Sidekick Strategies
Events
Book a Free CallContact Us
HubSpot Updates

HubSpot Account Service Keys

September 29, 2026

What This Update Actually Is

HubSpot shipped Service Keys as a direct replacement for legacy private apps. Both solve the same core problem: giving an external tool a secure way to talk to your HubSpot data. But the implementation is completely different.

Legacy private apps lived in the developer section of your portal and required comfort with app-level concepts like scopes, OAuth flows, and token management. Service Keys strip all of that away.

You navigate to Settings, pick permissions, copy a key, and paste it into your tool. That's it. The key is scoped to only the data you select, doesn't expire when an employee leaves, logs all activity for auditing, and can be rotated with a seven-day grace period so your integrations don't break mid-sync.

One important caveat: you'll need either a Developer Seat or the "Developer tools access" permission assigned by your account admin before you can create or manage Service Keys. If you don't see the Settings option, that's the first place to check.

Why HubSpot Shipped This

Here's the pattern we see constantly in portals: a marketing ops manager needs to push HubSpot contact data into Tableau. They know exactly what they need. But connecting the two tools means either learning private app development or waiting days for a developer to have capacity.

That bottleneck costs real time. Reports get delayed. Decisions get made on stale data. Humans who are perfectly capable of setting up the integration get stuck waiting on a queue.

There's also a security problem hiding inside the old workflow. Legacy private app tokens were often tied to individual employee accounts. When someone left, the token stayed active until someone remembered to revoke it. Service Keys fix this. Keys are account-level, not person-level, so an employee departure doesn't silently break or expose an integration.

HubSpot also moved Service Keys onto its modern Developer Platform infrastructure. That matters because it means these keys are built to last, not patched onto aging internals.

How to Use It Step by Step

  1. Get access first. Ask your account admin to assign you a Developer Seat or enable the "Developer tools access" permission on your user profile.
  2. Navigate to Settings, then Integrations, then Service Keys. This is where all account-level keys live.
  3. Click Create service key. Give it a name that explains exactly what it connects and why, for example: "Tableau - Marketing Pipeline Sync" or "Power BI - Sales Dashboard." You'll thank yourself later.
  4. Select only the permissions your integration actually needs. Read contacts, read deals, read companies. Don't grant write access unless the tool genuinely needs to push data back into HubSpot.
  5. Click Create and copy the key immediately. HubSpot will only show you the full token once. Paste it directly into your external tool's API credentials field.
  6. Test the connection in your external tool before closing the tab. Confirm data is flowing, then document the key name and its purpose in your team's integration log.
  7. Schedule a rotation cadence. Use the built-in Rotate function when needed. You'll get a seven-day window where both the old and new key work, so you can update your tool without an outage.

What It Touches in Your HubSpot Strategy

Service Keys look like a developer feature. They aren't. They're a RevOps and data strategy feature wearing a technical label.

Think about every place your HubSpot data needs to travel. Your BI platform. Your data warehouse. Your custom automation layer. Your finance system. Every one of those connections previously required either a developer or a third-party connector tool with its own cost and maintenance overhead.

Key Takeaway

Service Keys reduce your dependency on expensive middleware tools. If you're currently paying for a connector just to pipe HubSpot data into a warehouse or BI platform, a Service Key may let you drop that tool entirely.

On the security side, this update should prompt a full audit of your existing private apps. Identify which ones are still active, what permissions they hold, and whether they're tied to former employees. Migrate active ones to Service Keys and delete the rest.

If you're managing a complex HubSpot portal with multiple integrations, Service Keys also give you a single inventory view. Every key, its permissions, and its last activity in one screen. That's an audit win you didn't have before.

Worth noting: if you're assigning Developer Seats to unlock Service Keys, you'll want to understand how seat management works in your account. HubSpot recently made it easier to swap unassigned seats for credits or different seat types, which is covered in detail in the unassigned seats and HubSpot credits update.

If your stack includes NetSuite, pair this with the NetSuite Connector for Breeze Assistant update. Together, they move HubSpot much closer to a true data hub where humans can query and act on data from multiple systems without leaving a single interface.

Key Takeaway

Treat Service Keys as living infrastructure. Name them clearly, document their purpose, review permissions quarterly, and rotate them on a schedule. A key with stale permissions or a forgotten name is a security liability waiting to surface.

Who Should Care Most

This update is most valuable for the humans in these roles and situations:

  • Marketing operations managers who sync HubSpot data to Tableau, Looker, or Google Data Studio and are tired of routing requests through a dev backlog.
  • RevOps leads who own the integration layer between HubSpot and external systems and need a clean, auditable record of what's connected and why.
  • Sales analysts connecting pipeline data to Power BI or similar BI platforms who need fresh data without manual exports.
  • HubSpot admins at companies with high employee turnover who've inherited active private app tokens with unclear ownership.
  • Growing companies running HubSpot at any tier who want to build a tighter data stack without adding developer headcount.

This update is available to all hubs and all tiers. Whether you're on Starter or Enterprise, you can use Service Keys.

George's Take

I've seen this play out in portal after portal: a really capable RevOps or marketing ops professional gets within arm's reach of a reporting win, then hits a wall because API access required a developer. Service Keys remove that wall. And the security architecture here is genuinely smart. Scoped permissions, activity logging, seven-day rotation windows, account-level ownership. This isn't just a convenience feature. It's a signal that HubSpot wants humans who run operations to own the full integration layer, not just the front-end settings. If you've got legacy private apps in your portal right now, I'd schedule an audit this week. Not next month. This week.

“Service Keys aren't a developer feature with a friendlier UI. They're an ops feature built on a developer foundation, and that distinction matters for every RevOps team trying to own their data stack.”
— George B. Thomas

If you're thinking about how Service Keys fit into a broader integration architecture, especially if Salesforce is in your stack, read our breakdown of the HubSpot Salesforce integration rebuild for the full picture of where HubSpot's data connectivity is heading.

If you want help auditing your existing private apps, migrating to Service Keys, or building a smarter integration layer across your HubSpot portal, our team at Sidekick Strategies is ready to dig in. Book a strategy call and let's map it out together.

Frequently Asked Questions

What are HubSpot Service Keys and what do they replace?

HubSpot Service Keys are account-level API credentials that let you connect external tools like Tableau and Power BI to HubSpot without writing code. They replace legacy private apps by moving authentication onto HubSpot's modern Developer Platform. Service Keys are scoped to specific data permissions and don't expire when employees leave your company.

Do I need a developer to create HubSpot Service Keys?

No. Service Keys are designed for marketing ops, RevOps, and data professionals who need API access without developer skills. You'll need a Developer Seat or the Developer tools access permission from your admin, but creating, managing, and rotating keys is done entirely through the HubSpot Settings UI with no code required.

Where do I find Service Keys in HubSpot?

Go to Settings, then Integrations, then Service Keys. From there you can create new keys, view activity logs, rename keys, rotate credentials, and delete keys you no longer need. You must have the Developer tools access permission or a Developer Seat assigned before this option appears in your Settings.

How do HubSpot Service Keys stay secure?

Service Keys use three security layers: scoped permissions so each key only accesses the data it needs, activity logging so every API call is auditable, and key rotation with a seven-day grace period so you can update integrations before the old key expires. Keys are account-level, not tied to individual employees, so departures don't create orphaned access tokens.

What external tools can I connect using HubSpot Service Keys?

Any tool that accepts an API key for authentication. Common examples include Tableau, Power BI, data warehouses like BigQuery or Snowflake, and custom automation services. If your tool has an API credentials field, a HubSpot Service Key can fill it. HubSpot's developer documentation covers the technical details of how to authenticate with each type of integration.

Should I migrate my existing HubSpot private apps to Service Keys?

Yes, and sooner rather than later. Start by auditing your current private apps in Settings: check what permissions each holds, whether the creating employee still works at your company, and whether the integration is still active. Migrate live integrations to Service Keys and delete inactive ones. This reduces your security exposure and moves you onto infrastructure HubSpot is actively maintaining.

Comments

Join the conversation. Share what resonated, ask questions, or add your perspective.

Leave a Comment

We'd love to hear your thoughts. Your comment will appear after review.

Never shared publicly.

0/2,000

Ready To Talk?

Need Help Making Sense of HubSpot?

Sidekick Strategies helps your humans get the most out of every HubSpot update, feature, and tool. Let's make your portal work harder for you.