
Security News
The Next Open Source Security Race: Triage at Machine Speed
Claude Opus 4.6 has uncovered more than 500 open source vulnerabilities, raising new considerations for disclosure, triage, and patching at scale.
@hubspot/cli
Advanced tools
A CLI for HubSpot developers to enable local development and automation. Learn more about building on HubSpot.
For more information on using these tools, see Local Development Tooling: Getting Started
npm install -g @hubspot/cli
Once the @hubspot/cli has been added to a project, a config file named hubspot.config.yml will also be needed. It is recommended that the config file is kept in your $HOME directory.
cd ~
hs init
You can set up command autocompletion by running
hs completion
and copying the output to either your .bashrc or .zshrc, and then sourcing that file source ~/.bashrc source ~/.zshrc or restarting your terminal.
A full breakdown of the commands can be found on the local development tools reference page.
Note: When @hubspot/cli is installed local to a project, the commands need to be prefixed with either yarn if using yarn or npx if using npm.
There are two ways that the tools can authenticate with HubSpot.
hs init or hs auth personalaccesskey and follow the instructionshs auth oauth2OAuth2 and follow the stepsNote: The Account ID used should be the Test Account ID (not the developer app ID). Client ID and Client Secret are from the developer app.
The CLI will exit with one of the following exit codes:
0: A successful run1: There was a config problem or an internal error2: There are warnings or validation issuesThe best way to stay up to date is to check out the Github Releases and also follow our developer changelog posts for an easier to read breakdown of major changes.
FAQs
The official CLI for developing on HubSpot
The npm package @hubspot/cli receives a total of 30,049 weekly downloads. As such, @hubspot/cli popularity was classified as popular.
We found that @hubspot/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 40 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Claude Opus 4.6 has uncovered more than 500 open source vulnerabilities, raising new considerations for disclosure, triage, and patching at scale.

Research
/Security News
Malicious dYdX client packages were published to npm and PyPI after a maintainer compromise, enabling wallet credential theft and remote code execution.

Security News
gem.coop is testing registry-level dependency cooldowns to limit exposure during the brief window when malicious gems are most likely to spread.