SSolarc Labs
Buyer-intent answers

HubSpot · private apps · Service Keys

HubSpot Legacy Private-App Creation Sunset: Choose Service Key or Project App

A HubSpot-backed routing checklist for admins and integration teams deciding how to replace new legacy private-app creation before the September and October 2026 account cutoffs.

Primary query: HubSpot legacy private app creation disabled September 28 October 26 2026 Service Keys · Updated 2026-09-07

Direct answer

What should HubSpot teams use when legacy private-app creation is disabled in September and October 2026?

HubSpot says new legacy private-app creation is disabled on 28 September 2026 for accounts created on or after that date and on 26 October 2026 for older accounts. Existing legacy private apps continue to work. For new system-to-system integrations that do not need webhooks, HubSpot directs customers toward Service Keys; integrations that need webhooks should use the Projects-based app path instead. The migration decision therefore starts with the integration capability, not with blindly converting every existing private app.

Practical sequence

What to do next

  1. 01

    Classify the target account by creation date so the applicable 28 September or 26 October 2026 creation cutoff is clear.

  2. 02

    Inventory the integration’s purpose, required scopes, whether it is single-account or multi-account, and whether it requires webhooks.

  3. 03

    Route simple account-level system-to-system integrations without webhooks toward a Service Key and keep the scope set to the permissions actually required.

  4. 04

    Route integrations that require webhooks or broader app capabilities to the Projects-based app platform rather than assuming a Service Key can replace them.

  5. 05

    Record the chosen path, owner, credential-rotation plan and acceptance test before the relevant cutoff; leave existing working legacy private apps unchanged unless there is a separate reason to migrate them.

Decision facts

New-account cutoff

HubSpot disables legacy private-app creation on 28 September 2026 for accounts created on or after that date.

Existing-account cutoff

For accounts created before 28 September 2026, creation is disabled on 26 October 2026.

Capability split

Service Keys are intended for system-to-system integrations and do not support webhooks; webhook use requires an app path.

Boundaries

  • Existing legacy private apps are not automatically disabled by this creation sunset, so do not manufacture migration work where the current integration remains supported and fit for purpose.
  • Never paste live HubSpot Service Keys or private-app tokens into public tooling; credential creation and rotation belong inside the account’s approved admin workflow.

Primary sources

Free proof before paid workflow

Validate the job with a bounded proof path first.

Run the free HubSpot integration route preflight