HubSpot: 403 "MISSING_SCOPES" errors
A 403 from HubSpot with the category MISSING_SCOPES means the connection's HubSpot authorization doesn't include a permission (scope) that the request needs. It usually shows up on the Proxy API, or on a newer Unified API resource such as lists, while everything else on the connection works.
HubSpot returns two versions of this error, and they need different fixes.
"This app hasn't been granted all required scopes"
{
"category": "MISSING_SCOPES",
"message": "This app hasn't been granted all required scopes to make this call. …",
"errors": [{ "context": { "requiredGranularScopes": ["crm.objects.quotes.read", "…"] } }]
}
HubSpot tells you which scopes would allow the call in requiredGranularScopes. To fix it:
Add the scope to the scopes Apideck requests. Apideck requests the scope list shown on the HubSpot connector settings page. If you've overridden that list, add the missing scope to your override.
If you use your own HubSpot app, add the same scope to your app in HubSpot. The scopes on your app must exactly match what Apideck requests, or authorization fails.
Ask the consumer to re-authorize the HubSpot connection in Vault. Changing scopes doesn't affect connections that were already authorized: HubSpot only grants the new scope on a fresh authorization.
Lists: for /crm/lists, the list scopes (crm.lists.read, crm.lists.write) are part of Apideck's default HubSpot scopes. If lists return this error, the connection was most likely authorized with a custom scope list that leaves them out, or before your scope settings included them. Add them and re-authorize as above.
"The scope needed for this API call isn't available for public use"
{
"category": "MISSING_SCOPES",
"message": "The scope needed for this API call isn't available for public use. …"
}
This one can't be fixed by adding scopes or re-authorizing. HubSpot doesn't make this endpoint available to public apps like the one Apideck connects through. Check HubSpot's API documentation for an alternative endpoint that is available to public apps.
Related
Contact Apideck support through the Customer Portal (the Requests link at the top of this help center), your Slack channel with us, or support@apideck.com if you're still stuck.
