<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HubSpot - Starface interation // User-Permissions in APIs &amp; Integrations</title>
    <link>https://community.hubspot.com/t5/APIs-Integrations/HubSpot-Starface-interation-User-Permissions/m-p/1234515#M86162</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.hubspot.com/t5/user/viewprofilepage/user-id/883871"&gt;@BFlory&lt;/a&gt;&amp;nbsp;&amp;nbsp;, the screenshot you shared is actually very helpful, and it points to something subtle but important in how HubSpot evaluates permissions during OAuth installs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Even though the user shows “Alle Tickets” for view, edit, delete, and merge, HubSpot does not treat object permissions and seat entitlements as the same thing during OAuth authorization. For apps requesting the tickets scope, HubSpot checks two things at install time. First, the user must have permission to approve app scopes. Second, the user must hold a Service Hub seat that unlocks ticket access at the product level, not just via role permissions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="936" data-end="1306"&gt;A Core seat alone is not always sufficient for ticket-scoped OAuth apps, even if it “includes starters” on paper. The Core seat allows access to many features, but ticket APIs are still gated behind Service Hub entitlements when used by external apps. That’s why Super Admins work and standard users do not, even when their permissions look identical in the UI.&lt;/P&gt;
&lt;P data-start="1308" data-end="1752"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="1308" data-end="1752"&gt;A quick way to confirm this is to temporarily assign the affected user a Service Hub seat (even a lower tier), then retry the STARFACE connection. In most cases, the authorization succeeds immediately once the seat is present. HubSpot documents this behavior implicitly under OAuth scope approval and object access, where product access is evaluated separately from role permissions (&lt;A class="" href="https://developers.hubspot.com/docs/api/working-with-oauth" target="_blank" rel="noopener" data-start="1692" data-end="1750"&gt;https://developers.hubspot.com/docs/api/working-with-oauth).&lt;/A&gt;&lt;/P&gt;
&lt;P data-start="1754" data-end="2010"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="1754" data-end="2010"&gt;One more thing to double-check: make sure the authorizing user is the one completing the OAuth flow. Even if a Super Admin enabled Marketplace permissions globally, the individual user approving the app must personally meet the seat and scope requirements.&lt;/P&gt;
&lt;P data-start="2012" data-end="2109" data-is-last-node="" data-is-only-node=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="2012" data-end="2109" data-is-last-node="" data-is-only-node=""&gt;Hope this helps clarify why everything looks “green” in permissions, yet the install still fails.&lt;/P&gt;</description>
    <pubDate>Tue, 16 Dec 2025 15:13:29 GMT</pubDate>
    <dc:creator>RubenBurdin</dc:creator>
    <dc:date>2025-12-16T15:13:29Z</dc:date>
    <item>
      <title>HubSpot - Starface interation // User-Permissions</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/HubSpot-Starface-interation-User-Permissions/m-p/1234370#M86144</link>
      <description>&lt;P&gt;Hello HubSpot community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently we are trying to implement starface into our HubSpot. Everything works quite fine for all Superadmins. Unfortunately, we get this notification:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-12-15 111601.png" style="width: 400px;"&gt;&lt;img src="https://community.hubspot.com/t5/image/serverpage/image-id/164011i4CCC881D1A5269AB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2025-12-15 111601.png" alt="Screenshot 2025-12-15 111601.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Translation:&amp;nbsp;The linking process could not be completed. Authorization failed because your user account does not have permission for the required areas (tickets). Please contact your account super administrator to request the necessary permissions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I go into the specific user permissions as a superadmin, I see the following:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BFlory_0-1765875782737.png" style="width: 400px;"&gt;&lt;img src="https://community.hubspot.com/t5/image/serverpage/image-id/164012i35AC84EDE4189046/image-size/medium?v=v2&amp;amp;px=400" role="button" title="BFlory_0-1765875782737.png" alt="BFlory_0-1765875782737.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;As I do understand this, every permission is granted at highest level.&lt;/P&gt;&lt;P&gt;Does anyone know what may cause the problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 09:03:52 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/HubSpot-Starface-interation-User-Permissions/m-p/1234370#M86144</guid>
      <dc:creator>BFlory</dc:creator>
      <dc:date>2025-12-16T09:03:52Z</dc:date>
    </item>
    <item>
      <title>Re: HubSpot - Starface interation // User-Permissions</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/HubSpot-Starface-interation-User-Permissions/m-p/1234405#M86153</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.hubspot.com/t5/user/viewprofilepage/user-id/883871"&gt;@BFlory&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This screenshot does not indicate a user permission issue. Instead, it relates to who has the authority to approve the scopes requested by STARFACE.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For apps that need the tickets scope and often additional CRM scopes, HubSpot only allows users with App Marketplace Access or Super Admin rights to approve these scopes. Ensure your account has this permission.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 11:16:55 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/HubSpot-Starface-interation-User-Permissions/m-p/1234405#M86153</guid>
      <dc:creator>GiantFocal</dc:creator>
      <dc:date>2025-12-16T11:16:55Z</dc:date>
    </item>
    <item>
      <title>Re: HubSpot - Starface interation // User-Permissions</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/HubSpot-Starface-interation-User-Permissions/m-p/1234483#M86158</link>
      <description>&lt;P&gt;Hello, Can you confirm that the authorizing user has a Service Hub Seat?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This could be caused by OAuth seat requirements if the user doesn't have the correct seat to provide the tickets scope.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me know if this helps, or if you have any other questions!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;P&gt;&lt;SPAN class="lia-unicode-emoji"&gt;&lt;SPAN class="lia-unicode-emoji"&gt;&lt;span class="lia-unicode-emoji" title=":heavy_check_mark:"&gt;✔️&lt;/span&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Was I able to help answer your question? Help the community by&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;marking it as a solution.&lt;/STRONG&gt;&lt;/P&gt;&lt;TABLE width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="20.365535248041773%" height="191px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BrandonWoodruff_0-1765895797837.jpeg" style="width: 200px;"&gt;&lt;img src="https://community.hubspot.com/t5/image/serverpage/image-id/164036iDE0D171AAA5595A8/image-size/small?v=v2&amp;amp;px=200" role="button" title="BrandonWoodruff_0-1765895797837.jpeg" alt="BrandonWoodruff_0-1765895797837.jpeg" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD width="79.50391644908615%" height="191px"&gt;&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://www.linkedin.com/in/brandon-woody-woodruff/" target="_blank" rel="noopener nofollow noreferrer"&gt;Brandon Woodruff&lt;/A&gt;&lt;BR /&gt;&lt;/STRONG&gt;Senior Software Developer @&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.pearagon.com/" target="_blank" rel="nofollow noopener noreferrer"&gt;Pearagon&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Still have questions? Reach out at&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="mailto:brandon@pearagon.com" target="_blank" rel="noopener nofollow noreferrer"&gt;brandon@pearagon.com&lt;/A&gt;&lt;/P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BrandonWoodruff_1-1765895797727.png" style="width: 200px;"&gt;&lt;img src="https://community.hubspot.com/t5/image/serverpage/image-id/164037i081BF86A94A06148/image-size/small?v=v2&amp;amp;px=200" role="button" title="BrandonWoodruff_1-1765895797727.png" alt="BrandonWoodruff_1-1765895797727.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 14:37:18 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/HubSpot-Starface-interation-User-Permissions/m-p/1234483#M86158</guid>
      <dc:creator>BrandonWoodruff</dc:creator>
      <dc:date>2025-12-16T14:37:18Z</dc:date>
    </item>
    <item>
      <title>Re: HubSpot - Starface interation // User-Permissions</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/HubSpot-Starface-interation-User-Permissions/m-p/1234493#M86159</link>
      <description>&lt;P&gt;Hey Brandon,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The user has the license "Core":&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BFlory_0-1765896209952.png" style="width: 400px;"&gt;&lt;img src="https://community.hubspot.com/t5/image/serverpage/image-id/164040iA70FD3CA12C7E48C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="BFlory_0-1765896209952.png" alt="BFlory_0-1765896209952.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Shouldn't it be fine this way, since it includes all the "starters":&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BFlory_1-1765896279732.png" style="width: 400px;"&gt;&lt;img src="https://community.hubspot.com/t5/image/serverpage/image-id/164041i091821AEC4B8D7A8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="BFlory_1-1765896279732.png" alt="BFlory_1-1765896279732.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 14:45:21 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/HubSpot-Starface-interation-User-Permissions/m-p/1234493#M86159</guid>
      <dc:creator>BFlory</dc:creator>
      <dc:date>2025-12-16T14:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: HubSpot - Starface interation // User-Permissions</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/HubSpot-Starface-interation-User-Permissions/m-p/1234501#M86160</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.hubspot.com/t5/user/viewprofilepage/user-id/577159"&gt;@GiantFocal&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I went to the following settings in HubSpot and turned on every thing that had to do with market place:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BFlory_5-1765896498086.png" style="width: 400px;"&gt;&lt;img src="https://community.hubspot.com/t5/image/serverpage/image-id/164045i373639408012A949/image-size/medium?v=v2&amp;amp;px=400" role="button" title="BFlory_5-1765896498086.png" alt="BFlory_5-1765896498086.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately this did not seem to be enough to change it. The message still appeared when we wanted to connect it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 14:48:53 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/HubSpot-Starface-interation-User-Permissions/m-p/1234501#M86160</guid>
      <dc:creator>BFlory</dc:creator>
      <dc:date>2025-12-16T14:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: HubSpot - Starface interation // User-Permissions</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/HubSpot-Starface-interation-User-Permissions/m-p/1234515#M86162</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.hubspot.com/t5/user/viewprofilepage/user-id/883871"&gt;@BFlory&lt;/a&gt;&amp;nbsp;&amp;nbsp;, the screenshot you shared is actually very helpful, and it points to something subtle but important in how HubSpot evaluates permissions during OAuth installs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Even though the user shows “Alle Tickets” for view, edit, delete, and merge, HubSpot does not treat object permissions and seat entitlements as the same thing during OAuth authorization. For apps requesting the tickets scope, HubSpot checks two things at install time. First, the user must have permission to approve app scopes. Second, the user must hold a Service Hub seat that unlocks ticket access at the product level, not just via role permissions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="936" data-end="1306"&gt;A Core seat alone is not always sufficient for ticket-scoped OAuth apps, even if it “includes starters” on paper. The Core seat allows access to many features, but ticket APIs are still gated behind Service Hub entitlements when used by external apps. That’s why Super Admins work and standard users do not, even when their permissions look identical in the UI.&lt;/P&gt;
&lt;P data-start="1308" data-end="1752"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="1308" data-end="1752"&gt;A quick way to confirm this is to temporarily assign the affected user a Service Hub seat (even a lower tier), then retry the STARFACE connection. In most cases, the authorization succeeds immediately once the seat is present. HubSpot documents this behavior implicitly under OAuth scope approval and object access, where product access is evaluated separately from role permissions (&lt;A class="" href="https://developers.hubspot.com/docs/api/working-with-oauth" target="_blank" rel="noopener" data-start="1692" data-end="1750"&gt;https://developers.hubspot.com/docs/api/working-with-oauth).&lt;/A&gt;&lt;/P&gt;
&lt;P data-start="1754" data-end="2010"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="1754" data-end="2010"&gt;One more thing to double-check: make sure the authorizing user is the one completing the OAuth flow. Even if a Super Admin enabled Marketplace permissions globally, the individual user approving the app must personally meet the seat and scope requirements.&lt;/P&gt;
&lt;P data-start="2012" data-end="2109" data-is-last-node="" data-is-only-node=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="2012" data-end="2109" data-is-last-node="" data-is-only-node=""&gt;Hope this helps clarify why everything looks “green” in permissions, yet the install still fails.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 15:13:29 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/HubSpot-Starface-interation-User-Permissions/m-p/1234515#M86162</guid>
      <dc:creator>RubenBurdin</dc:creator>
      <dc:date>2025-12-16T15:13:29Z</dc:date>
    </item>
    <item>
      <title>Re: HubSpot - Starface interation // User-Permissions</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/HubSpot-Starface-interation-User-Permissions/m-p/1234991#M86191</link>
      <description>&lt;P&gt;Thank you for your detailed reply.&lt;BR /&gt;&lt;BR /&gt;We solved it with granting Super Admin permission to the user, connecting the app via OAuth and reassigning the original role. In that way it worked! Hopefully this does not come to a problem sometime later on but for now, it is fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot and best regards&lt;BR /&gt;&lt;BR /&gt;Ben&lt;/P&gt;</description>
      <pubDate>Wed, 17 Dec 2025 14:27:47 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/HubSpot-Starface-interation-User-Permissions/m-p/1234991#M86191</guid>
      <dc:creator>BFlory</dc:creator>
      <dc:date>2025-12-17T14:27:47Z</dc:date>
    </item>
  </channel>
</rss>

