Read-only access
Howly connects with read-only OAuth 2.0 and never modifies anything in your, or a client’s, HubSpot portal.
Encrypted in transit
All data between HubSpot, Howly, and your browser is encrypted with TLS 1.2 or higher.
Revocable anytime
Revoke Howly’s access at any time from your HubSpot Connected Apps settings.
Official HubSpot app
Howly is an official HubSpot app and Technology Partner, built on HubSpot’s own OAuth and API standards.
Secure by design
Howly is built around HubSpot’s own OAuth and API standards. It connects with read-only access and never modifies your data, so you get full context on your workflows without any risk to your portal. You can see the listing on the HubSpot Marketplace.What Howly can access
Howly requests read-only access, and only what it needs to map and audit your automations:- Automation — your workflows, the core of what Howly maps.
- Contacts, companies, deals, and lists (read-only) — needed to resolve how workflows connect to each other, since enrollment and connections run through list membership and property conditions across these objects. Tickets are requested optionally, so portals without Service Hub can still connect.
How data is protected in transit
All data transmitted between HubSpot, Howly, and your browser is encrypted with TLS 1.2 or higher.AI-powered audits
Howly’s AI audit sends workflow structure to Anthropic’s Claude API to generate findings: workflow names, status, trigger types, action types, and action counts, along with portal-wide summary statistics. For very large portals, only the 150 most recently modified workflows are sent in full detail; the aggregate statistics are still based on your entire portal. No contact, deal, or ticket record data is ever included, only workflow structure. Audit results are cached for 24 hours to avoid rerunning the same analysis, then discarded.What Howly stores
The live structure of your workflows — names, triggers, actions, and connections — is cached in memory for up to two hours to keep the app responsive, then cleared. It is never written to a database table.
- Any note, purpose, or risk level you add to a workflow
- Any planned workflow you build in the workflow planner
- Your canvas layout and saved views
- Your HubSpot connection token, so you’re not reconnecting constantly
- A hashed version of any MCP access token you create — never the raw token

