Package release
ocyan-plugin-hubspot
mandel/testing ยท Version 0.1.1rc1
Guarded MandelBlog HubSpot enquiry intake boundary
Metadata
| author_email | MandelBlog <[email protected]> |
|---|---|
| classifiers |
|
| description_content_type | text/markdown |
| license_expression | LicenseRef-Proprietary |
| metadata_version | 2.4 |
| project_urls |
|
| requires_python | <3.13,>=3.12 |
Release files
| File | Test results | History |
|---|---|---|
ocyan_plugin_hubspot-0.1.1rc1-py3-none-any.whl
|
|
|
ocyan_plugin_hubspot-0.1.1rc1.tar.gz
|
|
ocyan.plugin.hubspot
MandelBlog's guarded HubSpot CRM integration boundary.
This initial implementation contains a read-only legacy form-submission adapter and a guarded Enquiry intake service. It does not schedule itself and does not execute HubSpot mutations unless a caller explicitly invokes the canary/write path.
Scope
- Native HubSpot Enquiry form submissions.
- Current date-based Contact and Task APIs (
2026-03), verified against the current HubSpot developer reference. - Guarded lifecycle, lead-status, owner, and follow-up-task policy.
- Durable SQLite cursor/idempotency/dead-letter state.
- No Deals, Companies, native Leads, workflows, consent changes, marketing automation, or custom properties.
The form-submission endpoint is intentionally isolated in FormSubmissionAdapter
because HubSpot currently exposes that read surface through the legacy Forms API.
It is a compatibility adapter, not a reason to use legacy CRM object paths.
Configuration
Configuration is supplied by the host application or an approved secret-management mechanism. The package never reads or stores credentials in source control.
Required values:
- HubSpot account ID.
- HubSpot Service Key reference, resolved at runtime as
HUBSPOT_ACCESS_TOKEN. - Approved Enquiry form ID.
- Confirmed MandelBlog owner ID.
- SQLite state path outside the repository.
The canary requires an explicit form ID and submission conversionId; it must not process arbitrary historical submissions.
Development
python3.12 -m unittest discover -s tests -v
python3.12 -m json.tool config.example.json >/dev/null
Production scheduling, deployment, and the real canary require separate approval.
API and safety contract
HubSpotClient targets the currently documented date-versioned CRM object paths:
- Contacts:
/crm/objects/2026-03/contacts - Tasks:
/crm/objects/2026-03/tasks
It deliberately has no ambient write behaviour. A consumer must explicitly enable the approved canary path before the guarded intake service can update a Contact or create its one associated Task. Runtime credentials remain in the host's approved secret mechanism; API error text is redacted before it reaches callers.
Certification uses deterministic fake transports only. A live API smoke test is separately approved, opt-in operational work and is not needed to install, test, or certify this package.