Field-by-field comparison
Compare the evidence before choosing an MCP.
Each signal stays separate, missing facts remain visible, and the column order follows your selection.
| Evidence field | HubSpot MCPMCP100 Selected | Slack MCP ServerMCP100 Selected |
|---|---|---|
| Task fit | ||
| Best for |
|
|
| Not ideal for |
|
|
| Avoid when |
|
|
| Provenance | ||
| Provenance details | First-party MCP HubSpot · Publisher source ↗ | First-party MCP Slack · Publisher source ↗ |
| Maintenance | ||
| Maintenance details | Repo: Not documented Package: Not documented | Repo: Not documented Package: Not documented |
| Popularity evidence | ||
| Client coverage | ||
| Client coverage details | Claude Code✓ Streamable HTTP Claude Desktop✓ Streamable HTTP Codex✓ Streamable HTTP VS Code✓ Streamable HTTP Cursor✓ Streamable HTTP OpenCode✓ Streamable HTTP | Claude Code✓ Streamable HTTP Claude Desktop✓ Streamable HTTP Codex✓ Streamable HTTP VS Code✓ Streamable HTTP Cursor✓ Streamable HTTP OpenCode✓ Streamable HTTP |
| Client coverage note | Local stdio runs on your computer. Streamable HTTP connects to a remotely hosted MCP server. | |
| Access and data | ||
| Authentication | OAuth 2.1 with PKCE is required. A HubSpot MCP auth app supplies client ID, client secret, and registered redirect URL; the user selects an account and grants available permissions. | Slack uses confidential OAuth for MCP clients with a registered fixed Slack app ID and client secret. Cursor's publisher-documented integration uses Slack's fixed client ID and opens an OAuth workspace authorization flow. |
| Cost | HubSpot documents the remote MCP server as generally available to all HubSpot accounts without a separate MCP fee. HubSpot subscription features, API limits, integration hosting, and AI-client costs still apply. | Slack documents no separate MCP server fee. Access to history, search, apps, administration, and AI-client capabilities depends on the workspace's Slack plan; standard Slack API rate limits apply. |
| Permissions | Read access includes CRM records, activities, marketing content, campaigns, and organizational context. Write access includes supported contacts, companies, deals, tickets, line items, products, calls, emails, meetings, notes, and tasks. Every action respects the authenticated HubSpot user's permissions. | Slack maps tools to granular user-token scopes for public/private/DM search, files, channel history, messages, reactions, conversations, canvases, profiles, and member lists. Actions execute on behalf of the authenticated user and remain subject to workspace/app approval, Slack access controls, and IP allowlists. |
| Data handling | HubSpot's hosted MCP service relays authorized CRM and activity data to the MCP client. Sensitive Data accounts block activity objects through MCP. Client credentials, OAuth tokens, retrieved records, and tool results must be protected by the integrating application. | Searches, messages, channel history, file content, canvases, user profiles, and tool outputs flow through Slack's managed MCP endpoint to the configured client and its model provider. Slack audit logs can record MCP activity; client-side retention is governed separately. |
| Limitations | ||
| Tradeoffs |
|
|
| Risk context | CRM and activity tools can expose personal and commercially sensitive data or create consequential customer records and communications. Use a dedicated auth app, narrow user permissions, secure PKCE and token storage, re-review scope changes, and confirm mutations. No MCP100 execution testing is claimed. | Slack may contain private messages, credentials, customer data, files, and regulated communications. Request only required OAuth scopes, use an approved app, review the client/model retention policy, isolate other untrusted MCP sources, audit activity, and confirm every send/create/update action. This review does not claim MCP100 execution testing. |
| Evidence date | ||
| Editorial review | 2026-07-24 | 2026-07-24 |
| Candidate evidence | 2026-07-29T20:58:26.000Z | 2026-07-29T20:58:26.000Z |
Popularity, maintenance, fit, permissions, and client support are independent evidence fields.
Read the evidence method →