256:1c1bdd3601dbd46b11c5451ca50b6bb521d17b982acf3af7f73dab9ef53eb50d",
                "start_byte": 10256,
                "end_byte": 11041,
                "value_digest": "sha256:627552140b273c89f019f9071fe739f28d3f52c2af5076b6ac6b5bc90210b44c"
              },
              {
                "artifact_digest": "sha256:1c1bdd3601dbd46b11c5451ca50b6bb521d17b982acf3af7f73dab9ef53eb50d",
                "start_byte": 6263,
                "end_byte": 7065,
                "value_digest": "sha256:c8851a542db785b13e57b4b57d8ae02a11ef88eda692d72d06b4ff4d002d1f22"
              },
              {
                "artifact_digest": "sha256:5a7ec41132e54a4541dab0f3897a1362e623fd428294b9f56312b7160f4e8690",
                "start_byte": 10252,
                "end_byte": 11044,
                "value_digest": "sha256:c2cf9661a9ebeb4f5ee59a9b0b35fce1f0636af723d6c49bbdf8308804f20048"
              },
              {
                "artifact_digest": "sha256:5a7ec41132e54a4541dab0f3897a1362e623fd428294b9f56312b7160f4e8690",
                "start_byte": 8643,
                "end_byte": 9451,
                "value_digest": "sha256:4f9943bd3c8df365b0a5b76ff296c9552422d65e8a3cc64143dd257deba2d619"
              }
            ]
          }
        ],
        "note": "Provisioning of CRM objects is triggerable programmatically via a direct POST request to /crm/v3/objects/{objectType}. Additionally, OAuth app installation follows deterministically from user access authorization."
      },
      {
        "stage": "operate",
        "signal_code": "credential_lifecycle",
        "selector_group_id": "credential_lifecycle-primary",
        "value": "partial",
        "observed_at": "2026-08-20T15:56:21.795Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "oauth"
          },
          {
            "node_kind": "resource",
            "node_id": "readiness-ae84fdbaa51b9b88febbd2301b4157e03f052892fed3e42d69d878696fe3944c"
          }
        ],
        "assessment_method": {
          "name": "public-http-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:28bb59668fc92f487c4e98f0d73302afb969b8cd9d4f6b0071b02820fac3b41c",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:5a7ec41132e54a4541dab0f3897a1362e623fd428294b9f56312b7160f4e8690",
              "sha256:8c010825c11303feeffc271614b00d9ca73434a442fdf4f47eb2b342285e65b4",
              "sha256:ad04653f6752f60e07d22bc8134224226663c290a84ef0a203b9151905e871fb"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "oauth"
            },
            "locators": [
              {
                "artifact_digest": "sha256:5a7ec41132e54a4541dab0f3897a1362e623fd428294b9f56312b7160f4e8690",
                "start_byte": 11045,
                "end_byte": 11836,
                "value_digest": "sha256:8d339c6a623686702506daa90ef3921fc5dc016efb33b357924e275c2d5aef09"
              }
            ]
          },
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:9cf9f3f3750426a003a2f5a7cf6385fa83e0923188e65779af963621c7e848a1",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:8ff0d4b2afc5bde79fb3ccd3ed9c603836a056ac2b3326949fa183cadbbe1c44",
              "sha256:c9db578e2109ea5b2bb5b9817020fac550e28cd992ddabb224eac6fae679e157",
              "sha256:cc609a6b00edc7cdea917e19b1ef0ee97eabdd1b10fde1d4e500a87903f30a4e",
              "sha256:e04fea523de929b478a85f3e2b5c50bf0e1534e5fcf07f7aff61ac31c03256d3"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "readiness-ae84fdbaa51b9b88febbd2301b4157e03f052892fed3e42d69d878696fe3944c"
            },
            "locators": [
              {
                "artifact_digest": "sha256:e04fea523de929b478a85f3e2b5c50bf0e1534e5fcf07f7aff61ac31c03256d3",
                "start_byte": 13411,
                "end_byte": 14214,
                "value_digest": "sha256:b2b4ef971e343fa2d2f2f397f219e0e8ae4675405edf22b489cb21266e0a62e0"
              }
            ]
          }
        ],
        "note": "HubSpot documents that access tokens can be refreshed using a refresh token when expired, and private app access tokens can be rotated (either immediately or scheduled for 7 days) or revoked by deleting the app, but recovery or full agent-executable lifecycle without human intervention is not established."
      },
      {
        "stage": "operate",
        "signal_code": "failure_contract",
        "selector_group_id": "failure_contract-primary",
        "value": "partial",
        "observed_at": "2026-08-20T15:56:36.345Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "api-errors"
          }
        ],
        "assessment_method": {
          "name": "public-http-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:2480a61022e49dbc5fc26878f43d0f43260f4cfbfed286e38cd13879762e540f",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:0c6d1afdd521921426efa33b341ec83e49229f7dcd95e5259b997ee7d314527f",
              "sha256:1840fcd29427cdd7949e6c0f7b32a6f7ecf0c13d2731e6543d011a739c3b9861",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:ba1692d70cd807b1670a4fba10eabe5f4a79217bda9aad5bf5a8ee3027559771"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "api-errors"
            },
            "locators": [
              {
                "artifact_digest": "sha256:1840fcd29427cdd7949e6c0f7b32a6f7ecf0c13d2731e6543d011a739c3b9861",
                "start_byte": 8087,
                "end_byte": 8877,
                "value_digest": "sha256:f4ae78f34d6c6e0b68611889604d5bd75e3be8a417c6f8a538e6e84b2fe5c2a0"
              }
            ]
          }
        ],
        "note": "HubSpot documents rate limit errors (429), timeouts (502/504), service temporary errors (503), SSL issues (525/526), and retry guidance including Retry-After headers, but full idempotency, cancellation, and reconciliation semantics are not completely established."
      },
      {
        "stage": "operate",
        "signal_code": "operation_authentication",
        "selector_group_id": "operation_authentication-primary",
        "value": "yes",
        "observed_at": "2026-08-20T15:56:21.795Z",
        "tested_surfaces": [
          {
            "node_kind": "resource",
            "node_id": "oauth"
          },
          {
            "node_kind": "resource",
            "node_id": "readiness-ae84fdbaa51b9b88febbd2301b4157e03f052892fed3e42d69d878696fe3944c"
          }
        ],
        "assessment_method": {
          "name": "public-http-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:9cf9f3f3750426a003a2f5a7cf6385fa83e0923188e65779af963621c7e848a1",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:275ff04b67420a0d125842795895ef56b15e78216272a80813bfe19b9a667e97",
              "sha256:c9db578e2109ea5b2bb5b9817020fac550e28cd992ddabb224eac6fae679e157",
              "sha256:cc609a6b00edc7cdea917e19b1ef0ee97eabdd1b10fde1d4e500a87903f30a4e",
              "sha256:e04fea523de929b478a85f3e2b5c50bf0e1534e5fcf07f7aff61ac31c03256d3"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "readiness-ae84fdbaa51b9b88febbd2301b4157e03f052892fed3e42d69d878696fe3944c"
            },
            "locators": [
              {
                "artifact_digest": "sha256:e04fea523de929b478a85f3e2b5c50bf0e1534e5fcf07f7aff61ac31c03256d3",
                "start_byte": 10368,
                "end_byte": 11014,
                "value_digest": "sha256:45bbe217e840df39d07dcf7da82157fa8f1142d0bf5edc5df1af1debd0dbe5df"
              }
            ]
          },
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:28bb59668fc92f487c4e98f0d73302afb969b8cd9d4f6b0071b02820fac3b41c",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:5a7ec41132e54a4541dab0f3897a1362e623fd428294b9f56312b7160f4e8690",
              "sha256:8c010825c11303feeffc271614b00d9ca73434a442fdf4f47eb2b342285e65b4",
              "sha256:b37a68692b31de8319a34a1fca284c06f51cc194782a99a8b5ef123bb371ff0c"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "oauth"
            },
            "locators": [
              {
                "artifact_digest": "sha256:5a7ec41132e54a4541dab0f3897a1362e623fd428294b9f56312b7160f4e8690",
                "start_byte": 13456,
                "end_byte": 14258,
                "value_digest": "sha256:a64966c6c67a9d011c6b60fada5e03ff36513afb0e48422220edac72cd45389d"
              }
            ]
          }
        ],
        "note": "HubSpot documents request-time authentication using Bearer access tokens generated via OAuth or private apps with scope-restricted permissions."
      },
      {
        "stage": "operate",
        "signal_code": "operation_contract",
        "selector_group_id": "operation_contract-primary",
        "value": "yes",
        "observed_at": "2026-08-20T15:57:53.221Z",
        "tested_surfaces": [
          {
            "node_kind": "interface",
            "node_id": "crm-api"
          }
        ],
        "assessment_method": {
          "name": "public-http-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:911c3b49ca3920d9bb0bd5481f58d3e3a1b7df092e574f4f25eb07438815660e",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:0bab3a8f1d92bb78b3f478d5ad47cebd2b5c6d0b2143ec9ed77d66413cf97763",
              "sha256:3af3b1d1eee7b5a2da7be1a31f0a42364e780bf145a9907d9e41401a271e36e0",
              "sha256:443ea5e4dae9ce65309ae94ab389a756fa97367ab67a21eaf94c4da588483be9",
              "sha256:62b090664baddee217f0ee6cb396d836067021a2d06fda285d27439dc5ef620b"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "api-overview"
            },
            "locators": [
              {
                "artifact_digest": "sha256:0bab3a8f1d92bb78b3f478d5ad47cebd2b5c6d0b2143ec9ed77d66413cf97763",
                "start_byte": 5058,
                "end_byte": 5859,
                "value_digest": "sha256:865ab74db06c08d141be658a7b17838f9fef55f94fd5dac4eccc7ebfac90ba6c"
              }
            ]
          },
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:7c809aa42fd15dc3cada7b52c48957996bc3bcee06fcd2eb825d74d0cc916ac2",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:1c1bdd3601dbd46b11c5451ca50b6bb521d17b982acf3af7f73dab9ef53eb50d",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:73935ff9f38573c67ccce49508e523f35b57edfbd838c3cfa0c6ed5df298cb5c",
              "sha256:963f19e001ee5cdbd089968ef9f54435555634f9437bb1ee7b12f44759825678"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "crm-operations"
            },
            "locators": [
              {
                "artifact_digest": "sha256:1c1bdd3601dbd46b11c5451ca50b6bb521d17b982acf3af7f73dab9ef53eb50d",
                "start_byte": 10256,
                "end_byte": 11041,
                "value_digest": "sha256:627552140b273c89f019f9071fe739f28d3f52c2af5076b6ac6b5bc90210b44c"
              }
            ]
          },
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:2480a61022e49dbc5fc26878f43d0f43260f4cfbfed286e38cd13879762e540f",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:0c6d1afdd521921426efa33b341ec83e49229f7dcd95e5259b997ee7d314527f",
              "sha256:1840fcd29427cdd7949e6c0f7b32a6f7ecf0c13d2731e6543d011a739c3b9861",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:9079190bf6145b9368d8273b31f7a48a58086a669d91082392b38de573ced2b9"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "api-errors"
            },
            "locators": [
              {
                "artifact_digest": "sha256:1840fcd29427cdd7949e6c0f7b32a6f7ecf0c13d2731e6543d011a739c3b9861",
                "start_byte": 9678,
                "end_byte": 10483,
                "value_digest": "sha256:d678e52c2dca044741a094a9a8d7446de2a7edc607aff34ffc18b6a43759e28c"
              }
            ]
          },
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:0d9c30b23946eac421179fee1df4d8d980426370cc004146d26f4dbaef6635ef",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:1179c795de06384176efc754606cba3a0a2d9b60b99e30acf9f9ab684b6ff64c",
              "sha256:33b82e99572b25f609fdf7ab3505e8a129b0d917c236773dcf7e5f33bd991433",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:502f14c2a483ac09e6b1e29ba7360eb1b74cd60b8c8939fe70995726207be2e2"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "api-limits"
            },
            "locators": [
              {
                "artifact_digest": "sha256:1179c795de06384176efc754606cba3a0a2d9b60b99e30acf9f9ab684b6ff64c",
                "start_byte": 15797,
                "end_byte": 16477,
                "value_digest": "sha256:0f82f983fd1280996544285aa84471c6893e1688a9f0aab82d05ea13e387b46d"
              }
            ]
          }
        ],
        "note": "HubSpot documents stable operational contracts, endpoints, request schemas, parameters, and response structures across error handling, usage guidelines, date-versioned API reference overview, and CRM object creation operations."
      },
      {
        "stage": "operate",
        "signal_code": "target_interface_access",
        "selector_group_id": "target_interface_access-primary",
        "value": "yes",
        "observed_at": "2026-08-20T15:57:53.221Z",
        "tested_surfaces": [
          {
            "node_kind": "interface",
            "node_id": "crm-api"
          }
        ],
        "assessment_method": {
          "name": "public-http-semantic-assessment",
          "version": "2026-08-20",
          "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
        },
        "determination_bases": [
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:7c809aa42fd15dc3cada7b52c48957996bc3bcee06fcd2eb825d74d0cc916ac2",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:1c1bdd3601dbd46b11c5451ca50b6bb521d17b982acf3af7f73dab9ef53eb50d",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:5c84abbbc34abddb1fcf0efa188d3d91ca5fd66a6f0e5f4722825b9d59241878",
              "sha256:73935ff9f38573c67ccce49508e523f35b57edfbd838c3cfa0c6ed5df298cb5c"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "crm-operations"
            },
            "locators": [
              {
                "artifact_digest": "sha256:1c1bdd3601dbd46b11c5451ca50b6bb521d17b982acf3af7f73dab9ef53eb50d",
                "start_byte": 8654,
                "end_byte": 9454,
                "value_digest": "sha256:664c44f6c3a1e8e9c5c6d96f54ab232e18dc757695800be045d1bfb8cb444377"
              }
            ]
          },
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:911c3b49ca3920d9bb0bd5481f58d3e3a1b7df092e574f4f25eb07438815660e",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:0bab3a8f1d92bb78b3f478d5ad47cebd2b5c6d0b2143ec9ed77d66413cf97763",
              "sha256:3af3b1d1eee7b5a2da7be1a31f0a42364e780bf145a9907d9e41401a271e36e0",
              "sha256:443ea5e4dae9ce65309ae94ab389a756fa97367ab67a21eaf94c4da588483be9",
              "sha256:62b090664baddee217f0ee6cb396d836067021a2d06fda285d27439dc5ef620b"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "api-overview"
            },
            "locators": [
              {
                "artifact_digest": "sha256:0bab3a8f1d92bb78b3f478d5ad47cebd2b5c6d0b2143ec9ed77d66413cf97763",
                "start_byte": 5058,
                "end_byte": 5859,
                "value_digest": "sha256:865ab74db06c08d141be658a7b17838f9fef55f94fd5dac4eccc7ebfac90ba6c"
              }
            ]
          },
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:2480a61022e49dbc5fc26878f43d0f43260f4cfbfed286e38cd13879762e540f",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:0c6d1afdd521921426efa33b341ec83e49229f7dcd95e5259b997ee7d314527f",
              "sha256:1840fcd29427cdd7949e6c0f7b32a6f7ecf0c13d2731e6543d011a739c3b9861",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:af0f7c906ab713ce61017091a9afe018b31cca371b1ed98484cb97e080bce5d7"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "api-errors"
            },
            "locators": [
              {
                "artifact_digest": "sha256:1840fcd29427cdd7949e6c0f7b32a6f7ecf0c13d2731e6543d011a739c3b9861",
                "start_byte": 5688,
                "end_byte": 6492,
                "value_digest": "sha256:643bd4ee76d90d39b7d2420278ac3aa33a0e893bd9939b91219bf8c483e8a9a6"
              }
            ]
          },
          {
            "kind": "explicit_first_party_declaration",
            "captures": [
              {
                "retained_capture_digest": "sha256:0d9c30b23946eac421179fee1df4d8d980426370cc004146d26f4dbaef6635ef",
                "capture_rung": "http"
              }
            ],
            "artifact_digests": [
              "sha256:1179c795de06384176efc754606cba3a0a2d9b60b99e30acf9f9ab684b6ff64c",
              "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
              "sha256:502f14c2a483ac09e6b1e29ba7360eb1b74cd60b8c8939fe70995726207be2e2",
              "sha256:faf3f8e7dce0e3875b88fdaf4548b31aa56a9d2febcf82a837fb9eca79479f05"
            ],
            "source_surface": {
              "node_kind": "resource",
              "node_id": "api-limits"
            },
            "locators": [
              {
                "artifact_digest": "sha256:1179c795de06384176efc754606cba3a0a2d9b60b99e30acf9f9ab684b6ff64c",
                "start_byte": 8574,
                "end_byte": 9372,
                "value_digest": "sha256:86db9d7762823f78e6ddd5a45d43a168a8f6516303db6455a0112536c72479c5"
              }
            ]
          }
        ],
        "note": "HubSpot provides machine-operable HTTP API endpoints across error handling, platform usage limits, date-versioned API overview, and CRM object creation operations."
      }
    ],
    "revision_digest": "sha256:986780b22e79c504c57a411c051874457bcd59191cdf762126879fdeeda0cb55"
  }
}
