HelpSpot 5.8.7
Updated: 6 Oct 2026, 11:23 AM EDT
Release Date: 10/05/2026
Upgrade Note
HTTPS certificate verification: HelpSpot now verifies certificates for outbound HTTPS requests by default. Live Lookup and webhook integrations using self-signed or otherwise untrusted certificates may stop working after the upgrade. Use a trusted certificate wherever possible. If a temporary exception is necessary, administrators can add exact hostnames under Admin > Settings > System > TLS Verification Exceptions. Exceptions disable certificate checks for configured Live Lookup and webhook URLs on those hosts, including redirects, and increase the risk of interception. See System and Live Lookup or webhook stopped working after upgrading to HelpSpot 5.8.7.
New Features
- Load more detailed search results: Detailed search now includes a Load More control, so you can continue beyond the initial result limit. The result count reflects all matching requests. See Search.
- Permanently delete requests from the trash: Administrators with permission to manage the trash can select trashed requests and permanently delete them using a confirmation step. See SPAM & Trash.
- Configurable portal password reset expiry: Choose how long customer portal password reset links remain valid: 10 minutes, 30 minutes, 1 hour, 4 hours, or 24 hours. The default remains 10 minutes. Reset emails now use the HelpSpot language and state the configured expiry correctly. See Change how long customer portal password reset links stay valid.
- Database conversion for self-hosted installations: The
db:convert-enginecommand provides an experimental path to copy a current HelpSpot database into a new MySQL database, including conversions from SQL Server. It creates the destination schema, copies the data, and verifies the copy.
Improvements
- Larger request notes: Increased the note limit from 70,000 to 500,000 characters. Notes that exceed the limit now include a visible truncation notice, rather than silently losing the end of the content. See HelpSpot Limits.
- Announcement timestamps: Staff announcement banners now show when the announcement was posted, using the installation's date format and timezone. See Announcements.
- Clearer Microsoft mailbox reconnect guidance: When Microsoft authorization expires or is revoked, administrators receive a localized notification directing them to reconnect the mailbox. Repeated reports of the same authorization failure are reduced. See Troubleshooting O365 OAuth Mailboxes.
Bug Fixes
- Microsoft Graph reply threading: Outgoing replies sent through Microsoft Graph now preserve the reply headers needed to keep messages in the correct email conversation.
- Advanced Microsoft mailbox authentication: Mailbox checks now use refreshed access tokens, preventing expired tokens from interrupting mail import. Failed refresh attempts do not overwrite stored credentials, and connection tests no longer change mailbox health status.
- Duplicate emails with inline attachments: Corrected duplicate detection for incoming messages containing inline attachments, so changing internal image identifiers no longer lets duplicate messages bypass loop detection. See New Request Loop Protection.
- Recurring requests with missing attachments: Recurring requests now skip missing local attachment files instead of failing. Attachment lists are kept separate for each recurring request, and a storage failure on one recurrence no longer prevents unrelated recurrences from running.
- MCP desktop-client sign-in: Fixed OAuth authorization redirects to registered localhost callbacks that were blocked by the browser's content security policy.
Security & Dependency Updates
This release includes security hardening and dependency updates.