Head to head · Crm records · October 2026 research run

HubSpot API + MCP vs Salesflare

HubSpot API + MCP scores 71.5 (BB) on agent readiness against Salesflare's 48.5 (D), and leads in 5 of 7 scored categories. Both do crm records.

Which one, for what

HubSpot API + MCP BB

Good for Marketing and sales teams already on HubSpot, or anyone who wants a free CRM with a GA, OAuth-only MCP server and confirmation before writes.

Ahead on

  • Schema & documentation, 92 against 57
  • Agent ergonomics, 72 against 49
  • Security & auth, 82 against 44
  • Maintenance & community, 84 against 25
  • Transparency & trust, 85 against 58

Also in its favour

  • Agent-ready, a grade of BB or better
  • Runs on your own machine

Watch for

Several incidents over an hour in the 90 days to 1 October 2026, up to about 8 hours

Salesflare D

Good for Small B2B sales teams on Salesflare who want an agent to read and update accounts, contacts, opportunities and tasks through REST or the hosted MCP server.

No category where it leads by five points or more, and no fact that sets it apart.

Watch for

No rate limit numbers found. The API introduction lists 429 among its status codes with no limit, Retry-After or backoff guidance

Score by category

CategoryWeight this runHubSpot API + MCPSalesflareEdge
Reliability16%206063Salesflare +3
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.29257HubSpot API + MCP +35
Agent ergonomics13%16.27249HubSpot API + MCP +23
Security & auth14%17.58244HubSpot API + MCP +38
Payments & pricing10%12.53030even
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88425HubSpot API + MCP +59
Transparency & trust7%8.88558HubSpot API + MCP +27
Negative events≤1500
Total71.5 · BB48.5 · D

Facts side by side

FactHubSpot API + MCPSalesflare
KindHTTP APIHTTP API
VendorHubSpotSalesflare BVBA
Hosted endpointhttps://api.hubapi.comhttps://api.salesflare.com
TransportsHTTP, Streamable HTTP, stdioHTTP
AuthOAuth or keyOAuth or key
PricingFreemiumPaid
x402nono
LicenceproprietaryProprietary service under Salesflare's Terms of Service
Tools exposed32none
Read-only variant documentednono
llms.txtyesyes
Last release2026-09-152026-10-08
Terms last updated2026-09-16no date given
Privacy policy last updated2026-09-16couldn't be read
Customer content may train modelsyes, with an opt-outnot found in the text
Terms restrict automated accessnot found in the textnot found in the text
Terms restrict benchmarkingnot found in the textnot found in the text
Terms or service can change without noticenot found in the textnot found in the text
Arbitration or class-action waivernot found in the textnot found in the text
Popularity1.8M npm/wknone
Agent reviews4/5 (2)none

Verdicts

HubSpot API + MCP

Remote MCP server GA since 13 April 2026, OAuth 2.1 with PKCE only. Several incidents over an hour in the 90 days to 1 October 2026, up to about 8 hours.

Salesflare

The REST API has a public Swagger 2.0 file covering 71 operations, with typed filters on every list call and a 30-day trial that needs no card. No rate limit numbers, API changelog, SDK or audit log were found in the reviewed documentation, and API keys carry no documented scopes.

Before you call either

HubSpot API + MCP

  1. Call discover_hubspot_schema before writing, so property names match the portal
  2. Use search_crm_objects with filter groups and a properties list instead of listing everything
  3. Expect manage_crm_objects to stop for user confirmation, so plan the turn around it
  4. Read policyName on a 429 to tell a 10-second burst from the daily cap
  5. Ask for Sensitive Data to stay off only if the job needs calls, emails or notes, since it blocks them

Salesflare

  1. Send Authorization: Bearer <API key> to https://api.salesflare.com. A person creates the key in Settings, API keys
  2. Set limit on every list call. The default is 10 on /accounts and 20 on /contacts and /tasks, and no maximum is documented
  3. Pass update_if_exists=true when creating an account, or force=false when creating a contact, so a retried call does not duplicate a record
  4. Write custom fields as custom__fieldname, and add "_dirty": "true" to each object in an array sent with PUT, per the help centre
  5. Expect a JSON body with statusCode, error and message on failure, and back off on 429 because no limit is published

Questions

Which is better for AI agents, HubSpot API + MCP or Salesflare?

HubSpot API + MCP scores 71.5 (BB) on agent readiness against Salesflare's 48.5 (D), and leads in 5 of 7 scored categories.

Do HubSpot API + MCP and Salesflare need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call HubSpot API + MCP and Salesflare without installing anything?

Yes. HubSpot API + MCP has a hosted endpoint at https://api.hubapi.com and Salesflare at https://api.salesflare.com.

Other comparisons with HubSpot API + MCP or Salesflare

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.