An MCP server for LinkedIn that reads LinkedIn profiles, companies, jobs, and messages using your own browser session. It drives a real, headless browser via patchright (an undetected fork of Playwright). The project is an independent, community effort and is not affiliated with or endorsed by LinkedIn or Microsoft.
🛠️ Key Features
MCP server for LinkedIn
Reads profiles, companies, jobs, and messages
Uses a real headless browser via patchright (undetected fork of Playwright)
Operates through your own browser session
🚀 Use Cases
LinkedIn profile retrieval
Company and job search workflows
Message reading within an MCP-based integration
Recruiting-related automation via browser-driven access
⚡ Developer Benefits
Integrates LinkedIn data access into Model Context Protocol
Headless browser automation using Playwright-derived patchright
⚠️ Limitations
Limited to functionality described: profiles, companies, jobs, and messages via a browser session
Effectiveness depends on using a compatible “own browser session” setup
Disclaimer: This is an independent, community project. It is not affiliated with, authorized by, endorsed by, or sponsored by LinkedIn Corporation or Microsoft. "LinkedIn" is a registered trademark of LinkedIn Corporation and is used here only descriptively to identify the third-party service this software interoperates with.
An MCP server for LinkedIn. It drives a real, headless browser
(patchright, an
undetected fork of Playwright) using your own logged-in LinkedIn session cookie.
There is no scraping API, no credential stuffing, no bypass of LinkedIn's login. Your
agent gets 12 read tools (profiles, companies, jobs, posts, your inbox) and two write
tools, kept deliberately separate: sending a message and sending a connection
request. Every action goes through a single browser session, one at a time, paced
against limits you control. See Safety below.
Terminal demo of linkedin-api-mcp: an agent calls search_people to find a member, then send_message to message them, then reads the conversation back to confirm the message actually arrived. 14 tools, 68 tests, MIT licence.
Install (one-click)
Deeplinks exist for Cursor and VS Code only; no other client has a documented
install-link format. These prefill the command below, nothing else needs filling
in since the cookie lives in your OS keyring, not an environment variable.
Codex CLI's config schema has changed across versions and this block is not
independently verified against a live install. If it doesn't load, the reliable
path is running uvx linkedin-api-mcp yourself and pointing Codex at whatever
its current stdio-server config expects.
Zed: settings.json
No deeplink exists for Zed. Add this under context_servers in your Zed
settings:
No deeplink exists for Windsurf. It only resolves servers from its own
registry, so this has to be pasted in manually via Windsurf Settings → MCP
Servers → Edit raw config:
Open DevTools (F12 or Cmd+Opt+I) → Application → Cookies →
https://www.linkedin.com.
Find the row named li_at and copy its Value.
WARNING
This cookie is your LinkedIn login. Anyone who has it can act as you:
read your messages, message your connections, see everything your account can
see, without needing your password. It survives a password change, and it
cannot be revoked from any session list LinkedIn shows you. Never paste it
into a chat, a commit, an issue, a screenshot, or anywhere other than
linkedin-api-mcp auth.
Store it:
bash
uvx linkedin-api-mcp auth
Paste the value in when prompted; the terminal will not echo it back. By
default it's stored in your OS keyring (Keychain, Windows Credential Manager,
or Secret Service on Linux), never written to a config file.
Verify LinkedIn accepts it before wiring up a client:
bash
uvx linkedin-api-mcp --test
Prints the server's redacted configuration and confirms the session is live.
It never prints the cookie itself.
Tools
Tool
Description
get_profile
Fetch a member's profile (headline, about, experience, education, skills) by URL or public identifier.
get_my_profile
Fetch the profile of the account this server is logged in as.
search_people
Search LinkedIn members by keyword.
get_inbox
List recent message thread previews.
get_conversation
Fetch the full message history of one thread, by id.
search_conversations
Search your message threads by participant or keyword.
send_message ✏️
Write. Sends a real message to another member from your account.
connect ✏️
Write. Sends a real connection invitation to another member from your account.
get_company
Fetch a company page (about, size, industry, recent posts).
search_companies
Search LinkedIn companies by keyword.
search_jobs
Search job postings by keyword and optional location.
get_job
Fetch one job posting in full.
search_posts
Search LinkedIn feed posts by keyword.
linkedin_status
Check session validity and current usage against the rate limits in Safety.
14 tools: 12 read, 2 write. send_message and connect are the only two that
change anything, and both are visible to another real person the moment they
run: there is no draft, preview, or undo step. Everything else only reads what
your account can already see. Covered by 68 tests.
What's verified, and what isn't
This is a days-old project. Rather than claim everything works, here's what's
actually been checked against a live account, and what hasn't.
Implemented and tested, but not yet exercised against a live account by hand.
Known gap
conversation_id from get_inbox
Comes back null. LinkedIn binds inbox rows to in-memory JS objects rather than URLs, so there's no id to read out of the page.
Known gap
Reaction and comment counts on search_posts
Come back null.
Known gap
experience and education on get_profile
LinkedIn loads these sections only on scroll; they currently come back empty.
Safety
A serialised action queue. Every tool call, including linkedin_status,
passes through the same queue before it touches the browser: one action at a
time, never in parallel.
A minimum interval and an hourly ceiling, both enforced, not just claimed:
Setting
Default
Env var
Effect
Minimum interval between actions
2 seconds
LINKEDIN_MIN_INTERVAL
Calls are paced against the previous one, not run back-to-back.
Actions per rolling hour
120
LINKEDIN_MAX_PER_HOUR
Once hit, further calls fail immediately with a rate_limited error rather than queueing or sleeping.
The ceiling is local to this server: it exists to stop a looping agent from
generating a burst of LinkedIn traffic, not because LinkedIn told us these
numbers. Lowering them is always safe; raising them is you deciding you're
willing to accept more risk than the defaults assume.
Prompt-injection fencing on all scraped free text. Anything read off a
LinkedIn page (a headline, an about section, a message) passes through your
agent as data. It is fenced before your agent sees it, so text on a profile
or in a message cannot pose as an instruction.
send_message proves delivery before reporting success. It polls the
conversation until the sent text actually appears, and raises
send_unconfirmed rather than a false {"sent": true} if it doesn't.
Other environment variables the server reads: LINKEDIN_COOKIE (overrides the
keyring), LINKEDIN_HEADLESS (default true), LINKEDIN_NAV_TIMEOUT_MS (default
30000).
FAQ
Is this safe to use? Will I get banned?
This tool controls a real browser session; it doesn't exploit undocumented APIs or bypass authentication. LinkedIn's User Agreement prohibits automated access, and accounts using automated tools can be restricted or banned. Use at your own risk; there is no guarantee of account safety. If you encounter any issues, let me know in the Discussions.
What if my agents execute too many actions?
Tool calls run sequentially through a queue. You are responsible for the volume of automation you run; use it sparingly and prompt your agents responsibly.
Use it, change it, redistribute it, build something commercial on it: the only
condition is that you keep the copyright notice and licence text. It comes with no
warranty of any kind.
Contributions are accepted under the same licence.
Install the development dependencies and run pytest from the repository root:
bash
pip install -e ".[dev]"
python -m pytest -q
The default test suite does not need Chromium, a LinkedIn account,
LINKEDIN_COOKIE, or network access. Browser interactions are replaced by the test
doubles in tests/fakes.py, which parse canned HTML and expose
the small Playwright surface used by the tools. For a parsing-test example, see
tests/test_people_parsing.py.
This is an independent project, not affiliated with LinkedIn Corporation. See the
disclaimer at the top of this document.
Install
Configuration
Environment variables
LINKEDIN_COOKIEsecret
Your LinkedIn li_at session cookie. Optional if you have already stored it in the OS keyring with `linkedin-api-mcp auth`, which is the recommended route: this cookie is equivalent to being logged in as you.
LINKEDIN_HEADLESS
Run the browser headless. Defaults to true; set to 0 to watch what it does.
LINKEDIN_MIN_INTERVAL
Minimum seconds between LinkedIn actions. Defaults to 2.
LINKEDIN_MAX_PER_HOUR
Hard ceiling on LinkedIn actions per rolling hour. Defaults to 120. The server refuses past this rather than sleeping, so an agent in a loop is told to stop.