Quick tipDeveloperSmart CRMDeveloper

HubSQL beta: what it is, what it is not, and the 403 MISSING_SCOPES fix

HubSQL sounds like a database you can plug other tools into. It is an API. Here is what that means in practice.

Subscription
Private beta (invite only at the time of writing)
Permissions
Private or legacy app with the required read scopes
Time
6 min · Advanced
Last verified

Short answer

HubSQL is a read-only HTTP API for running SQL-style queries against HubSpot data. It is not a database, so you cannot link another SQL server to it directly. You can feed other systems with a sync script, within beta rate limits. If you get 403 MISSING_SCOPES, the app behind your token needs more read scopes. That is what happened to me, and after I added them the same query returned 200.

1. What HubSQL is

HubSpot describes HubSQL as a data access layer for running standard SQL, with joins, filters, and aggregations, against your CRM data. It entered private beta in September 2026 and access is by invitation. HubSpot had not published full public documentation when I wrote this, so check the docs HubSpot gave your account and treat everything below as my testing on one portal.

2. What it is not

When asked whether it could integrate with other SQL servers, my answer was no, not directly. It is an HTTP API that returns query results. It is not a database you can point another server at. To get HubSpot data into another system, write a sync script that runs the query and loads the results, and keep it inside the beta rate limits. In my test it was also read-only.

3. The 403 MISSING_SCOPES fix

My first query to a portal that had the beta turned on returned 403 MISSING_SCOPES. Beta access was fine. The token's app simply did not have the read scopes the query needed. After I added them to the app, the same deal-by-stage query returned HTTP 200 with about 1,700 deals across 22 stages.

HubSpot has moved private apps into the Legacy Apps page, so look for your app there.

Private Apps page saying Your private apps have moved with the Go to Legacy Apps button highlighted
Private apps now point you to Legacy Apps.
Legacy Apps list with two private apps and the Create legacy app button highlighted
The Legacy Apps list. Open the app that owns your token to change its scopes.
Treat the token like a password

Never paste a token into a chat, a screenshot, or a repo. If one is exposed, rotate it in the app settings.

You can open Private apps to get there from your own portal. You need developer access to the account.

Sources

New field notes by email

One email when a new article publishes.

Still stuck?

If this did not fix it, the problem is probably specific to your setup. Book a call and we will look at it together.

Book a call with Sam