Field-by-field comparison
Compare the evidence before choosing an MCP.
Each signal stays separate, missing facts remain visible, and the column order follows your selection.
| Evidence field | Apify MCP ServerMCP100 Selected | HubSpot MCPMCP100 Selected |
|---|---|---|
| Task fit | ||
| Best for |
|
|
| Not ideal for |
|
|
| Avoid when |
|
|
| Provenance | ||
| Provenance details | Community implementation com.apify · Publisher source ↗ | First-party MCP HubSpot · Publisher source ↗ |
| Maintenance | ||
| Maintenance details | Repo: Aug 14, 2026 Package: Not documented | Repo: Not documented Package: Not documented |
| Popularity evidence | ||
| GitHub stars | 3,664 GitHub stars · checked 2026-08-14T18:46:26.000Z | Not documented |
| External adoption evidence |
| Not documented |
| Client coverage | ||
| Client coverage details | Claude Code✓ Streamable HTTP Claude Desktop✓ Streamable HTTP Codex✓ Streamable HTTP VS Code✓ Streamable HTTP Cursor✓ Streamable HTTP OpenCode✓ Streamable HTTP | Claude Code✓ Streamable HTTP Claude Desktop✓ Streamable HTTP Codex✓ Streamable HTTP VS Code✓ Streamable HTTP Cursor✓ Streamable HTTP OpenCode✓ Streamable HTTP |
| Client coverage note | Local stdio runs on your computer. Streamable HTTP connects to a remotely hosted MCP server. | |
| Access and data | ||
| Authentication | Hosted mode supports OAuth or Authorization Bearer APIFY_TOKEN; local stdio uses APIFY_TOKEN. Discovery tools can be unauthenticated, and agentic payment tokens are additional alternatives. | OAuth 2.1 with PKCE is required. A HubSpot MCP auth app supplies client ID, client secret, and registered redirect URL; the user selects an account and grants available permissions. |
| Cost | Actor and platform usage is chargeable according to Actor pricing; even free Actors incur platform usage. x402, Skyfire, and AGI payment paths are documented; no fixed MCP fee is stated. | HubSpot documents the remote MCP server as generally available to all HubSpot accounts without a separate MCP fee. HubSpot subscription features, API limits, integration hosting, and AI-client costs still apply. |
| Permissions | Dynamically exposes Apify Actors, including web, social, maps, and e-commerce scrapers, plus run, dataset, key-value-store, and documentation tools. call-actor executes external Actors. | Read access includes CRM records, activities, marketing content, campaigns, and organizational context. Write access includes supported contacts, companies, deals, tickets, line items, products, calls, emails, meetings, notes, and tasks. Every action respects the authenticated HubSpot user's permissions. |
| Data handling | Requests and Actor inputs are sent to Apify; run results can be stored in Apify datasets and key-value stores. Telemetry is enabled by default and stdio uses Sentry; detailed retention is not documented. | HubSpot's hosted MCP service relays authorized CRM and activity data to the MCP client. Sensitive Data accounts block activity objects through MCP. Client credentials, OAuth tokens, retrieved records, and tool results must be protected by the integrating application. |
| Limitations | ||
| Tradeoffs |
|
|
| Risk context | Actor execution can scrape external sites, process personal or regulated data, incur spend, and return untrusted content. Restrict tools, use scoped tokens, review Actor pricing and terms, and control telemetry and storage. | CRM and activity tools can expose personal and commercially sensitive data or create consequential customer records and communications. Use a dedicated auth app, narrow user permissions, secure PKCE and token storage, re-review scope changes, and confirm mutations. No MCP100 execution testing is claimed. |
| Evidence date | ||
| Editorial review | 2026-08-11 | 2026-07-24 |
| Candidate evidence | 2026-08-14T18:46:26.000Z | 2026-07-29T20:58:26.000Z |
Popularity, maintenance, fit, permissions, and client support are independent evidence fields.
Read the evidence method →