Bugfix: Update for Webhook Association Events Containing Internal CRM Objects

Thank you for your question and comment @baribeau !

Non-public/internal objects are used exclusively by HubSpot’s internal platforms, features, or legacy infrastructure and are not intended to be exposed via the standard public APIs. Their data, structure, or relationships are considered proprietary, sensitive, or are not designed to be externally supported.

It is essential to note that this change is specifically targeted at association events involving internal, non-public CRM objects. Historically, direct access and Webhook events for these internal objects were already restricted from public APIs. However, there was an oversight where association events—events triggered when these internal objects were linked with public objects—were still being sent via Webhooks. This update closes that gap and aligns association event handling with existing data security policies. Other Webhook event types and all association events involving only public objects (including your Custom Objects) are not affected and will continue to function as before.