What Oleria discovers
User accounts, profile attributes, and role hierarchy synced from HubSpot’s account directory. Oleria uses this data for dormant account detection and access reviews, refreshed on HubSpot’s standard sync schedule.Prerequisites
- Admin access in HubSpot with permission to create a private app.
- Admin access on the Oleria platform to add a new integration.
The exact location of these settings can change over time. If the steps below don’t match what you see, refer to HubSpot’s own API documentation.
Get your SCIM credentials from HubSpot
1
Create a private app in HubSpot
Sign in to HubSpot as an admin, go to Settings → Integrations → Private Apps, and create a private app with read scopes for CRM contacts and user management.
2
Copy your SCIM Base URL and Authentication token
Copy the app’s access token, then note both values before you leave the page - you’ll paste them into Oleria in the next section:
- SCIM Base URL - the HTTPS API endpoint for your HubSpot account.
- Authentication token - the private app’s access token.
Copy the token now. Many applications display it only once. Store it securely and rotate it per your organization’s security policy.
Connect HubSpot to Oleria
1
Open the integration
Go to your Oleria workspace, select Integrations, then select the HubSpot tile.
2
Complete the connection form
Select Continue and fill in the connection form:
3
Save the integration
Select Connect to validate the credentials and save the integration.
Verify the integration
Confirm the new instance appears in your Oleria workspace under Connected Integrations with a status of Healthy. Oleria syncs users from HubSpot on the standard SCIM provisioning schedule once the initial sync completes.If HubSpot rotates your access token, update the Authentication token in Oleria by editing the integration.
Governance actions
Oleria can also invoke lifecycle actions in HubSpot when the token you provide has write access:- Enable or disable a user account
- Create a new user
Many teams start with a read-only token for visibility, then grant write access once they’re ready to automate remediation in HubSpot.

