If you're waiting for another AI agent announcement, this week's HubSpot news is a bit less flashy but arguably more important if you run anything custom on the platform. HubSpot has been steadily tightening how its API layer behaves, and three separate changes are converging in the same few weeks — one of which took effect on 8 September.
CRM API write validation is now enforced
From 8 September, HubSpot's 2026-09 API version enforces admin-configured validation rules on every CRM record creation or edit made through the API — not just changes made inside the HubSpot UI. In practice, that means required fields, restricted picklist values and other rules your admin set up to keep data clean now apply just as strictly to Zapier zaps, Make scenarios, custom code and any other integration writing to your CRM. Integrations that have quietly ignored those rules for years — because nobody was enforcing them at the API level — can start throwing validation errors or silently failing to write data. If you rely on any third-party tool to push data into HubSpot, this is worth testing in a sandbox account this week rather than finding out the hard way when a lead doesn't sync.
Private apps are being retired — meet Service Keys
HubSpot has also permanently switched off the ability to create new legacy, non-Project private apps through the UI, as of 27 August. If you or a developer built a custom integration a few years ago using the old private-app method, any new version of that kind of integration now needs to be built as a Service Key inside a Developer Platform Project (version 2026.09 or later). Existing legacy apps aren't being ripped out overnight, but any new build has to use the new method — and it's a good prompt to check who last touched your custom integrations and whether they're still supported.
Two sunset dates worth putting in the calendar
Two longer countdowns are also running. The original Pipelines API (v1) reaches end of life on 4 December 2026 — anything still calling those endpoints needs to move to the 2026-03 API version or newer before then, and this is a hard cutoff rather than a gentle deprecation. Separately, Node 18.x and 20.x are being phased out as supported runtimes for Chatflows custom code snippets, so any bot logic built on those versions needs a runtime bump before HubSpot drops support.
Why HubSpot is tightening the screws now
None of this is random housekeeping. HubSpot has spent this year pushing hard into AI agents that read and write CRM data on their own — Agent Hub, Breeze-powered workflows, and a growing marketplace of automations. The more things (human or AI) are writing to your CRM without a person double-checking each record, the more it matters that the platform actually enforces the data-quality rules an admin configured, rather than treating them as UI-only suggestions. Tightening API-level validation is HubSpot shoring up the foundation underneath all that automation.
What this actually means for your business
If your team only uses HubSpot's native marketing, sales and service tools day to day, none of this changes your experience directly. But if you've ever paid an agency or developer to build a custom integration, connected a form tool, data warehouse sync, or automation platform to HubSpot, or plan to lean more heavily on AI agents writing to your CRM, it's worth a short conversation with whoever built or manages that integration. Ask two questions: is it still on the legacy private app model, and does it write data in a way that respects your current validation rules? Getting ahead of both now is a lot cheaper than a broken sync discovered in a Monday-morning report.
Related services

Written by
Nic Franklin
Founder
Nic leads strategy across every Franklin account, connecting paid media, CRM and sales execution into one revenue system. He has spent over a decade building performance programs for Australian property, health and hospitality brands.






