Quick tipDeveloperSmart CRM

HubSpot Service Keys: the replacement for private app tokens

Service Keys are HubSpot's answer for a token you paste into a BI tool or script. They cover most private app uses, except webhooks.

Subscription
Public beta; all tiers with Developer Tools access
Permissions
Developer tools access
Time
5 min · Intermediate
Last verified

Short answer

Service Keys, under Settings > Integrations > Service Keys, are scoped API credentials for system-to-system integrations, BI tools, data warehouses and internal scripts. HubSpot's changelog says creating one needs Developer Tools access, a key can only get scopes the creating user already has, and Service Keys do not support webhooks. HubSpot positions them as the replacement for legacy private apps, whose creation is being turned off.

1. Where

Service Keys sit in the Development area under Keys, next to Personal Access Key and Developer API Key.

Service Keys page with a Create service key button and one existing key
Create service key (1) and existing keys (2).

2. Rules

  • Creating a key needs Developer Tools access.
  • A key can only be given scopes the creator already has, and only the scopes you select.
  • No webhooks. If you need webhooks, use a project-based app or keep a legacy private app.
  • Name keys for their job, such as powerbi-contacts-read, and grant the least scope.

3. Private apps

New legacy private apps are being switched off. See private apps moved to Legacy Apps for the dates.

Sources

New field notes by email

One email when a new article publishes.

Still stuck?

If this did not fix it, the problem is probably specific to your setup. Book a call and we will look at it together.

Book a call with Sam