Account Service Keys

Tuesday, September 29, 2026

Developer PlatformFreeStarterProfessionalEnterpriseLive

What it is

Service Keys provide a simplified authentication solution for customers who need API access without the complexity of full app development. This replaces legacy private apps by rebuilding them on the modern Developer Platform infrastructure.

Why it matters

Connecting HubSpot to external tools like data warehouses, BI platforms, or automation services should be simple, but it used to require developer workflows not built for everyday users. Now ops, analysts, and RevOps can create secure API credentials themselves: connect to tools like Tableau, Power BI, and data warehouses in minutes; keep scoped access to only the data integrations need; keep integrations running with keys that don't expire when employees leave; and stay in control with activity logging and easy key rotation.

The Take

Ryan Ginsberg

Why are there so many different kinds of keys? There is really only one key; HubSpot is going through a transition. The best guess at the problem is that these things were always reserved for technical-minded folks, developed by technical people and not for the non-technical. AI has enabled far more people to reach them, so now the platform has to think about usability and how the public benefits, and there is something of an identity crisis in the middle of that: non-technical, non-developer use cases for access keys, service keys and OAuth flows. Under the hood each one also carries its own infrastructure requirements and security protocols, managed separately, which is why the nuances of how each authenticates against a third-party service do not collapse into one.

Where they sit today: a personal access key comes with a fixed set of scopes you cannot add to or remove, so it is the ready-made, least-risk option for most folks. The developer API key is a templated key for development. Service keys are where the real work happens, and they replace legacy private apps for anyone who wanted to do whatever the API allowed. New scopes keep landing there; knowledge base, memberships and tickets all showed up recently. The pain is that CLI, MCP and the HubSpot connector for Claude each have their own scope list, each with a checkbox per scope. With great power comes great responsibility, but the day everyone is looking forward to, probably next year, is the one where that complexity comes out of human hands. Nobody wants humans clicking all those checkboxes.

Watch Us Discuss This

The full segment from the show, us working through this update start to finish.

Account service keys: why are there so many kinds of keys?8:24

Produced by Value-First Media