Grok Bot for HubSpot Service Hub: Set It Up Safely
Want a Grok Bot working your HubSpot Service Hub tickets? Connect HubSpot to Carly, add the Carly connector to Grok Bot once, and every Bot works your Service Hub inbox through one account-aware connection with approval rules in front of customer replies.
The route most support leads try first is Cursor’s HubSpot plugin. It reads tickets well enough, but it cannot answer a customer conversation, it needs an admin to build an app before anyone connects, and its cloud sign-in (the side Grok Bot runs on) has been failing since August.
The quick answer: put HubSpot and your support mailbox in Carly, then point Grok Bot at Carly.
1. Connect HubSpot to Carly
- Sign in at carlyassistant.com.
- Open carlyassistant.com/integrations, find HubSpot, click Connect.
- Authorize the HubSpot account that holds your Service Hub.
- On the same page, connect the mailbox your customers write to: find Gmail or Outlook, click Connect.
Carly connects to thousands of apps, so if part of your queue still lives in Zendesk or Intercom, connect those here too, along with Slack for escalations and Google Calendar or Outlook Calendar for callbacks. The HubSpot integration page lists what Carly can do inside HubSpot.
2. Add Carly to Grok Bot
- Select Plugins in the Grok Bot sidebar, or tap your avatar and choose Plugins on mobile.
- Add Carly’s remote MCP server,
https://carlyassistant.com/mcp/. - Finish the authorization in the browser tab that opens. If it sits on Waiting for authorization, use Reopen.
- Sign in to the Carly account holding your HubSpot connection.
- Confirm Carly appears under Installed.
No client ID, no client secret, no redirect URLs to register in HubSpot. The HubSpot login lives in Carly, so it does not ride along in the shared browser every Bot can open.
What one Bot can do afterwards
- Triage the queue. Read new tickets and inbound email, tag by topic and urgency, and assign by rule (“billing goes to Emily, bugs go to Josh”).
- Reply from a real support address. Draft and send answers from support@ through your connected Gmail or Outlook, threaded under the customer’s original message.
- Keep the record honest. Update the ticket and the deal behind it, add notes, log the call, and mark what is resolved.
- Log the customer. Create or update the contact and company so the next agent sees the history.
- Escalate by rule. Anything mentioning a refund, a cancellation, or a named enterprise account goes to Slack with a summary instead of an auto-reply.
- Send a daily digest. Open tickets by stage, oldest waiting customer, and what closed yesterday, emailed to the team at 8am.
Put a Require approval rule on customer-facing sends while you trust the Bot. Carly holds the reply until you approve it, which is the preview a Grok Bot routine does not give you. You can also build the same triage as a standing workflow in plain English that runs without a Bot open, or give it to a named Carly agent with its own email address that you CC on hard threads.
The HubSpot plugin, and where it stops
Grok Bot reaches HubSpot through Cursor’s plugin marketplace. The HubSpot plugin is a thin wrapper around HubSpot’s official remote MCP server, and its README describes it as working with CRM records, activities, conversations and marketing email drafts “in the signed-in HubSpot account.”
An admin has to build an app first. HubSpot’s remote server needs a dedicated MCP auth app. Someone with developer access creates it under Development, MCP Auth Apps, registers two redirect URLs, and pastes the client ID and secret into the plugin settings. Only then can anyone sign in.
Cloud sign-in has been broken since August. On Aug 10, 2026 a user reported on Cursor’s forum that HubSpot rejects the plugin’s login because Cursor sends a cursor:// redirect, which HubSpot’s auth apps do not accept. Cursor staff got it working locally after a full restart, but the cloud side stayed at Needs Authentication. A second team confirmed the same failure on Aug 18, and staff said on Sep 14 that the status was unchanged, with no fix date, advising users to keep cloud use paused for HubSpot. Grok Bot runs on a cloud computer.
It reads conversations but cannot answer them. HubSpot’s own documentation lists conversations (live chat, team email, WhatsApp, SMS) under read access only. Write access covers tickets, contacts and pipelines, not replies. A Bot can see the customer’s question and update the ticket, then someone still has to type the answer.
Sensitive Data blocks it entirely. If your HubSpot account has Sensitive Data turned on, HubSpot blocks activity data (calls, emails, meetings, notes, tasks) and conversation data through the MCP server. For a support team that is most of the job.
Help desk visibility is wide. HubSpot states that help desk conversations are visible to all users through the server. Inbox restrictions carry over; help desk has none.
One account, shared by every Bot. The plugin holds the signed-in user’s HubSpot permissions. Every Bot on your Grok Bot account shares one cloud computer with shared browser sessions and credentials, and SpaceXAI calls the separate screens “separate work surfaces, not separate security boundaries.” The Bot drafting a refund reply and the Bot cleaning up contacts have the same access.
No dry run. Grok Bot has Auto-review rules (“ask first before sending any external email”), but SpaceXAI calls Auto Review model-based and says an approval does not reverse work already done. Nothing previews what a routine will do before it runs.
The HubSpot plugin next to Carly
| Need | Grok Bot’s HubSpot plugin or shared browser | Carly connector |
|---|---|---|
| Setup | Admin builds an MCP auth app, sets client ID and secret | Click Connect, authorize |
| Works in Grok Bot’s cloud | Blocked by an open sign-in bug since Aug 10 | Yes |
| Read tickets and contacts | Yes | Yes |
| Reply to a customer | No, conversations are read-only | Yes, from your support address |
| Sensitive Data turned on | Activities and conversations blocked | Carly reads the mailbox your customers write to |
| Approval before a customer send | Model-based Auto Review | Require approval rules on the send itself |
| Zendesk or Intercom queue alongside | Intercom plugin only, separate login | Yes, same connection list |
| Keeps running on a schedule | Routines on the shared machine | Workflows and agents, with or without a Bot |
Carly offers free Zapier-style workflows; AI agents from $35/month.
Quick fixes
| Problem | Fix |
|---|---|
| HubSpot plugin shows Needs Authentication | Connect HubSpot in Carly instead; no auth app needed |
| ”redirect URL is invalid” from HubSpot | That is the open cursor:// bug, not your setup; route through Carly |
| Bot can see a chat but not answer it | Send the reply from your connected support mailbox through Carly |
| Activity data missing | Sensitive Data is on; Carly works from the mailbox and ticket instead |
| Replies going out before review | Add a Require approval rule for external email |
| Refunds need a human | Add an escalation rule that posts to Slack and holds the reply |
Frequently asked questions
Does Grok Bot have a HubSpot integration?
Through Cursor’s plugin marketplace, yes: a HubSpot plugin that wraps HubSpot’s remote MCP server. It needs an admin-built MCP auth app, and its cloud sign-in has been failing since Aug 10, 2026. Connecting HubSpot to Carly and adding the Carly connector avoids both.
Can Grok Bot reply to HubSpot help desk tickets?
Not through the HubSpot plugin. HubSpot’s server lists conversations as read-only, so a Bot can read a ticket’s thread but not answer it. With Carly, the Bot sends the reply from your connected support mailbox, and an approval rule can hold it for review first.
Is it safe to give Grok Bot my HubSpot login?
Every Bot on your account shares one cloud computer, including browser sessions and credentials, so whatever one Bot can reach, all of them can. Keeping the HubSpot connection in Carly means the login is not sitting in that shared browser, and approval rules sit in front of customer sends.
Does this work if our HubSpot account has Sensitive Data turned on?
The HubSpot plugin loses activity and conversation data when Sensitive Data is on. Carly works the queue from the support mailbox your customers write to and the ticket records, so the Bot still has the customer’s words. If your setup needs a closer look, book a call with the Carly team.
Can one Bot cover HubSpot, Zendesk and Intercom together?
Yes. Connect all of them to Carly and one Bot works across all of them, with each account kept separate. Get started.
Related: Grok Bot · Multiple Gmail accounts in Grok Bot · Multiple Outlook accounts in Grok Bot · HubSpot MCP · Claude and HubSpot
Ready to automate your busywork?
Carly schedules, researches, and briefs you—so you can focus on what matters.
See what people say
"Before Carly, I relied on a Calendly link, but the whole process felt impersonal and not very professional. Carly changed that by handling all the back-and-forth, so I'm no longer stuck in endless email threads trying to line up schedules.
Now Carly reaches out to candidates, shares my real-time availability, lets them pick a slot, then sends a Zoom link and drops it straight into my calendar. She sends reminders to both of us before each call, which has significantly reduced no-shows and last-minute confusion.
On top of scheduling, Carly acts like a full executive assistant, sending me my schedule the night before so I can prepare for each call. It reminds me of the old x.ai assistant, but Carly is noticeably smarter, faster, and better suited to my healthcare recruitment business."


