← All guides
Desk

Connect HubSpot to your desk

HubSpot connects with one token from a private app you create in about two minutes. The token is read-only, works on every HubSpot plan including free, and is stored write-only: once saved, nothing in the browser can read it back.

Create the private app and copy its token

HubSpot: gear icon, Integrations, Private Apps, Create private app, two read scopes, then copy the pat- token
  1. In HubSpot, click the gear icon (top right) to open Settings.
  2. In the left menu: Integrations → Private Apps → press the create button. On the newest HubSpot (late 2025 on) the menu item is called Legacy apps instead, press Create legacy app and pick Private, the screens after that are the same. Name it, say, Ervona Desk.
  3. Open the Scopes tab and add exactly two: crm.objects.contacts.read and crm.lists.read. Both read-only, the desk can pull people from this token, never edit them.
  4. Press Create app, confirm, and copy the access token (it starts with pat-). HubSpot shows it in full only here.
  5. In Desk, under Bot accounts → Connect HubSpot, paste the token and press Connect.

On an older HubSpot account?

  1. If your Settings menu says "Account Setup": same place, older labels. Gear icon → Account Setup → IntegrationsPrivate Apps.
  2. If you found a page called "API key": that is HubSpot's old system, retired in 2022. Those keys no longer work anywhere, including here. Create a private app as above, it replaced the API key one for one.
  3. If Private Apps (or Legacy apps) is missing entirely: only a super admin can create these, and there is no permission that grants it to anyone else. Ask a super admin to create the app and hand you the token.

If Connect says no

  1. Token rejected: it was copied incompletely, or the app is missing one of the two scopes. Open the app, check the Scopes tab, and copy the token again from the Auth tab.
  2. It worked, then stopped: someone rotated the token in HubSpot (your app → Auth → Rotate). "Rotate and expire now" kills the old token on the spot; "Rotate and expire later" gives it seven more days. Either way, paste the new one in Desk.
  3. Lists do not show up: only saved lists appear, and only ones the desk can read with crm.lists.read. Active and static lists both work.