Skip to main content

n8n CRM Automation for HubSpot, Pipedrive and Salesforce (2026)

Automate HubSpot, Pipedrive or Salesforce with n8n: credentials, triggers, lead capture without duplicates, deal alerts, stale-deal reports and API limits.

AI Automation Architect

Published
Jan 15, 2026
Updated
Sep 30, 2026
Reading time
12 min read
Quick answer

n8n has built-in app and trigger nodes for HubSpot, Pipedrive and Salesforce. Connect HubSpot with a service key or OAuth2, Pipedrive with an API token or OAuth2, and Salesforce with OAuth2 or JWT through an External Client App. Good first workflows are lead capture that updates existing records instead of creating duplicates, an alert when a deal is won, and a weekly report of deals that have gone quiet. Pace bulk jobs to each CRM's API limits and route failures to an error workflow.

Checked against n8n's HubSpot, Pipedrive and Salesforce node and credential docs, the node source code in n8n 2.41.4, and each vendor's API documentation on October 1, 2026. This update replaces the January 2026 version, whose case study, time savings, revenue figures, rate limits, star ratings and scoring rules we could not verify.

What n8n supports for each CRM

CRMApp node coversTrigger nodeAuthentication in n8n
HubSpotContacts (including create/update and search), contact lists, companies, deals, engagements, forms, ticketsWebhooks for company, contact, conversation, deal and ticket events, such as created, deleted or property changedService key (recommended) or OAuth2; the trigger needs a developer API key and app
PipedriveDeals, persons, organizations, leads, activities, notes, files, deal products, productsWebhooks for create, change or delete events on deals, persons, organizations, leads, activities, notes and moreAPI token or OAuth2
SalesforceAccounts, contacts, leads, opportunities, cases, tasks, attachments, custom objects, documents, flows, SOQL queries; upsert for accounts, contacts, leads, opportunities and custom objectsPolls for created or updated accounts, contacts, leads, opportunities, cases, tasks, users, attachments and custom objectsOAuth2 or JWT, through an External Client App

Sources: n8n's HubSpot, Pipedrive and Salesforce node docs, their trigger pages, and the Pipedrive Trigger source. All three app nodes can be connected to the AI Agent node as tools. When an operation is missing, use the HTTP Request node with Authentication set to Predefined Credential Type and pick the same CRM credential.

Connect your CRM

HubSpot

  • Service key (recommended by n8n): in HubSpot, go to Development > Keys > Service Keys, create a key with the scopes you need, and paste it into the n8n credential's App Token field. You need super admin or Developer tools access, and HubSpot lists service keys as a public beta.
  • OAuth2: on n8n Cloud, select Connect my account. Self-hosted instances need their own HubSpot app with n8n's OAuth Redirect URL.
  • Scopes to start with: crm.objects.contacts.read and .write, the same pair for companies and deals, crm.objects.owners.read, crm.lists.write, forms and tickets, plus the matching schema read scopes.
  • Trigger: the HubSpot Trigger needs a developer API key credential backed by a HubSpot developer app. HubSpot allows one webhook at a time for it, so publishing a second HubSpot Trigger workflow stops the first.

HubSpot's regular API keys are deprecated, and private apps created in the HubSpot UI are now legacy, per n8n's HubSpot credential guide.

Pipedrive

  • API token: copy Your personal API token from Personal preferences > API in Pipedrive. If you belong to several companies, switch to the right one first.
  • OAuth2: needs a Pipedrive developer sandbox account and a public app with n8n's OAuth Redirect URL as its callback. The Pipedrive Trigger requires the webhooks:full scope.
  • Protect the trigger: set Incoming Authentication to Basic Auth on the Pipedrive Trigger. n8n registers the username and password with Pipedrive and rejects calls without them.

Details in n8n's Pipedrive credential guide.

Salesforce

  • Check API access. Salesforce's REST API guide says API access is enabled by default in Enterprise, Performance, Unlimited and Developer editions, and Professional Edition can add it. Without it, requests fail with API_DISABLED_FOR_ORG. The connecting user also needs the API Enabled permission.
  • Create an External Client App. Salesforce is deprecating Connected Apps, and n8n's Salesforce credential guide recommends External Client Apps for new integrations.
  • OAuth2: set the app's callback to https://your-n8n-domain/rest/oauth2-credential/callback on self-hosted n8n or https://oauth.n8n.cloud/oauth2/callback on n8n Cloud, add the Full access and refresh_token, offline_access scopes, and choose Production or Sandbox as the Environment Type in n8n.
  • JWT: for server-to-server access, upload a certificate to the app, enable the JWT Bearer Flow, and give n8n the Consumer Key, username and private key.

Workflow 1: Capture leads without creating duplicates

Duplicates are the most common CRM automation mistake. Every lead-capture workflow should look up the person before creating anything. The shape is the same for all three CRMs: n8n Form Trigger or Webhook → If (email present) → Edit Fields (normalize) → CRM lookup or upsert → notify the owner.

  1. Trigger: an n8n Form Trigger for a hosted form, or a Webhook node your site or ads tool posts to. For a JSON POST, the Webhook node puts the payload under body.
  2. If: keep only items where {{ $json.body.email }} is not empty; send the rest to a review list.
  3. Edit Fields (Set): add an email field with the expression below, so "Ana@Example.com " and "ana@example.com" match.
{{ ($json.body.email || '').trim().toLowerCase() }}

Then write to the CRM:

CRMn8n step that avoids duplicates
HubSpotContact > Create/Update with Email set to the normalized email. It creates the contact or updates the one that already has that email.
PipedrivePerson > Search with Term set to the email, Exact Match on and Search Fields set to Email. If a person comes back, update it; if not, Person > Create. A Pipedrive lead must be linked to a person or an organization, so create the lead last with the person ID.
SalesforceLead > Upsert with Match Against set to an External ID field that stores the normalized email, or Lead > Get Many with a condition on Email before Create. Leads require Last Name and Company.

Finish with a Slack or email message to the lead owner, and set the workflow's error workflow so a failed CRM call alerts you instead of losing the lead; see our n8n error handling guide.

Workflow 2: Alert the team when a deal is won

This Pipedrive example posts to Slack the moment a deal's status changes to won:

  1. Pipedrive Trigger: Action Change, Entity Deal, Incoming Authentication Basic Auth.
  2. If: {{ $json.data.status }} is equal to won, and {{ $json.previous.status }} exists.
  3. Slack: send a message such as the one below.
Deal won: {{ $json.data.title }} ({{ $json.data.value }} {{ $json.data.currency }})

The second condition matters. Pipedrive's webhooks v2, which n8n's trigger registers by default, send the current deal under data and only the fields that changed under previous. Checking that previous.status exists makes the alert fire once, when the status flips, rather than on every later edit to a won deal. Pipedrive gives each delivery 10 seconds, retries 3 more times after 3, 30 and 150 seconds, and deletes a webhook with no successful deliveries for 3 consecutive days, so keep the workflow published and n8n online.

In HubSpot, the same idea uses the HubSpot Trigger's Deal > Property changed event on the deal stage property. In Salesforce, use the Salesforce Trigger's On Opportunity Updated event. The trigger returns only a few default opportunity fields, such as the ID, amount and probability (see getDefaultFields in the node's source), so fetch the record with a Salesforce node before checking StageName or IsWon. Because that trigger polls, alerts arrive on your polling interval rather than instantly.

Workflow 3: A weekly report of deals that have gone quiet

A Schedule Trigger every Monday, one query, and one Slack message. In Salesforce, use the node's Search resource to run SOQL:

SELECT Id, Name, StageName, Amount, LastModifiedDate, Owner.Name
FROM Opportunity
WHERE IsClosed = false AND LastModifiedDate < LAST_N_DAYS:14
ORDER BY Amount DESC
LIMIT 50

Then turn the results into a single message with a Code node in Run Once for All Items mode:

// One Slack message listing every quiet deal
const lines = $input.all().map(({ json }) =>
  '- ' + json.Name + ' (' + json.StageName + ', ' + (json.Amount ?? 'no amount') + '), owner: ' + (json.Owner?.Name ?? 'unassigned')
);

return [{ json: { text: 'Open deals with no update in 14 days:\n' + lines.join('\n') } }];

Map {{ $json.text }} into a Slack node. In HubSpot, use Deal > Search deals with a filter on the last-modified date property; in Pipedrive, Deal > Get Many and an If node on update_time. If the query finds nothing, the workflow simply ends. Keep reports read-only: a report that also edits deals is harder to trust.

Stay inside each CRM's API limits

CRMPublished limits (October 2026)
HubSpotPrivately distributed apps: 100 requests per 10 seconds and 250,000 a day on Free and Starter; 190 per 10 seconds on Professional (625,000 a day) and Enterprise (1,000,000 a day). The CRM Search API has stricter limits.
PipedriveA daily token budget of 30,000 tokens x plan multiplier (Lite 1, Growth 2, Premium 5, Ultimate 7) x seats. A search costs 40 tokens and a list request 20. Burst limits per 2 seconds range from 20 requests (Lite, API token) to 480 (Ultimate, OAuth).
SalesforceAPI access depends on edition (see Connect your CRM above). Check your org's API request limits in Salesforce before running large syncs.

Sources: HubSpot's API usage guidelines and Pipedrive's rate limiting guide. When Pipedrive's daily budget runs out, requests return 429 until it resets at midnight in Pipedrive's server timezone. In n8n, pace bulk jobs with Loop Over Items and a Wait node, or the HTTP Request node's Batching option, and turn on Retry On Fail for brief 429s. Prefer search and single-record calls over pulling whole lists, and sync only what changed since the last run.

Avoid sync loops and bad data

  • Break loops. If n8n updates a record that also has a change trigger, the update fires the trigger again. Skip changes made by your integration user; Pipedrive's webhook meta block includes the user_id and a change_source.
  • Pick one source of truth per field. Two-way syncs where both systems can overwrite the same field end in flip-flopping values.
  • Store the other system's ID. A custom field holding the matching record ID makes updates exact and lookups cheap.
  • Ask before destructive steps. Put Slack's Send and Wait for Response or Gmail's approval operation in front of deletes and merges.
  • Use a dedicated integration user with only the permissions the workflows need. In Salesforce, the Integration user license limits integration users to API-only operations.

Let an AI agent work with your CRM

Because all three nodes work as AI Agent tools, an agent can look up a contact, summarize a deal's history or draft a follow-up note. Give it narrow tools: fix the resource and operation, let the model fill only specific fields with $fromAI(), prefer search and read operations, and keep an approval step in front of anything that writes. Our n8n AI integration guide covers the agent setup.

Next steps

Start with Workflow 1, since it protects the data every other workflow depends on, then add alerts and reports. For the building blocks, see our n8n tutorial for beginners, API integration guide, n8n email sequences and the n8n workflow library. If you would rather build your own AI product than build CRM automations for clients, AI SaaS Builder covers validating an idea, building it on Supabase, Next.js and the Claude API, launching it and charging with Stripe.

Operator program · recommended for this article

Want the full AI SaaS Builder playbook?

A 10-module, 52-lesson curriculum: validate an idea, build on Supabase and Next.js, add AI features with the Claude API, speed up with Claude Code and MCP, deploy on Vercel, launch, and charge with Stripe.

10 modules · one-time purchase · 30-day money-back guaranteeiimagined.ai by Anyro

n8n CRM automation FAQ

Does n8n integrate with HubSpot, Pipedrive and Salesforce?

Yes. n8n has a built-in app node and a trigger node for each. The HubSpot node covers contacts, companies, deals, engagements, forms and tickets; the Pipedrive node covers deals, persons, organizations, leads, activities, notes, files and products; the Salesforce node covers accounts, contacts, leads, opportunities, cases, tasks, custom objects, flows and SOQL queries.

Which HubSpot credential should I use in n8n?

For the HubSpot node, n8n recommends a HubSpot service key, pasted into the credential's App Token field, or OAuth2, which n8n Cloud connects with Connect my account. The HubSpot Trigger node needs a developer API key credential backed by a HubSpot developer app. HubSpot's old API keys are deprecated, and private apps created in the UI are now legacy.

Why can't n8n connect to my Salesforce org?

Check API access first. Salesforce enables it by default only in Enterprise, Performance, Unlimited and Developer editions; Professional needs an add-on, and other orgs return an API_DISABLED_FOR_ORG error. The connecting user also needs the API Enabled permission. On n8n Cloud, n8n's docs suggest enabling Approve Connected Apps for Non-Admins on the user's profile if the connection fails.

How do I stop n8n creating duplicate CRM contacts?

Normalize the email address, then look up before you create. HubSpot's Create/Update contact operation updates the existing contact with that email. In Pipedrive, search persons by email with Exact Match and update the match if one exists. In Salesforce, upsert against an External ID field, or check with a condition on Email before creating.

Is the n8n Salesforce Trigger real time?

No. It polls Salesforce on the interval you set and fetches records created or updated since the last check. Polling triggers only count as an n8n execution when they find new data. For instant events, have Salesforce call an n8n Webhook node instead.

Can n8n run when a Pipedrive deal changes stage or is won?

Yes. The Pipedrive Trigger with Action set to Change and Entity set to Deal receives Pipedrive's webhook for every deal update. The payload holds the deal under data and only the changed fields under previous, so an If node can check the new stage or status and ignore unrelated edits.

All-Access subscription

Every program. Member benefits.
One subscription.

Use all four premium programs with weekly live coaching, a private community, and the resource vault.

Confirm current lessons, downloadable resources and member-benefit arrangements before purchasing.

  • All 4 premium programs plus free Futures Trading
  • Weekly live coaching calls
  • Private community access
  • Resource vault and templates
  • 30-day money-back guarantee, cancel anytime
$99/ month
$99 for the first month · $702 to buy all four standalone
Start All-AccessOr browse standalone programs
30-day money-back guarantee · $99/month · cancel anytime