How installation normally works
What a forward deployed engineer does by hand today.
A public app installed into the customer's portal through an OAuth install link, or a private app for a single portal.
IntegrationsHubSpot
HubSpot is comparatively simple, which makes it a good early test of whether the destination model generalises without special cases.
Your AI, MCP server or API

Their workspace and approved access
Their entitled capabilities and version
Validation, health and the next action
Available today
Ready for customer deployments with customer-scoped authorization, validation and lifecycle management.
What a forward deployed engineer does by hand today.
A public app installed into the customer's portal through an OAuth install link, or a private app for a single portal.
The person whose calendar decides your go-live date.
A HubSpot super admin, or a user with app installation permission.
Whose identity the product acts as, and where that grant lives.
OAuth 2.0 per portal, with refresh tokens and portal-scoped access.
The repeatable half, turned into software.
The public app OAuth flow, resolving the portal id by introspecting the token because it is not in the token response, reading the scopes the install actually holds rather than the ones we asked for, and per-portal credential storage.
The half that is theirs and should stay theirs.
The portal, and which objects the app may touch.
How capabilities map onto what the platform will let you do.
Granular scopes per object type. Adding a scope to a published app requires existing customers to reinstall, which is a per-customer deployment event rather than a release.
What has to execute before anyone is told it works.
Reading a real object in the portal after install.
Rotation, expiry, revocation, and who notices first.
Refresh tokens per portal, rotated before expiry.
What happens to this customer when you ship version four.
App versions are global; installed scopes are per portal. Those diverge the moment you add a scope.
What actually goes wrong, named rather than generalised.
Scope changes requiring reinstall across the whole customer base. Portal-level API limits shared with everything else the customer runs.
How you learn it broke without the customer telling you.
Health compares the scopes this installation holds against what the current package needs. HubSpot does not extend existing installs when an app adds a scope, so an older customer shows as needing a reinstall instead of the capability silently failing for them.
Ready for customer deployments with customer-scoped authorization, validation and lifecycle management.
Available for customer deployments, with customer-scoped authorization, validation and lifecycle management.
Connect a source, approve what ships and send your customer an install link. 2 customer environments free. No card required.