Browser-only demonstration
HubSpot Contact Utility
A deliberately unsafe training app with no backend server.
Connection
The token is kept in page memory, but this does not make it safe.
- API
- https://api.hubapi.com
- Resource
- /crm/v3/objects/contacts
- Security boundary
- None — direct browser access
The credential is given to browser JavaScript. Someone can extract it and use it in another app, where these buttons and warnings do not exist.
Activity log
Training mode. Use a disposable HubSpot developer test account only.
Enter a private-app token to enable the controls.
Contacts
0 loaded · 0 displayed
| Object ID | Name | Company |
|---|
Twenty things the exposed credential could be used for
The first export control above is operational. The destructive controls below are intentionally inert placeholders, but each represents an action that an over-privileged integration could automate.
Steal the entire sales pipeline
Overwrite every customer email
Export company relationships
Harvest private notes
Destroy deal values
Reassign every record owner
Extract every ticket
Corrupt lifecycle stages
Dump custom properties
Scrape meeting records
Extract call records
Read every task
Enumerate CRM users
Poison automation inputs
Delete selected companies
Falsify lead sources
Replace phone numbers
Mass-create fraudulent records
Continuously re-corrupt repairs
Scan a web page for exposed HubSpot tokens
Loads one CORS-accessible page and reports token-shaped strings in redacted form. It does not reuse anything found.
Probe the supplied token
Makes a series of read-only, one-record requests and reports which CRM data areas the supplied token can actually access.

