What HubSpot Breeze is in 2026, and which parts can touch money
"HubSpot Breeze" covers three different things, and they carry very different authority. Breeze Assistant is the in-app helper that drafts, summarizes and searches the CRM for the person using it. Breeze agents are the paid, autonomous workers: Customer Agent for support, Prospecting Agent for outbound, plus Data, Content and Knowledge Base agents. Breeze Intelligence is the enrichment layer. In July 2026 HubSpot moved the agents into a new home called Agent Hub and renamed Breeze Studio to Agent Builder, so you will see both names in the product and in older guides.
Most of what Breeze does never touches money. Answering a ticket, writing an email or filling a property is a content risk, not a financial one. The financial surface is narrower and easy to miss. HubSpot says Customer Agent can take action when a question needs it, such as order status through Shopify or changes in the CRM, within the rules you set. Agent Builder lets you give any agent agent tools, which are custom workflow actions that POST to a URL you control. And the HubSpot MCP server lets Claude, ChatGPT or your own agent read and write CRM commerce objects from outside HubSpot entirely.
That is where a buyer's money shows up: a quote with the wrong discount, an order line at the wrong price, a cart pushed to checkout, or an agent tool that calls your refund or purchasing API. We went looking for the control that limits the amount, and measured what HubSpot publishes.
How we measured the HubSpot MCP server
On 1 October 2026 we sent unauthenticated requests to mcp.hubspot.com with no account and no credentials, so anyone can repeat this in a terminal. Every probe was paired with a randomly generated control path, because some servers answer 200 to anything and look like they support every endpoint.
The root of mcp.hubspot.com answered a JSON-RPC initialize POST with 401 and a WWW-Authenticate: Bearer resource_metadata header pointing at /.well-known/oauth-protected-resource. That is the behavior the current MCP authorization spec asks for, and fewer hosts in our series get it right than you would expect. The protected-resource document returned 200 and named mcp.hubspot.com as its own authorization server. The authorization-server document returned 200 with authorization code, refresh token and client credentials grants, PKCE S256, and a token introspection endpoint.
Two details stand out. Both documents publish scopes_supported as an empty list, so an MCP client cannot see in advance what it is asking for. And api.hubapi.com/.well-known/oauth-authorization-server returns the same MCP issuer, so HubSpot has pointed its main API host's discovery document at the MCP authorization server. The random control paths on the root and under /.well-known/ returned 404, and so did /mcp, so the server is not a catch-all.
157 HubSpot OAuth scopes, 29 about commerce, and not one about a limit
Because the MCP server does not list its scopes, we read the source of truth instead: HubSpot's public scopes reference for apps, last modified 15 September 2026. Its scope table lists 157 scopes. 64 grant write access. 29 relate to commerce, billing, currency or tax.
The commerce writes are concrete. An app or agent holding them can create and change carts, line_items, orders and quotes, move orders through pipelines with crm.pipelines.orders.write, and change the schemas of invoices and subscriptions. settings.billing.write lets it manage and assign paid seats. settings.currencies.write lets it change exchange rates.
We then searched all 157 names for limit, budget, spend, approv, amount, threshold and cap. Zero matches. HubSpot models money in detail, with commerce payments, invoices, subscriptions and tax rates, and it scopes access by object and by sensitivity tier. It does not scope by amount. A token that can write a quote can write a quote for any total.
One honest qualification. HubSpot's commerce payments API is read-only for live processing: its documentation says it cannot be used to create payments intended for payment processing, only to record payments made elsewhere. So a HubSpot token cannot charge a card on its own. What it can do is set the prices, discounts and quantities that a human or an automated checkout then charges, and mark invoices as paid. The MCP documentation also lists invoices and subscriptions among read-and-write objects, while the scope table offers only read scopes on those two object types, which is worth checking against your own install.
Agent tools and the TAKE_ACTION review step
HubSpot deserves credit for one control most platforms in our series lack. Every custom agent tool declares a toolType of GET_DATA, GENERATE or TAKE_ACTION, and for TAKE_ACTION the developer reference says that by default, this type of action requires users to review the output before approving the tool execution. A tool can also return an execution state of BLOCK with an expiry duration, which halts the workflow.
The limits of that control matter for anyone approving a rollout. The review is a per-execution yes or no, not a threshold, so it cannot say "approve automatically under 200 dollars and ask above that." It is a default, which means it can be relaxed as volume grows and the reviews become a bottleneck. The tool schema itself has no amount, budget or rate field; actionUrl, inputFields, outputFields and the LLM description are what HubSpot sees. And the feature is still marked beta. So the first time a team turns off review to let Customer Agent issue credits overnight, there is no dollar ceiling left anywhere in HubSpot.
That is also the architectural opening. Because an agent tool is a POST to a URL you control, the URL can be a policy service that checks the amount, the running total and the counterparty before it calls the system that moves the money, and returns BLOCK when the answer is no.
HubSpot Credits caps the AI bill, not the money agents move
HubSpot does have spending controls, and they are good ones. They govern a different bill. HubSpot Credits cost 0.01 dollars each, sold in capacity packs of 1,000 for 10 dollars, or as pay-as-you-go overage at 0.010 dollars per credit invoiced in increments of 10. Seat-based Smart CRM and Hub subscriptions include 500 credits a month on Starter, 3,000 on Professional and 5,000 on Enterprise. Customer Agent uses 50 credits (0.50 dollars) per resolved conversation, Prospecting Agent 100 credits (1 dollar) per lead it recommends for outreach, and Data Agent 10 credits per prompt per record.
Once you have bought additional credits, HubSpot lets you set a maximum monthly credit limit for the account, and feature-level limits for individual agents. Per HubSpot's knowledge base, updated 9 September 2026, when usage reaches the account limit any feature requiring credits will be paused until the next monthly cycle. Watch one default: once you have purchased additional credits, going over the limit auto-upgrades you to a higher credit pack for the rest of your term unless you switch overage to pay-as-you-go.
None of that touches the quote, the order or the refund. A Customer Agent that resolves 2,000 conversations costs 1,000 dollars in credits whether each conversation ended with a password reset or a 400 dollar goodwill credit. The credit limit stops the agent from running up HubSpot's invoice. It cannot see yours.
A rollout checklist for HubSpot agents that touch commerce
- List every agent and integration holding a commerce write scope. Carts, line items, orders, quotes and order pipelines are the ones that change what a customer is charged. Remove them from any app that only needs to read.
- Keep TAKE_ACTION review on for every agent tool that creates a credit, refund, discount or purchase, and read a few weeks of decisions before you relax it for any band.
- Point money-moving agent tools at a policy service, not straight at Stripe, Shopify or your purchasing API, so the amount is checked outside the language model.
- Set a per-action ceiling and a daily and monthly total per agent, not just per tool, so two tools cannot add up past your budget.
- Set HubSpot's account credit limit and switch overage to pay-as-you-go if you do not want an automatic pack upgrade.
- Reconcile monthly per agent. Put the credit bill and the money each agent moved side by side so cost per outcome includes both.
How AgentsPay fits alongside HubSpot Breeze
AgentsPay does not replace HubSpot, HubSpot Payments or your processor. It sits between the agent tool and the money. Your TAKE_ACTION tool posts to AgentsPay instead of calling the refund, credit or purchase endpoint directly, and AgentsPay applies the policy you set for that agent: a per-transaction ceiling, a daily and monthly budget, a merchant or counterparty allowlist, and an approval threshold that sends anything above it to a named person for a one-tap decision. Below the threshold it goes through without a human in the loop, which is exactly the threshold HubSpot's review step cannot express. The agent's credentials cannot change that policy.
Every decision lands in an audit trail tied to the agent and the HubSpot record, and when an agent needs to buy something itself it can be issued a scoped virtual card on your own issuer. See how AI agent spend controls and approval thresholds work, or compare the same measurement for Salesforce Agentforce, Zendesk AI agents and Intercom Fin. If you are costing the agents first, our HubSpot Customer Agent pricing breakdown works the numbers.