Package release

ocyan-plugin-hubspot

mandel/testing ยท Version 0.1.1rc1

Guarded MandelBlog HubSpot enquiry intake boundary

Metadata

author_email MandelBlog <[email protected]>
classifiers
  • Development Status :: 4 - Beta
  • Programming Language :: Python :: 3 :: Only
  • Programming Language :: Python :: 3.12
description_content_type text/markdown
license_expression LicenseRef-Proprietary
project_urls
  • Repository, https://git.mandelblog.com/mandel-plugins/ocyan.plugin.hubspot
requires_python <3.13,>=3.12

Release files

FileTest resultsHistory
ocyan_plugin_hubspot-0.1.1rc1-py3-none-any.whl
Size
8 KB
Type
Python Wheel
Python
3
ocyan_plugin_hubspot-0.1.1rc1.tar.gz
Size
13 KB
Type
Source

ocyan.plugin.hubspot

MandelBlog's guarded HubSpot CRM integration boundary.

This initial implementation contains a read-only legacy form-submission adapter and a guarded Enquiry intake service. It does not schedule itself and does not execute HubSpot mutations unless a caller explicitly invokes the canary/write path.

Scope

The form-submission endpoint is intentionally isolated in FormSubmissionAdapter because HubSpot currently exposes that read surface through the legacy Forms API. It is a compatibility adapter, not a reason to use legacy CRM object paths.

Configuration

Configuration is supplied by the host application or an approved secret-management mechanism. The package never reads or stores credentials in source control.

Required values:

The canary requires an explicit form ID and submission conversionId; it must not process arbitrary historical submissions.

Development

python3.12 -m unittest discover -s tests -v
python3.12 -m json.tool config.example.json >/dev/null

Production scheduling, deployment, and the real canary require separate approval.

API and safety contract

HubSpotClient targets the currently documented date-versioned CRM object paths:

It deliberately has no ambient write behaviour. A consumer must explicitly enable the approved canary path before the guarded intake service can update a Contact or create its one associated Task. Runtime credentials remain in the host's approved secret mechanism; API error text is redacted before it reaches callers.

Certification uses deterministic fake transports only. A live API smoke test is separately approved, opt-in operational work and is not needed to install, test, or certify this package.