What access you grant when connecting a CRM or app

Updated Markdown

Connecting HubSpot, Google Sheets, Salesforce or any other app opens that service's own secure sign-in popup. You log in and approve access there, not on a ListPlus screen — ListPlus never sees or asks for your password.

What access is granted#

The popup is run by the service you're connecting to (Google, HubSpot, Salesforce and so on) and lists exactly what it's about to share with ListPlus, such as reading your records or, for sources that support Sync Changes (Google Sheets, Airtable, HubSpot, Notion, Salesforce, Pipedrive), writing updates back. Review that screen before approving — it's the same consent screen that service shows for any third-party app, and the access ListPlus ends up with is exactly what you approve there.

A few apps, such as Lemlist or Phantombuster, ask for that app's API key in the popup instead of showing a consent screen; the key is held by the secure sign-in service, not by ListPlus.

Where the access is held#

The access you approve is held by the secure sign-in service, not by ListPlus. ListPlus stores no usernames or passwords for HubSpot, Google, Salesforce or any other connected app, on any plan — your password never passes through ListPlus; the access token is kept by the sign-in service and used only when someone imports, reloads, syncs, exports or sends through a pipeline with that account.

Shared in your workspace#

A connected account belongs to the workspace it was connected in, not only to you. The connect window says so: "You're connecting your login for this workspace – everyone on the team can use it, and actions run in your name." Every member of the workspace can use it for imports, Reload, exports and pipelines (Sync Changes: owner and admins only), and whatever they do with it happens under the login of the person who connected it. Any member can connect an account. Settings → Connected accounts lists all of them with "connected by (name)". Accounts connected in one workspace aren't available in your other workspaces.

Revoking access#

You can remove a connection two ways:

  • In ListPlus — open Settings → Connected accounts and click Disconnect on the account (or, in the New List flow, click the small delete icon on it). The workspace owner, an admin, or the person who connected the account can disconnect it.
  • In the connected service itself — from that service's own account or security settings, where it lists apps it has granted access to (for example, Google's "Third-party apps with account access"). Removing the entry for this connection there revokes the access immediately, even if you don't disconnect it in ListPlus first.

Either way stops ListPlus from being able to read from or, where enabled, write to that account; imports, sync and pipelines using it stop working until it's connected again. If you only revoke access in the service and leave the connection listed in ListPlus, the next import, reload or sync using it simply fails until you reconnect or remove it.

Related topics: connect-crm-and-sheets · sync-overview · pipelines-crm-slack-and-webhook · roles-and-permissions · subprocessors.

FAQ#

What exactly can ListPlus do with my account once I connect it?#

Only what you approve on that service's own consent screen when connecting — typically reading your records, and for sources that support Sync Changes (Google Sheets, Airtable, HubSpot, Notion, Salesforce, Pipedrive), writing updates back or creating records through a pipeline. ListPlus uses this access only when someone in your workspace imports, reloads, syncs, exports or sends a pipeline with it.

Do all connected apps use the same sign-in popup?#

Most do, but a few — such as Lemlist or Phantombuster — ask for that app's API key in the popup instead of showing a consent screen. The key itself is still held by the secure sign-in service, not by ListPlus.

Can I revoke ListPlus's access from inside Google or HubSpot?#

Yes — revoking access in the connected service takes effect immediately, regardless of whether the connection still shows in ListPlus. The next time ListPlus tries to use it, the action fails until you reconnect or remove it from ListPlus.

When does ListPlus actually use my connected account's access?#

Only when someone in your workspace triggers it — an import, Reload, Sync Changes, an export, or clicking Send in a pipeline. ListPlus doesn't access a connected account in the background or on a schedule.

Can other members of my workspace use an account I connected?#

Yes. A connected account belongs to the workspace, so every member can use it for imports, Reload, exports and pipelines (Sync Changes: owner and admins only), and those actions run under your login. It isn't available in your other workspaces; connect it there separately if needed.

Who can disconnect a connected account?#

The workspace owner, an admin, or the person who connected it, under Settings → Connected accounts → Disconnect. Imports, sync and pipelines using that account stop working until it's connected again.

Does disconnecting an account delete data I already imported with it?#

No — disconnecting only removes ListPlus's ongoing access to that account. Lists you already created or imported into with it stay exactly as they are; you just can't Reload, Sync Changes or send pipelines with that connection anymore until you reconnect.