Provisioning HubSpot with PingOne
HubSpot supports user data management through PingOne provisioning. By using the HubSpot connection in PingOne, you can synchronize users between HubSpot and PingOne.
Provisioning capabilities
The following table summarizes the inbound and outbound provisioning capabilities for each resource type:
| Resource | Capability | Description | Inbound | Outbound |
|---|---|---|---|---|
User |
Create |
Generates a new user record in the destination. |
Yes |
Yes |
Read |
Retrieves or polls user attributes for synchronization. |
Yes |
Yes |
|
Update |
Modifies existing attributes, such as |
Yes |
Yes |
|
Delete |
Deletes a user or temporarily suspends an account. |
Yes |
Yes |
|
Group |
Create |
Provisions a new group in the target application. |
No |
No |
Rename |
Updates the display name or identifier of an existing group. |
No |
No |
|
Delete |
Removes a group from the target application. |
No |
No |
|
Membership |
Add and remove |
Adds or removes users from groups. |
No |
No |
Before you begin
Make sure that you have:
-
A HubSpot account. Learn more in Set up your HubSpot account in the HubSpot documentation.
-
The following credentials from your HubSpot account:
-
Client Id
-
Client Secret
-
Refresh Token
-
-
Users created and assigned to a group specifically for HubSpot provisioning in PingOne. Learn more in Adding a user in PingOne and Managing groups.
Steps
-
Create a HubSpot connection:
-
In the PingOne admin console, go to Integrations > Provisioning.
-
Click and then click New Connection.
-
Click Select for Identity Store.
-
Click Select for the HubSpot connection, and click Next.
-
Enter a Name and Description for this provisioning connection.
-
Click Next.
-
In the Configure Authentication section, select OAUTH for the Authentication Method and enter the following::
Field Example Client ID
86c4cc4f-9f9e-4db9-abc5-f8b48a0b1372Client Secret
2e4e176d-48b3-4fe3-b82c-e878c151e32bRefresh Token
na2-b10d-8b23-4daa-86ba-8d84056dc470 -
Click Next.
-
In the User Actions section, select the following as needed:
Field Description Enable users creation
Creates a user in the target identity store when the user is created in the source identity store.
Enable users updation
Updates user attributes in the target identity store when the user is updated in the source identity store.
Enable users deprovision
Deprovisions a user in the target identity store when the user is deprovisioned in the source identity store. If you select Enable users deprovision, the following options appear:
-
Remove Action: To remove a user in the target identity store when the user is deleted in the source identity store, select Delete.
-
Deprovision on rule deletion: Deprovisions users if the associated provisioning rule is deleted.
-
-
Click Save.
-
To enable the connection, click the toggle at the top of the details panel to the right (blue).
You can disable the connection by clicking the toggle to the left (gray).
-
-
Create an inbound or outbound rule and select the existing HubSpot connection as the target or source. You can optionally add attribute mappings.
Use the following inbound mapping examples for the HubSpot rule configuration:
HubSpot PingOne Directory trueEnabledcityLocalitylastnameFamily NamefirstnameGiven NameemailUsernameUse the following outbound mapping examples for the HubSpot rule configuration:
PingOne Directory HubSpot UsernameemailFamily NamelastnameGiven NamefirstName
Validation
-
View the sync status to confirm users and groups are successfully provisioned to Hubspot and to check for errors.
-
Review sync summary examples to help interpret your results.
Hubspot directory attributes
The following table lists common Hubspot attributes that can be mapped for user provisioning:
| PingOne Attribute | Description |
|---|---|
|
The user email attribute used for synchronization and matching. |
|
The user’s given name. |
|
The user’s family name. |
|
The user’s locality or city value. |