getting started
Connect HubSpot
Private app token with the content and files scopes. We find your blog and authors.
Quibo publishes to the HubSpot CMS blog through the official v3 API. You create a private app in your HubSpot account, paste its access token into Quibo, and we discover your blogs and blog authors automatically. Every article lands as a published post in the blog you choose.
What you'll need
- A HubSpot account with a blog (Content, Blog) and at least one blog author.
- Permission to create private apps (super admin or the "Private apps" permission).
- A private app access token with the CMS
contentscope and thefilesscope.
Create the private app
- In HubSpot open Settings (gear icon, top right).
- In the left sidebar go to Integrations, then Private apps.
- Click Create a private app.
- On the Basic info tab name it
Quibo(the logo and description are optional). - Open the Scopes tab and add:
- CMS:
content(read and write). This covers blog posts, blog authors and blog settings. - Files:
files. Used to upload the cover image to your file manager.
- CMS:
- Click Create app, confirm, then click Show token and copy it. The token starts with
pat-and is shown once; you can view it again later from the app's Auth tab.
Only these two scopes are needed. Do not grant contacts, deals or marketing scopes to this app: Quibo never asks for them.
Blog ID (optional)
Leave this empty if you have one blog: Quibo uses the first blog of the account. If you run several blogs (for example one per language), pick the right one:
- Go to Settings, Content, Blog.
- Open the General tab and choose the blog from the dropdown at the top.
- The blog id (HubSpot also calls it the content group id) is the long number in the page URL.
To switch blog later, open the site page, Update credentials, and enter the new Blog ID with the token.
Blog author ID (optional)
HubSpot requires a blog author on every published post. Quibo resolves it in this order: the Default author you pick in the brand profile (populated from the authors we discover in your account), then the author id pasted here, then the first author of the account. Paste an id here if you want a fixed fallback:
- Go to Content, Blog, then the Blog authors tab.
- Open the author: the id is the long number in the URL.
If the account has no blog author yet, create one first (a name is enough). Publishing fails with a clear message otherwise.
Plug it into Quibo
From Sites, then Connect a site pick HubSpot and fill in:
- Site name (for example Acme blog)
- Site URL: the public URL of your blog. Used to extract your brand voice.
- Output language
- Private app access token
- Blog ID (optional)
- Blog author ID (optional)
Click Connect site. Quibo verifies the token against HubSpot before saving anything: if the check fails, nothing is stored and the error is shown in the wizard. Test connection on the site page stays available to re-check it later.
Auto-discovery
When you connect, Quibo calls GET /cms/v3/blog-settings/settings and GET /cms/v3/blogs/authors and learns:
- Blogs: every blog of the account, with name, slug and public URL. The one you named (or the first one) becomes the target.
- Blog authors: id and display name of every author, so the Default author dropdown in the brand profile is populated automatically. Pick one and click Save brand profile.
Discovery runs again once a day, or whenever you click Re-crawl brand on the site page.
What we publish
For each article Quibo creates a post with POST /cms/v3/blogs/posts and then publishes it with POST /cms/v3/blogs/posts/schedule:
nameandslug: the article title and slugpostBody: HTML rendered from the article (headings, lists, images, FAQ)postSummaryandmetaDescription: the meta description (derived from the body when the article has none, since HubSpot refuses to publish without one)htmlTitle: the SEO title (falls back to the article title)featuredImageandfeaturedImageAltText: the cover, uploaded to the/quibofolder of your file manager with the AI Act marking embedded. If the token lacks thefilesscope, the post is published with the original image URL instead.headHtml: the JSON-LD structured data in a<script type="application/ld+json">taglanguage: the article languagecontentGroupIdandblogAuthorId: the blog and author resolved as described above
Content refreshes update the same post in place (PATCH /cms/v3/blogs/posts/{id}) and keep the original slug, URL and publish date.
Test the connection
In Sites, then your site click Test connection: we call GET /cms/v3/blog-settings/settings to verify the token and the content scope. A 401 means the token is wrong or was rotated; a 403 means the scope is missing.
Security
- The access token is encrypted at rest.
- It is never returned to the browser, never logged, never sent to a third party.
- Revoke it any time from Settings, Integrations, Private apps: open the app and delete it, or rotate the token from the Auth tab. Then open the site page in Quibo, use Update credentials in the Credentials card, and the new values are verified against your CMS before they replace the old ones.