Skip to content
Current/ Help Center

HubSpot: connect, import your book, and keep it in step

7 min read · Updated Jul 28, 2026

Moving off HubSpot — or keeping it running alongside Current while your team transitions? Both start in the same place: one HubSpot tile, one connection. This article is the orientation. Once you're connected, "HubSpot one-time import: exactly what comes across" covers the field-by-field mapping, and "HubSpot two-way sync vs one-time import: which to run" covers the ongoing bridge.

The most important thing to know up front: connecting HubSpot does nothing on its own. Connecting gives Current permission to read your portal. Nothing is pulled, matched, or written into your CRM until you run the import wizard and approve the match plan.

Connect the portal

There are two ways to connect, and both are done once by a Tenant Admin. Signing in with HubSpot is the quickest and what most workspaces should use. A private-app token is still there if you would rather scope a key by hand. Every workspace brings its own HubSpot portal either way.

  1. 1
    Open the HubSpot tile
    Open Integrations from the left sidebar, find the HubSpot tile, and choose Manage.
  2. 2
    Choose Connect with HubSpot
    You go to HubSpot, sign in if you are not already, and pick the account you want to connect. Current never sees your HubSpot password.
  3. 3
    Approve the permissions
    HubSpot shows exactly what Current is asking for. The read permissions for companies, contacts, deals, and owners are required. The write permissions are optional, and you only need them once you turn the two-way bridge on, so it is fine to connect read-only first.
  4. 4
    Land back in Current
    HubSpot returns you to Current and the tile flips to Connected with your portal ID. An Import wizard button appears next to Manage.
Note
Your connection renews itself
Access granted through HubSpot sign-in expires on HubSpot's schedule, and Current renews it in the background before it lapses. A connection that worked this morning still works tonight without anyone touching it. If HubSpot ever refuses the renewal, because access was revoked on their side, the tile says so and asks you to reconnect rather than failing quietly.

Using a private-app token instead

Under Advanced in the HubSpot drawer you can paste a private-app access token instead. Workspaces connected this way keep working exactly as they always have, so there is nothing you need to change.

  1. 1
    Create a private app in HubSpot
    In HubSpot: Settings → Integrations → Private Apps → create (or open) a private app. Name it something recognisable ("Current") so you can find it later.
  2. 2
    Grant the scopes
    At minimum, the core read scopes for contacts, companies, deals, and owners. Add the engagement and lists scopes below if you want relationship history and list-based segmentation to come across too.
  3. 3
    Copy the access token
    HubSpot shows the token (it starts with pat-) once. Copy it before you leave the page.
  4. 4
    Paste it into Current
    In the HubSpot drawer, open Advanced, paste the token, and press Connect with token. Current validates it live against HubSpot before storing anything — a bad token is rejected on the spot, not three days later.
Note
The token is write-only
Current stores the token server-side and never shows it back — not in the drawer, not in an export. To rotate it, paste a new token and press Replace connection.
Note
Disconnecting
Disconnect stops the import and the bridge immediately. If you connected by signing in with HubSpot, Current also revokes its own access at HubSpot, so the connection is gone from both sides rather than sitting dormant in your portal. If you connected with a token, the stored token is blanked here and you can delete the private app in HubSpot whenever you like.

The scopes, and what each one buys you

The Manage drawer shows a checklist of every scope Current uses, grouped by what it enables. It marks each one against the scopes HubSpot actually reported for your token — so you can see the gaps before you run an import rather than after. If HubSpot doesn't report the token's scopes at all, the checklist says so plainly instead of showing false crosses.

GroupScopesWhat you lose without them
Core importcrm.objects.contacts.read, crm.objects.companies.read, crm.objects.deals.read, crm.objects.owners.readThe import can't run. The owners scope is what maps each record to the right account executive — without it, deals come across unattributed.
Relationship historycrm.objects.notes.read, crm.objects.calls.read, crm.objects.meetings.read, crm.objects.tasks.read, crm.objects.emails.read, sales-email-readCompanies and deals import, but the activity trail behind them doesn't — your team loses the context of what was already said and done.
Full replacement + 2-way bridgecrm.schemas.contacts.read, crm.schemas.companies.read, crm.schemas.deals.read, crm.lists.read, plus the contacts/companies/deals write scopesWithout crm.lists.read, your HubSpot lists don't come across. The schemas scopes let the connection test verify property-level read access — the import itself pulls a defined set of standard HubSpot properties plus ITP's deal-economics fields, not arbitrary custom fields. The write scopes only matter once you turn the bridge on.
Note
If you connected with HubSpot sign-in
The permissions above describe a private app. Signing in with HubSpot asks for the same core read access, plus optional write access and lists. Two rows in the connection test read differently on this path. Lists is optional, so approve it when HubSpot offers it or choose Re-authorize to add it later, and your HubSpot lists come across as tags. Emails stays unread on purpose: HubSpot restricts that permission to allow-listed apps, and the import does not need it, because email activity comes across with your contacts. Notes, calls, meetings, and tasks all still import.
Tip
Test what the key can actually read — don't trust the list
The Manage drawer has a "Test what this key can read" button. It performs one cheap read per data family (contacts, companies, deals, owners, notes, calls, meetings, tasks, emails, custom fields, lists) and reports the real answer. This matters because some HubSpot keys report a scope but still refuse the granular engagement reads. Run it once before your first import, and again any time you rotate the token.

Then decide: import once, or keep both systems in step

Connecting the portal is the fork in the road. What you do next depends on whether HubSpot is being retired or is still where sales lives during a transition.

If this is you…Do this
HubSpot is being retired — you want the history and nothing elseRun the import wizard once. Read "HubSpot one-time import: exactly what comes across" first so you know what maps where.
Sales still works out of HubSpot for now, and Current needs to reflect itRun the import first, then set the HubSpot 2-way sync section of the same Manage drawer to Dual-run. Dual-run starts in Dry-run, so switch Dry-run off when you're ready for it to be live. See "HubSpot two-way sync vs one-time import: which to run".
You want HubSpot changes to flow in, but never write anything back to HubSpotImport only pulls changes in and never writes back — but today the scheduled sweep only runs for Dual-run workspaces, so Import only does not refresh on its own. If you need HubSpot changes to keep flowing in, use Dual-run with Dry-run left ON (Current pulls in, nothing is written back to HubSpot).
Note
Dual-run starts in Dry-run
Dry-run is on by default. Current logs every operation it would perform, in both directions, and writes nothing. Review the Recent activity log in the drawer, then switch Dry-run off to make the sync live.
Heads up
Nothing lands in your CRM until you approve it
The import wizard pulls HubSpot into a holding area, matches it against what you already have, and shows you the plan — new records, matched records, and anything ambiguous. Your live company, contact, and deal records are only created or updated after you approve. That review step is your safety net; don't skip it on a large book.

How HubSpot data behaves once it's in Current

Current is built around your PSA, and that hierarchy holds even after a HubSpot import. Where a company exists in both systems, the PSA-anchored record is the anchor: contract value, MRR, seat counts, and ticket traffic come from your PSA, never from HubSpot.

  • HubSpot lists come across as Current Lists: each list becomes an automatic List in the Lists area, and contacts are added to it as they import. Because they arrive as real Lists, HubSpot lists are picked from the Lists picker when you build a campaign audience — the old separate "HubSpot lists & lifecycle" filter is gone. (Current's own tags are a separate filter and still work as they always did.)
  • Lifecycle stages and lead statuses arrive the same way, as descriptive labels on contacts (for example "Lifecycle: customer"), never as a status field. Whether a company counts as a customer in Current is decided by an active recurring contract in your PSA (an Autotask contract or a ConnectWise agreement).
  • Deal owners are remembered even when that person has no Current login yet. When someone with a matching email joins, their historical deals are claimed automatically.
  • Engagement history (notes, calls, meetings, emails, tasks) is import-only. It comes across once and never drifts back and forth.

When something looks wrong

  • A dead token shows up when you use the connection, not on the tile — "Test what this key can read" reports "Token was rejected — reconnect with a fresh token", or the import fails with a HubSpot auth or permission error. Usually the private app was deleted or its token rotated in HubSpot; paste a fresh token and press Replace connection.
  • Import brings companies but no activity history — the engagement scopes are missing or the key can't read them. Run "Test what this key can read" to confirm, then add the scopes in HubSpot and reconnect.
  • Everything imported unowned — the owners read scope wasn't granted, so Current couldn't map HubSpot owners to people. Add the scope in HubSpot and reconnect. Records already imported keep their HubSpot owner id and are claimed automatically the next time that person's Current profile is created or their email is updated. To re-own them now, use Undo this import on the run and import again.
  • You can't see the HubSpot tile at all — it's shown only to Tenant Admins with CRM access. Ask an admin, or see "Roles & permissions: who sees what".
Note
Who can do this
Connecting, replacing, disconnecting, and changing the sync mode are Tenant Admin actions — the server rejects anyone else. It's a shared connection that affects every company, contact, and deal it touches — not a per-user setting.
Was this helpful?