hubspot-mcp (tillheidrich/hubspot-mcp) is an MCP server listed on the M8ven Trust Index. It scores 74 out of 100, grade C. It declares 57 tools. No publisher has claimed this listing.
Run HubSpot from Claude, Codex or Cursor: pages, blog, forms, emails, campaigns — and CRM only if you switch it on. With ALLOW_CRM=none (the default) no customer data is reachable, so none can reach the model. 65 tools, publishing gated per area, every consequential call confirmed. Local, MIT, your key never leaves the machine.
Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
tillheidrich
Source: github_repo_search
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
list_blogsList the blog instances in the portal, e.g. a marketing blog and a tech blog.
list_blog_postsList blog posts.
get_blog_postFetch one blog post.
create_blog_post_draftCreate a new blog post in DRAFT state.
update_blog_post_draftPatch a blog post's DRAFT. The published version is never touched.
reset_blog_post_draftDiscard draft changes on a blog post and restore the live version.
list_campaignsList marketing campaigns with their dates and goals.
get_campaignRead one campaign. Pass `properties` for metrics beyond the basics.
list_campaign_assetsList the assets attached to a campaign.
create_campaignCreate a campaign.
update_campaignUpdate campaign properties. Only the keys you pass change.
attach_asset_to_campaignAttach a page, post, email or form to a campaign.
detach_asset_from_campaignRemove an asset from a campaign. The asset itself is untouched.
search_crm_objectsSearch CRM records.
get_crm_objectRead one CRM record.
list_crm_propertiesList the properties defined on an object type.
list_crm_associationsList records of `to_type` linked to one record of `from_type`.
list_crm_ownersList HubSpot users who can own records. Optionally filter by email.
list_crm_pipelinesList pipelines and their stages for deals or tickets.
search_crm_listsFind contact lists by name. Use the ID with the marketing email tools.
list_workflowsList automation workflows with their enabled state.
get_crm_import_statusCheck how a CRM import is going.
create_crm_objectCreate a CRM record.
update_crm_objectUpdate properties on one CRM record. Only the keys you pass change.
batch_update_crm_objectsUpdate up to 100 records in one call.
associate_crm_objectsLink two records with HubSpot's default association label.
remove_crm_associationUnlink two records. The records themselves are untouched.
create_crm_listCreate a manual list. 0-1 is contacts, 0-2 companies.
add_records_to_listAdd records to a manual list.
remove_records_from_listRemove records from a manual list. The records are not deleted.
create_crm_propertyDefine a new property on an object type.
archive_crm_objectMove a CRM record to the recycle bin.
set_workflow_enabledTurn a workflow on or off.
list_templatesList CMS templates available in the portal.
list_domainsList domains connected to the portal.
list_blog_authorsList blog authors, for setting `author_id` on a blog post draft.
list_marketing_emailsList marketing emails.
get_marketing_emailFetch one marketing email.
create_marketing_email_draftCreate a marketing email in DRAFT state. Nothing is scheduled or sent.
update_marketing_email_draftPatch a marketing email's DRAFT. The published version is never touched.
duplicate_marketing_emailDuplicate a marketing email — the usual way to start next month's newsletter.
list_formsList forms in the portal.
get_formFetch one form.
create_formCreate a HubSpot form.
update_formPatch a form.
duplicate_formDuplicate a form — the usual way to make a second-language variant.
list_landing_pagesList landing pages.
list_site_pagesList site pages. Same filters as list_landing_pages.
get_pageFetch one landing or site page.
create_landing_page_draftCreate a new landing page in DRAFT state.
create_site_page_draftCreate a new site page in DRAFT state. Same arguments as create_landing_page_draft.
update_page_draftPatch a page's DRAFT. The published version is never touched.
reset_draftDiscard draft changes and restore the draft to match the live version.
duplicate_pageDuplicate an existing page as a new DRAFT, optionally applying overrides.
create_language_variantCreate a language variant of an existing page, e.g. EN from a DE page.
cancel_scheduled_publishCancel a pending scheduled publish.
generate_social_bulk_xlsx_fileWrite a HubSpot-format Excel file for scheduling social posts in bulk.
publish_pagebehind configTake a landing or site page live on the public website, now.
schedule_page_publishbehind configSchedule a landing or site page to go live at a future time.
unpublish_pagebehind configTake a live page down. It returns to draft; nothing is deleted.
publish_blog_postbehind configTake a blog post live on the public blog, now.
schedule_blog_post_publishbehind configSchedule a blog post to go live at a future time.
unpublish_blog_postbehind configTake a live blog post down. It returns to draft; nothing is deleted.
publish_marketing_emailbehind configSend a marketing email, or schedule it per its own settings.
unpublish_marketing_emailbehind configWithdraw a marketing email that has not gone out yet.
HUBSPOT_MCP_ENV_FILE, and enable the second one only for the session whereTool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
65/65 tools missing one or more hints — list_blogs (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); list_blog_posts (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get_blog_post (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +62 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/tillheidrich/hubspot-mcp)?variant=verified to the badge URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check