<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=1198476139004771&amp;ev=PageView&amp;noscript=1">

Build apps that respect individual user permissions with User-Level Apps

What is it?

User-Level Apps allow third-party developers to build project-based apps that act on behalf of a specific HubSpot user, rather than with broad, portal-wide access. When a user connects a User-Level App, the app's actions are evaluated against that user's own HubSpot permissions at runtime, including object-level access, field-level permissions, and role-based restrictions.

User-Level Apps are available to all developers building project-based apps on platform version 2026.09 and later.

 

Why does it matter?

Today, account-level apps receive access at install time and operate with the same permissions regardless of which user triggers the action. As apps take on more automated and AI-assisted workflows, this creates a gap: actions can be performed in ways that exceed what any individual user would be permitted to do directly.

User-Level Apps address this by scoping every app action to the connecting user's permissions. Admins can be confident that an app cannot exceed what a given user is authorized to do in HubSpot, and audit logs reflect the actual user behind each action.

 

How does it work?

To build a User-Level App, set isUserLevel: true in your app component configuration within your project. This opts the app into user-scoped authentication.

When a user connects the app via OAuth, they grant the app specific permissions. From that point, every action the app takes is evaluated against the intersection of the app's granted permissions and that user's CRM permissions, computed at the time the action occurs. This includes object-level access, field-level permissions, and role-based restrictions.

Actions taken through the app are attributed to the connecting user in HubSpot audit logs.

 

Who gets it?

Available to all developers building project-based apps on platform version 2026.09 and later.

What's not supported yet?

Refer to the developer documentation for the current list of supported APIs and platform capabilities.

Topics: Free (all hubs & tiers)

Related articles


Manage reports and dashboards programmatically with the new Reporting API
16 Sep 2026

Updates to HubSpot connector for Claude & remote MCP server
16 Sep 2026

Ready to maximize your business growth with our HubSpot-accredited services?

Contact us today to learn how we can help you succeed.