A CRM becomes a developer problem the day someone asks you to sync it with the product database. From that point the API limit, the webhook format and the per-seat price stop being sales questions and turn into engineering constraints you will live with for years.
As of October 9, 2026, HubSpot's usage guidelines cap a privately distributed app at 100 requests per 10 seconds on Free and Starter and 190 on Professional and Enterprise, so writing 50,000 records one request at a time takes 83 or 44 minutes. Twenty's cloud pricing page lists 50 API calls per minute on its Pro plan, which turns the same job into 16.7 hours. The CRM you pick decides which of those numbers you get.
What We Compared
Every price, limit and license below comes from the vendor's own pricing page, API documentation or repository, checked on October 9, 2026, in US dollars. I compared the five on what a developer touches: API limits, webhooks, extensibility, self-hosting and license. I left out Pipedrive because its pricing page blocks automated requests and I could not verify its numbers, and I did not cover Salesforce or Zoho CRM at all.
What a 50,000-Record Sync Costs in Minutes
The measurement that separates these tools is not a feature list. It is how long your nightly sync takes at each vendor's published write limit. This script converts the limits into requests per second and divides a 50,000-record job by them, assuming one request per record and no batching:
jsconst limits = [ { name: "HubSpot Free/Starter", rps: 100 / 10 }, { name: "HubSpot Professional/Enterprise", rps: 190 / 10 }, { name: "Attio (all plans)", rps: 25 }, { name: "Twenty Cloud Pro", rps: 50 / 60 }, { name: "Twenty Cloud Organization", rps: 100 / 60 }, ] const records = 50_000 for (const { name, rps } of limits) { const minutes = records / rps / 60 const label = minutes >= 120 ? `${(minutes / 60).toFixed(1)} h` : `${minutes.toFixed(0)} min` console.log(`${name.padEnd(34)} ${rps.toFixed(2).padStart(6)} req/s ${label.padStart(8)}`) }
BashHubSpot Free/Starter 10.00 req/s 83 min HubSpot Professional/Enterprise 19.00 req/s 44 min Attio (all plans) 25.00 req/s 33 min Twenty Cloud Pro 0.83 req/s 16.7 h Twenty Cloud Organization 1.67 req/s 8.3 h
Two vendors are missing from that table on purpose. Close does not publish a single number: its documentation says limits are enforced per endpoint group, with an organization limit three times the per-key limit. EspoCRM is self-hosted, so the ceiling is your own server. And the Twenty figures are the caps its pricing page lists for the cloud plans; I did not check whether a self-hosted instance has one.
HubSpot: Limits Scale With the Tier
HubSpot is the baseline every other entry gets compared to, and its API is broad: REST endpoints, a GraphQL API, and webhooks that carry an HMAC SHA-256 signature, which the HubSpot webhook signature guide walks through. What changes with price is the headroom. Privately distributed apps get 100 requests per 10 seconds on Free and Starter and 190 on Professional and Enterprise, with a daily ceiling shared across the account of 250,000, 625,000 and 1,000,000 requests. An API limit increase add-on raises the burst by 250 per app and the daily cap by 1,000,000, up to two purchases.

What it does not do is make the developer-friendly parts cheap. HubSpot's CRM page lists custom objects under the Enterprise tier, and the Starter price carries an asterisk saying the discount applies to new customers only. It is also closed source with no self-hosted option.
Pricing: Free · Starter from $15 per seat per month (new-customer discount) · Professional from $50 · Enterprise from $75 (as of October 9, 2026)
Attio: Flexible Data Model, Per-Seat Pricing
Attio is a CRM built around a configurable data model, and it publishes the most plainly stated API limits of the group: 100 requests per second for reads and 25 for writes across the whole API, a 429 with a Retry-After header when you exceed them, and extra score-based limits on its List records and List entries endpoints, where each query gets a complexity score from its filters, sorts and record count. Its documentation covers a REST API, webhooks for real-time change notifications, an App SDK and an MCP server. BeBeez reported a $52 million Series B led by GV on August 26, 2025.

The limits that matter here are on the model, not the requests. Attio's pricing table caps objects at 3 on Free, 5 on Plus, 12 on Pro and unlimited on Enterprise, and seats at 3, 10 and then unlimited. I found no open-source edition or self-hosted option on its pricing page or in its docs.
Pricing: Free · Plus $44 per user per month ($35 billed annually) · Pro $99 ($79 annually) · Enterprise custom (as of October 9, 2026)

Twenty: Open Source With a Generated API
Twenty is the open-source entry, and its license needs reading before you build on it. The LICENSE file in the repository says the project is mostly AGPLv3, with certain files marked as a commercial Enterprise license and the CLI, SDKs and UI library under MIT. Some write-ups call Twenty simply MIT-licensed, which is wrong for the core. The repository showed 58,131 stars and a v2.45.0 release on October 5, 2026.

For developers, the draw is that the API is generated from your workspace schema: its documentation describes REST and GraphQL APIs, webhooks that fire an HTTP POST on every create, update or delete, and apps written as TypeScript packages. You can run it yourself with Docker Compose or use the managed cloud. The cost of the cloud is the rate limit: 50 API calls per minute on Pro and 100 on Organization, per its pricing page. Twenty raised a $5 million seed led by Runa Capital in November 2024, and it ships often, with v2.45.0 out on October 5, 2026.
Pricing: Pro $9 per user per month billed yearly · Organization $19 · Enterprise from $50,000 a year · self-hosted free under AGPLv3 (as of October 9, 2026)

Close: Calling and Email Built In
Close is a sales CRM where calling, email and SMS are part of the product rather than integrations, and its API access works with API keys or OAuth. Webhook subscriptions support JSON event filters, and the rate-limit documentation tells you what to do on a 429: pause for the number of seconds in the rate_reset value before retrying that endpoint. Limits are per endpoint group, so lightweight requests get a higher ceiling than resource-intensive ones, and most responses carry a ratelimit header showing the limit closest to being hit. Its pricing page lists custom fields (250 on every plan) and custom objects among its features.

Close has no free plan, only a free trial, and workflows are not included in its Solo and Essentials tiers. Calling is billed on usage on top of the seat price, and I found no self-hosted option on its pricing page.
Pricing: Solo $19 per user per month ($9 annually) · Essentials $49 ($35) · Growth $109 ($99) · Scale $149 ($139) (as of October 9, 2026)

EspoCRM: Self-Hosted With a Full REST API
EspoCRM is a conventional web CRM that you run on your own server, and it is the cheapest to adopt: AGPL-3.0, version 10.0.9 released September 29, 2026, and 3,467 GitHub stars on October 9, 2026. Its API documentation says the frontend is a single-page application that talks to the backend over the REST API, so everything you can do in the interface you can do with an API call.

The tradeoff is that you operate it: upgrades, backups and the database are yours, and no vendor rate limit applies because your server is the limit. I did not verify its hosted pricing or its webhook support, so check both before relying on them.
Pricing: Self-hosted $0 (AGPL-3.0) · hosted pricing not checked (as of October 9, 2026)
Side by Side
| Tool | Free plan | Entry paid price | Self-host | License | Published API limit |
|---|---|---|---|---|---|
| HubSpot | Yes | $15 per seat (new customers) | No | Proprietary | 100 to 190 per 10 s per app |
| Attio | Yes (3 seats) | $44 monthly, $35 annual | Not listed | Proprietary | 25 writes/s, 100 reads/s |
| Twenty | Trial or self-host | $9 billed yearly | Yes | AGPLv3 plus commercial files | 50 to 100 per min (cloud) |
| Close | No (trial) | $19 monthly, $9 annual | Not listed | Proprietary | Per endpoint group |
| EspoCRM | Self-host | $0 | Yes | AGPL-3.0 | None from the vendor |
How to Choose Without Migrating Twice
- Count your real writes. Put your nightly record count into the script above and read off the minutes. If a sync has to finish in a 30-minute window, that already rules out some rows.
- Find the tier that holds your object model. HubSpot lists custom objects under Enterprise, Attio caps objects at 12 on Pro, and Twenty lists unlimited custom objects on every cloud plan. Price the tier you need, not the entry tier.
- Read the license against how you will use it. AGPLv3 asks you to offer source to users of a modified version you run as a network service. If you only call the API, that is rarely an issue; if you patch the core, it is.
- Implement the retry contract once. HubSpot, Attio and Close all return
429, but Attio sends aRetry-Afterdate and Close sends arate_resetvalue, so wrap them behind one function. - Capture a week of real webhook traffic first. Verify each signature before you trust a payload, and inspect the raw events to see which fields you actually need.
Which One Should You Actually Use?
Already on HubSpot Free or Starter and hitting the burst limit: move up to Professional before you migrate anything. It raises the per-app burst from 100 to 190 per 10 seconds and the daily cap from 250,000 to 625,000 requests.
A startup building product-led workflows on its own data model: Attio, if 12 objects on Pro is enough and per-seat pricing fits your headcount.
You want to own the data and build on the CRM itself: Twenty if you want a generated REST and GraphQL API and TypeScript apps, and you accept the AGPL and commercial-file split. Self-host it if the cloud API caps are too low for your sync.
A conventional CRM on your own server with a REST API: EspoCRM, with the operations work that implies.
Phone-heavy outbound sales: Close, because calling is built in, but budget for usage-based calling on top of seats.
Conclusion
The expensive part of leaving HubSpot is rarely the data export. It is discovering after the move that your sync is three times slower, or that the object you need sits on a higher tier. Before you sign anything, ask each vendor one question: how many API writes per minute does my plan allow, in writing, and is that number for the cloud or for self-hosting?
Related DevToolLab Tools
- Webhook Receiver & Inspector - capture a CRM webhook and read the exact headers and body before you write a handler for it.
- HMAC Generator - recompute a webhook signature from the secret and payload to see why a request was rejected.
- CSV Validator - check a contact export for ragged rows and bad delimiters before you import it into a new CRM.
- JSONPath Tester - test the expression that pulls a field out of a nested CRM API response.
