Quick tipDeveloperSmart CRM

Keep a HubSpot OAuth integration from breaking: refresh tokens

Access tokens expire. Refresh before they do.

Subscription
Developer account
Permissions
App developer access
Time
4 min · Advanced
Last verified

Short answer

HubSpot's developer blog: the access token expires (it uses 30 minutes in its example), and expires_in tells you when. Refresh before calls fail with a 401, by POSTing to the OAuth token endpoint, and always keep the latest refresh token returned. Never cache refresh tokens or client secrets in a general-purpose cache.

1. Rules

  • Read expires_in from every token response.
  • Refresh slightly early rather than on error.
  • Store refresh tokens and secrets like passwords.

2. Credentials

See client ID and secret.

3. Related

Service keys for data-only integrations.

Sources

New field notes by email

One email when a new article publishes.

Still stuck?

If this did not fix it, the problem is probably specific to your setup. Book a call and we will look at it together.

Book a call with Sam