Currently, HubSpot's private app API keys provide broad access across all CRM data, making it impossible to restrict API access at a granular level. For example, when granting API access, the user obtains full visibility of all contacts, lists, deals, and other objects within HubSpot. This creates significant security and data privacy concerns—particularly when integrating third-party applications or providing API access to external partners. I propose the implementation of granular, scoped API permissions within HubSpot’s private apps. Specifically, this would allow administrators to define and limit API access based on criteria such as: Specific contact or deal lists Custom property values Individual CRM objects or segments By enabling scoped permissions, agencies and technical administrators could safely integrate external systems and maintain data isolation and compliance with privacy standards. This approach aligns with industry-standard security practices, enhancing HubSpot's flexibility and robustness for advanced technical integrations.
... Exibir mais