Every LinkedIn MCP server, and why none of them is LinkedIn's
LinkedIn publishes no MCP server. We looked for one from LinkedIn or from Microsoft on 20 September 2026 and found none. All 13 servers below are built by someone else, and what separates them is not the tool count on their README — it is what they hand LinkedIn in order to get in. 4 put no LinkedIn account behind them at all. One runs on LinkedIn's own OAuth and cannot search people, because no LinkedIn permission grants that. The other 8 drive a real signed-in session, which is the route Section 8.2 of the User Agreement is written against.
- Checked against
- developer.linkedin.com ↗
- Last read
An MCP server is the difference between an assistant that describes the work and one that does it
Model Context Protocol is a published standard for handing an assistant a set of tools it can call. An MCP server is the program that publishes those tools: connect one to Claude, ChatGPT or Cursor and the model stops writing about a LinkedIn profile it cannot open and starts calling something that opens it. The protocol itself is neutral about what those tools do. What a LinkedIn MCP server can reach is decided entirely by the credential you give it, which is why this page is organised that way and not by feature.
All 13 read something back: profiles, company pages, job postings, posts, or search results as structured data an assistant can use. 5 of them stop there and have no write path at all.
Messages, connection requests, posts, comments, reactions, ad campaign changes. A write is the point at which a server stops being a reader and starts producing activity on LinkedIn that carries your name.
None of them supplies one, and there is no API to buy instead — a Core seat is $119.99 a month, read from LinkedIn on 12 September 2026.
One server reaches Recruiter search and messaging, and it needs a Recruiter seat on the account it is connected to. Every other server in the directory has no Recruiter surface of any kind.
Every LinkedIn MCP server is community-built, and they divide by what they authenticate with
We found no MCP server published by LinkedIn or by Microsoft as of 20 September 2026. The check covered five published places: LinkedIn's developer product catalogue, which lists no MCP product among its consumer, marketing, sales, talent, plugin and regulatory entries; the LinkedIn API documentation on Microsoft Learn, whose six business lines contain no MCP section; the README of the microsoft/mcp repository, which names thirty-one Microsoft servers and no LinkedIn one; the MCP Registry, where a search for "linkedin" returns third-party entries and none under a com.linkedin or com.microsoft name; and GitHub's own search, which finds no repository matching "mcp" in the linkedin organisation. It stops where publication stops: a partner-only or unannounced integration would appear in none of them. The classes below are not degrees of one thing. They are 5 different relationships with the platform, each with a ceiling that no amount of good engineering lifts, and they are listed here from the route that risks nothing to the route that risks your network.
Everything behind the login is out of reach — people search, the feed, connections, messaging. A signed-out client is also walled after a handful of pages.
No account of yours can be restricted, because no account of yours is used. You are instead paying someone else to do what LinkedIn’s terms forbid, so the exposure is contractual and legal rather than account-level.
It cannot search people or read another member’s profile: no permission on LinkedIn’s self-serve list grants either. Three permissions are self-serve — sign-in, email and posting on your own behalf. Everything else is approval-gated, and the Sales Navigator API is not accepting new partners.
It can reach everything you can, which is the point and the problem. Section 8.2 of the User Agreement bars bots and scraping by any means, and enforcement lands on the account rather than on the software.
The same reach as a browser session and the same clause against it, with two additions: the session is a credential equivalent to full account access wherever it is stored, and it is invalidated whenever LinkedIn decides the client does not look like a browser.
LinkedIn ships none. Several vendors do ship official servers for their own products, and that is a different thing: it means the company behind the tool maintains it, not that LinkedIn sanctions what it does. 6 of the 13 are a vendor's own server for the vendor's own product. The verdict page carries the search that was run and what it did not cover: is there an official LinkedIn MCP server?
LinkedIn's own API allows posting, your own profile and ads. It does not allow people search, connection requests or messaging.
Read the first four rows before the rest: they are the ones that decide what a LinkedIn MCP server can be. Three permissions are self-serve and none of them returns another member. A Messages API does exist — the common claim that LinkedIn has none is wrong — but it is restricted to approved partners and then forbids the automated send an agent would do with it. The rows after that are the terms and the ceilings the whole directory sits inside.
| What LinkedIn publishes | In detail | Source |
|---|---|---|
| Three permissions are self-serve. Everything else needs approval. | LinkedIn's own access page lists exactly three permissions any developer can obtain without review: profile and email, through Sign In with LinkedIn using OpenID Connect, and w_member_social, through Share on LinkedIn. In practice an individual developer can get sign-in and posting on their own behalf, and nothing else. | LinkedIn on getting API access ↗ |
| No self-serve permission grants people search or profile lookup. | Nothing on the public access list lets an application search members or read an arbitrary member's profile. That single gap is what separates the official servers in this directory from every other one. | LinkedIn on getting API access ↗ |
| A Messages API exists, and its own terms forbid automated sending. | It is restricted to approved partners, and the documentation states that "A message must be associated with a specific member action. Member actions do not include an automated or scheduled event." The member must be able to edit any prepared draft and take an affirmative action to send. The only message type is member-to-member; there is no InMail. The accurate statement is not that LinkedIn has no messaging API, but that the one it has is partner-gated and prohibits the thing an agent would do with it. | LinkedIn’s Messages API documentation ↗ |
| The Invitations API is partner-gated and on no self-serve list. | The Invitations API is the endpoint that sends a connection request — a POST to /v2/invitations, on behalf of the authenticated member only — and its documentation opens with one note: "Usage of this API is restricted to approved partners, subject to limitations via API agreement." No invitation permission appears anywhere on the access page, whose self-serve list is profile, email and w_member_social. | LinkedIn’s Invitations API documentation ↗ |
| LinkedIn is not accepting new Sales Navigator API partners. | The Sales Navigator API page carries a note above everything else: "We are not currently accepting new partners for access to the LinkedIn Sales Navigator API. We periodically review our onboarding capacity and will update this page if availability changes." Its display services also render LinkedIn's own interface inside a partner application rather than handing over data. | LinkedIn’s Sales Navigator API page ↗ |
| Marketing API member data may not be used for sales, advertising or recruiting. | The page is titled "Restricted Uses of LinkedIn Marketing APIs and Data" and scopes itself to the Marketing API Platform, so this is a rule about that programme rather than about LinkedIn data in general. It says member data "shouldn't be used for advertising, sales, or recruiting use cases (including to identify sales or marketing prospects or prospective talent for hire, for lead creation, to enhance customer data in a CRM or marketing automation platform, to build an audience list, or for ad targeting purposes)", and lower down adds account-based marketing and sending mass messages. It also says member data "can't be exported, distributed, or otherwise transferred from your application (including to your customers)". | Restricted Uses of LinkedIn Marketing APIs and Data ↗ |
| Marketing API caching: 24 hours for other members’ profiles, 48 for their activity. | The Marketing API Program Data Storage Requirements table allows 24-hour caching of profile data for a member who has not authenticated into your application — "nothing in these requirements or the LI MDP Terms shall permit you to cache this data in excess of 24 hours or store this data" — and 48 hours for members’ social activity data. Organisations’ social activity gets six weeks. These durations belong to the Marketing API Program; another LinkedIn API programme sets its own. | LinkedIn’s Marketing API storage requirements ↗ |
| Share on LinkedIn is capped at 150 requests per member per day. | The Share on LinkedIn guide prints the throttle as a two-row table: 150 requests a day for a member, 100,000 a day for an application, both counted on UTC days. It is the one self-serve product whose numbers LinkedIn publishes. | The Share on LinkedIn guide ↗ |
| Every other limit is unpublished, on a 24-hour window resetting at midnight UTC. | LinkedIn counts calls both per application and per member per application, over a 24-hour window that resets at midnight UTC, and returns 429 when a caller goes over. It states that standard rate limits are not published in documentation: an endpoint’s limit appears in the Developer Portal only after the application has called that endpoint at least once that day. | LinkedIn’s rate-limit documentation ↗ |
| Section 8.2 of the User Agreement bars bots and bars scraping by any means. | The agreement effective 3 November 2025 prohibits using bots or other automated methods to access the service, add or download contacts, send or redirect messages, or create, comment on, like, share or re-share posts. It separately prohibits software, scripts or robots used to scrape or copy the service, naming browser plugins and add-ons. | Section 8.2 of the User Agreement ↗ |
| The same section bars renting, selling or otherwise monetising access. | Section 8.2 prohibits agreeing to "Rent, lease, loan, trade, sell/re-sell or otherwise monetize the Services or related data or access to the same, without LinkedIn’s consent." Quoted here because this domain sold LinkedIn account rental until 10 September 2026 and no longer does; publishing a directory of automation tools while omitting the one clause that names that former business would be an evasion. | Section 8.2 of the User Agreement ↗ |
| Enforcement lands on the account, not on the software. | LinkedIn's prohibited-software page bars "bots or other unauthorized automated methods to access the Services, add or download contacts, send or redirect messages, create, comment on, like, share, or re-share posts, or otherwise drive inauthentic engagement", and states that members who use them risk having their accounts restricted or shut down. | LinkedIn’s prohibited-software page ↗ |
| LinkedIn’s robots.txt denies everything by default. | The default block is Disallow: / for all agents. Every major AI training and assistant crawler is blocked outright. Two AI search crawlers are granted search-engine-style access but are additionally blocked from public profiles, people search and the guest people directory — three paths the traditional search engines are not blocked from. LinkedIn publishes no llms.txt. | LinkedIn’s robots.txt ↗ |
Read from LinkedIn's own documentation and legal pages on 20 September 2026; every row links to the page it came from. These are the platform's rules for applications. The ceilings that apply to you as a member — invitations a week, InMail allowances, the 2,500-result search cap — are separate, apply whether or not a server is involved, and are on the LinkedIn limits page.
8 of the 13 reach LinkedIn through a signed-in session rather than an API
The consequence of the table above, stated per server and without a verdict attached. The second column is the credential the reader actually supplies, in the project's own terms. The fourth is derived from two things only — that credential, and whether the server writes to LinkedIn — so it can be re-derived by anybody who disagrees with it.
| Server | What it hands LinkedIn | Writes on LinkedIn | Account exposure |
|---|---|---|---|
| Subio Scrape | No account No credential of any kind. It sees only what LinkedIn serves a signed-out visitor. | None | Low |
| Bright Data MCP (LinkedIn tools) | Vendor API key A Bright Data API token. No LinkedIn account, login or cookie is involved. | None | Low |
| Anysite MCP Server | Vendor API key An Anysite API key or OAuth token. No LinkedIn login, cookie or grant is involved anywhere in the MCP path. | None | Low |
| Insaight | Vendor API key An Apify API token. No LinkedIn credentials of any kind. | None | Low |
| LinkedIn Ads MCP Server | OAuth 2.0 OAuth 2.0 against LinkedIn's Marketing API, under a developer app you register yourself. No cookie, no scraping, no browser session. | 10 actions | Medium |
| eliasbiondo/linkedin-mcp-server | Browser session Your own LinkedIn account, signed in by hand in a browser window the server opens. No API key, no OAuth, no pasted credential. | None | Medium |
| stickerdaniel/linkedin-mcp-server | Browser session Your own LinkedIn account, through a browser the server drives. No API key and no LinkedIn API. | 2 actions | High |
| La Growth Machine MCP | Browser session A browser sign-in to La Growth Machine, not to LinkedIn. LinkedIn is reached through an identity already connected inside the workspace. | 3 actions | High |
| Linked API MCP | Browser session Two vendor-issued API tokens, not LinkedIn credentials. You sign in to LinkedIn once, by hand, inside the vendor's cloud browser. | 15 actions | High |
| gtm-api/linkedin-mcp | Browser session OAuth to the vendor for interactive clients, or a vendor bearer token for headless ones. LinkedIn is connected separately, inside the vendor dashboard. | 19 actions | High |
| LinkedGrow | Browser session An API key for the MCP server. LinkedIn itself is connected separately, by entering the account's email and password in the application. | 5 actions | High |
| southleft/linkedin-mcp | Four credentials at once. Posting and analytics run on your own LinkedIn developer app; messaging, connections and search run on a session taken from a signed-in browser. | 23 actions | High |
| linkedincli | A session from your own logged-in browser, replayed against LinkedIn's internal API. No OAuth, no API key, no developer app. | 17 actions | High |
No LinkedIn account is behind the server, or it acts only through LinkedIn’s own approved API and only to read. Nothing here can get an account restricted.
The account is exposed in one direction. Either the server reads LinkedIn automatically without writing anything, which the User Agreement prohibits but which produces no activity anyone can report; or it writes through the approved API, where the exposure is what gets published rather than whether the account survives.
The server writes to LinkedIn as you, over a route LinkedIn does not sanction. Automated messages and connection requests under a member’s own name are what the enforcement is built to catch, and the account is what it acts on.
Exposure measures one thing: the chance that the LinkedIn account behind the server ends up restricted. It is not a quality score — the most careful project here and the least careful one both land on High, because both send messages from a real session — and it is not blast radius, since the ads server rated Medium can delete a live campaign in one call. That belongs on its profile page, and it is there.
All 13, filtered by the thing that actually decides it
Filter by what a server authenticates with first; everything else narrows a list you can already live with. This page describes what each one is, what it holds and what it exposes. It does not recommend running any of them, and it does not rank them: LinkedIn's User Agreement prohibits automated access by any means, and the exposure badge is there so that clause is in view at the moment of choosing rather than after it. Three of the categories are argued out in full rather than only filtered: the 3 with a Sales Navigator surface, the 1 with a Recruiter surface and the 5 in the posting category.
Subio Scrape
No accountReads public LinkedIn company and person pages, and a company's public posts when LinkedIn serves them signed out. It never logs in, so it puts no account at risk — and cannot see anything behind the login.
stdio7 toolsNo writes to LinkedInBright Data MCP (LinkedIn tools)
Vendor API keyA general web-access server with five LinkedIn extractors: hand it a profile, company, job, post or people-search URL and it returns structured JSON. It holds no LinkedIn credential, so there is no account to restrict.
stdio and Streamable HTTP69 toolsNo writes to LinkedInAnysite MCP Server
Vendor API keyA hosted, paid server that returns structured LinkedIn data — profiles, people search, companies, posts, jobs, the Ad Library — plus a dozen other sources, with server-side filtering and export. No LinkedIn login goes anywhere near it, and it cannot write to LinkedIn at all.
stdio and Streamable HTTP15 toolsNo writes to LinkedInInsaight
Vendor API keyResearch and record-keeping for manual outreach: it briefs you on a person or a company, mines a post's comment thread, and keeps a local ledger of what you sent and what replied. It has no send path at all.
stdio18 toolsNo writes to LinkedInLinkedIn Ads MCP Server
OAuth 2.0Campaign Manager through LinkedIn's official Marketing API, on an OAuth app you register yourself: reporting over your own ad accounts, and a write half that can change budgets and delete campaigns in a live account with no preview step.
stdio25 tools10 writes to LinkedIneliasbiondo/linkedin-mcp-server
Browser sessionRead-only LinkedIn scraping through a browser you sign into yourself: profiles section by section, company pages, job postings, people search. No write path at all, and no commits in six months.
stdio and Streamable HTTP7 toolsNo writes to LinkedInstickerdaniel/linkedin-mcp-server
Browser sessionProfiles, companies, jobs, the feed, post search and your own inbox, read through a browser you sign into on your own account. Two tools write — a message and a connection request — and only the message tool takes a confirmation flag.
stdio and Streamable HTTP19 tools2 writes to LinkedInLa Growth Machine MCP
Browser sessionThe operational half of an outbound platform, driven from a chat window: audiences, campaign drafts, inbox triage and SQL over your own funnel. Most of its tools never touch LinkedIn, and none of them launches a campaign.
Streamable HTTP41 tools3 writes to LinkedInLinked API MCP
Browser sessionA paid cloud-browser service whose tools cover messaging, connections, search, fetching, posting, engagement and Sales Navigator, plus admin tools that let an agent manage seats and rate limits. The MIT repository alone does nothing without the vendor.
stdio and Streamable HTTP62 tools15 writes to LinkedIngtm-api/linkedin-mcp
Browser sessionA hosted service whose meta-tools expose more than 160 LinkedIn actions, discovered at runtime, including Sales Navigator and Recruiter messaging. The ones that write reach a real account, behind a server-side preview-then-confirm gate.
stdio and Streamable HTTP3 meta-tools19 writes to LinkedInLinkedGrow
Browser sessionA self-hostable four-container outbound application whose MCP server is a route on your own instance. Its read tools touch nothing on LinkedIn; its write tools start real invitations, messages and scheduled posts under your name.
Streamable HTTP26 tools5 writes to LinkedInIt layers credentials rather than picking one: official OAuth for posting and analytics, a browser session for messaging and search, and a paid scraper API for research. The session path is what carries the account risk.
stdio83 tools23 writes to LinkedInProfile data, the feed, messaging, connections and engagement, on a session taken from your own browser. No rate limiting, no throttle, no dry run and no confirmation step, and the maintainer forbids running it on a server.
stdio43 tools17 writes to LinkedIn
Maintenance is derived from the last commit that changed code, not from the last commit: Active is within 90 days of the day this directory was read, Stale is up to 365. One repository here has commits three weeks old and no functional change since March, and deriving from the raw commit date would have printed Active over it. Anything past a year is moved out of the directory rather than shown in it.
The sanctioned route is also the narrowest one on this page
The 5 columns are chosen by a rule rather than by preference: the most-starred server in each authentication class on 20 September 2026. Read the boxed column first. It is the only one running on LinkedIn's own OAuth, and it is also the only one that cannot open a profile, run a search or send a message — not because its author stopped early, but because no LinkedIn permission would have let him continue.
| Subio ScrapeNo account — 35★ | Bright Data MCP (LinkedIn tools)Vendor API key — 2,655★ | LinkedIn Ads MCP ServerOAuth 2.0 — 34★ | stickerdaniel/linkedin-mcp-serverBrowser session — 3,551★ | linkedincliSession cookie — 57★ | |
|---|---|---|---|---|---|
| What it hands LinkedIn | No account | Vendor API key | OAuth 2.0 | Browser session | Session cookie |
| Your LinkedIn account is behind it | No | No | Yes | Yes | Yes |
| Account exposure | Low | Low | Medium | High | High |
| Writes to LinkedIn | Read only | Read only | 10 actions | 2 actions | 17 actions |
| Sales Navigator | No | No | No | No | No |
| Recruiter | No | No | No | No | No |
| Tools registered | 7 | 69 | 25 | 19 | 43 |
| Transport | stdio | stdio and Streamable HTTP | stdio | stdio and Streamable HTTP | stdio |
| Where it runs | Self-hosted | Either | Either | Self-hosted | Self-hosted |
| Licence | MIT | MIT | MIT | Apache-2.0 | MIT |
| Setup | Easy | Easy | Moderate | Moderate | Moderate |
| Maintenance | Active | Active | Stale | Active | Active |
Star counts and commit dates were read from the GitHub API on 20 September 2026 and are the one figure here that ages by the hour. Full records, with the tool list, the write actions and the project's own config block, are on Subio Scrape, Bright Data MCP (LinkedIn tools), LinkedIn Ads MCP Server, stickerdaniel/linkedin-mcp-server and linkedincli.
The specification changed on 28 July 2026, and most published guides describe the old one
Worth two minutes before you copy a snippet from anywhere, including from here. The handshake is gone, sessions are gone, one of the two original transports is formally deprecated, and the client config key is not the same word in every client. A tutorial written last year will read as though all four are still true.
| What is true now | In detail | Source |
|---|---|---|
| The current specification revision is 2026-07-28. | The versioning page names 2026-07-28 as the current revision, and modelcontextprotocol.io/specification redirects to it. Its changelog lists the changes "since the previous revision, 2025-11-25". Five dated revisions are published — 2024-11-05, 2025-03-26, 2025-06-18, 2025-11-25 and 2026-07-28 — beside a draft whose changelog reads "Changes since the most recent release will accumulate here." and holds nothing else. No date for a next revision is published. | The specification’s versioning page ↗ |
| MCP is now stateless. The initialize handshake is gone. | The initialize and initialized handshake was removed, as were protocol-level sessions and the session header on Streamable HTTP, the standalone GET stream, event-id resumability, ping and log-level setting. Servers must implement a discovery call advertising supported versions, capabilities and identity. Anything describing a session id or a handshake as current is describing the old model. | The 2026-07-28 changelog ↗ |
| The two current transports are stdio and Streamable HTTP. | The transports page defines two bindings, stdio and Streamable HTTP, and HTTP+SSE — the original 2024-11-05 transport — is not one of them. It sits instead in the specification's registry of deprecated features: deprecated in revision 2025-03-26, reclassified as Deprecated under the feature lifecycle policy by SEP-2596, migration path Streamable HTTP, earliest removal "Three months after SEP-2596 reaches Final". That is a condition, not a date. A server still offering an SSE endpoint is offering a legacy compatibility path, not a choice. | The specification’s deprecated-features registry ↗ |
| Authorization is OAuth 2.1, and dynamic client registration is deprecated. | Servers must implement protected resource metadata and clients must use it to discover the authorization server. Dynamic client registration is deprecated in favour of client ID metadata documents — an HTTPS URL used directly as the client id. Registration priority is pre-registered credentials, then metadata documents, then dynamic registration, then prompting the user. Local stdio servers should not use OAuth at all. | The specification’s authorization page ↗ |
| Claude Desktop and Claude Code read the same mcpServers object; type is for remote entries. | Claude Desktop uses claude_desktop_config.json with a top-level mcpServers object, inferring stdio from a command key. Claude Code uses .mcp.json for project scope or ~/.claude.json for local and user scope, under the same key, and its documentation says Claude Code reads an entry with no type as a stdio server — so a command-and-args block moves across unchanged, and "claude mcp add-from-claude-desktop" imports one outright. type is what a remote entry needs: a url with no type is a configuration error, and the accepted values are http (with streamable-http as an alias), sse and ws. The CLI takes "claude mcp add --transport stdio <name> -- <command>" and "claude mcp add --transport http <name> <url>". | Claude Code’s MCP documentation ↗ |
| VS Code uses a servers key, not mcpServers. | VS Code's own configuration reference says the file has three main sections, the first being "servers": an object that maps server names to their configurations. It lives in .vscode/mcp.json in the workspace, or in the user profile. Zed's documentation uses context_servers in settings.json; Gemini CLI's keeps the name mcpServers but selects Streamable HTTP with httpUrl, reserving url for the deprecated SSE transport. Getting one of these names wrong makes the snippet fail silently, which is why every config block in this directory is the project's own rather than one written here. | VS Code’s MCP configuration reference ↗ |
| The MCP Registry is still in preview. | Publishing goes through a command-line tool and a server manifest. Several servers in this directory carry a registry entry; a registry listing is a publication record, not a review. | The MCP Registry servers endpoint ↗ |
A row marked read second-hand was taken from a page summary rather than read line by line, and is worth confirming against its source before you build on it. The rest were read directly on 20 September 2026.
Four clients, four config files — and one of them does not use the key mcpServers
Each block below is copied unedited from the page linked beneath it. They are here as the shape, not as a server to install: take the actual block from the profile page of whichever server you chose, because a config that has been tidied by a third party is one the maintainer never ran. ChatGPT is not a fifth file — on the web it takes a remote server as a URL rather than a config block, which rules out most of this directory before features are discussed: what a ChatGPT connector reaches, and what it cannot.
- Decide what you are willing to hand over. Pick the authentication class before you pick the server. It decides what the server can reach and who carries the consequence, and it is the one property a tool list cannot compensate for.
- Take the config block from the project, not from an article. Every block on a profile page here is the project’s own, copied whole. A config that has been tidied by a third party is a config the maintainer never tested, and the failure it produces is silent.
- Put it in the file your client actually reads, under the key that client expects. Claude Desktop, Claude Code and Cursor use an mcpServers object; VS Code uses servers. In Claude Code an entry with no type is read as stdio, so type matters only for a remote server, where a url without one is rejected.
- Restart, then confirm the tools are listed before an agent touches them. A stdio server that fails to launch fails quietly in most clients. Ask the assistant to list its tools, and check the server log before you let anything run unattended.
Claude Desktop
macOS: ~/Library/Application Support/Claude/claude_desktop_config.json. Windows: %APPDATA%\Claude\claude_desktop_config.json. Reached through Settings → Developer → Edit Config, and it needs a full restart, not a window reload. The transport is inferred from the presence of a command key, so no type field is required. The official page publishes no Linux path. Logs land in ~/Library/Logs/Claude/mcp.log and mcp-server-SERVERNAME.log, which is the first place to look when a server does not appear.
{
"mcpServers": {
"filesystem": {
"command": "npx",
"args": [
"-y",
"@modelcontextprotocol/server-filesystem",
"/Users/username/Desktop",
"/Users/username/Downloads"
]
}
}
}modelcontextprotocol.io ↗, read 20 September 2026. which Claude surface reads which file.
Claude Code
Project scope is .mcp.json at the repository root; local and user scope live in ~/.claude.json, where the entry nests under projects → your path → mcpServers. The block below is the file the docs show claude mcp add writing at project scope. Claude Code reads an entry with no type as a stdio server, so a command-and-args block from Claude Desktop moves across unchanged and claude mcp add-from-claude-desktop imports one; type is required only when the entry has a url, where the values are http (alias streamable-http), sse and ws, and a url without one is reported as a configuration error. The CLI form is claude mcp add --transport stdio <name> -- <command> for a local server and claude mcp add --transport http <name> <url> for a remote one.
{
"mcpServers": {
"shared-server": {
"type": "http",
"url": "https://example.com/mcp"
}
}
}code.claude.com ↗, read 20 September 2026. the three Claude surfaces and their scopes.
Cursor
.cursor/mcp.json for one project, ~/.cursor/mcp.json globally. Same mcpServers key as Claude Desktop and no type field, so a Claude Desktop block moves across unchanged. A remote server uses url plus headers in place of command and args.
{
"mcpServers": {
"server-name": {
"command": "npx",
"args": ["-y", "mcp-server"],
"env": {
"API_KEY": "value"
}
}
}
}cursor.com ↗, read 20 September 2026. the LinkedIn servers that run in Cursor.
VS Code
The key is servers, not mcpServers. Paste a Claude Desktop block into this file and nothing happens and nothing says why. The file also takes an inputs array for prompted secrets, referenced as ${input:api-key}, so a token never has to be written into the config. One further trap: VS Code forwards configured servers to the Agent Host, which does not read .vscode/mcp.json itself — portable configuration goes in a workspace .mcp.json or ~/.copilot/mcp-config.json.
{
"servers": {
"memory": {
"command": "npx",
"args": ["-y", "@modelcontextprotocol/server-memory"]
}
}
}code.visualstudio.com ↗, read 20 September 2026.
7 more servers were researched and left out, each against a published rule
A directory that prints only what it liked is a list of whatever someone found first. These were read the same way as the 13 above and failed one of five rules: over a year since the last code change; tools that call endpoints the API they target does not expose to them; documentation describing a materially different server from the one in the repository; no licence, so no rights are granted; or reachable from no MCP client a reader is likely to have. They are listed so the next person to find the repository does not repeat the work.
| Server | Last commit | Why it is not in the directory |
|---|---|---|
| felipfr/linkedin-mcpserver ↗ | It authenticates with the client-credentials grant, which returns an application token carrying no member context, and then calls endpoints that LinkedIn does not expose to a self-service developer app at all: people search, job search, generic member messaging, the connections list and network size. Two independent users report exactly that in issue #4 — 401 and 429 responses with a normal app, even after adding the two self-serve products. The maintainer has not answered an issue since the day he published it, all four commits landed within about twelve minutes, and the documented build command fails because it operates on a file the build never produces. Publishing its tool list as capability would state that it does things nobody has got it to do. | |
| LinkedInMCP (Dishant27/linkedin-mcp-server) ↗ | The same design as felipfr/linkedin-mcpserver and the same identical endpoint set, reached the same way through a client-credentials grant with no member context. Its own open issue #1 asks whether the people-search endpoint is supported by the LinkedIn API and has no reply. It also does not build as pinned: the SDK version in package.json predates the module the entry file imports. Three of its four open issues are unanswered security and hygiene defects, including the client secret being sent as a URL query parameter and the repository having no gitignore while the README tells you to create an environment file in it. Note that its API pushed_at date looks recent only because a scheduled workflow pushes throwaway metrics branches; every substantive commit is from March 2025. | |
| LinkedIn Browser MCP Server (alinaqi/mcp-linkedin-server) ↗ | Three commits on a single day in February 2025 and nothing since — nineteen months at the verification date. An issue titled "are you maintaining this?" has been open and unanswered since March 2025. The README documents five of the seven tools the source registers, its only client example calls an HTTP endpoint the server does not serve, and its clone command still contains an unfilled placeholder. Three concrete defects sit in the source: the account password is kept in plaintext, the advertised session persistence silently never works unless an undocumented encryption key is set, and the saved session directory and file are created world-readable and world-writable. The page selectors it depends on are from early-2025 markup. | |
| Hritik003/linkedin-mcp ↗ | The README advertises four features — profile retrieval, job search with seven filters, feed posts, and resume parsing. Two exist. The whole server is one file of about a kilobyte holding two tools, and the profile tool takes no identifier at all, so it can only ever return your own profile. The repository description calls it a server "to seamlessly apply for jobs"; no apply tool exists. It also has no licence file, so no rights are granted, and it asks for your LinkedIn email and password in plaintext rather than a session. The only commit after January 2025 was an automated onboarding pull request from a directory service, not the author. | |
| fredericbarthelet/linkedin-mcp-server ↗ | The README states that MCP Inspector is the only client the author knows of that implements the draft authorization flow it is built on, and names no other. Claude Desktop, Claude Code and Cursor are not claimed or documented. Eighteen months without a commit, while the draft specification it implements has moved on: MCP now deprecates dynamic client registration in favour of client ID metadata documents. It also has no licence file, and its two tools are reading your own name and headline, and publishing a post to your own feed at public visibility with no draft, no confirmation and no way to delete it again. As a legible reference implementation of delegated OAuth it is worth reading; as a directory entry it is a server a reader cannot connect to anything. | |
| agency42/linkedin-mcp ↗ | Four commits between April and May 2025 and nothing in the sixteen and a half months since. No licence file, so no rights are granted. No tests, no CI, no releases, and no issue has ever been filed. Its two tools both publish to your own feed at public visibility, hardcoded, with no read tool of any kind, no preview and no delete. The README clone command is a literal placeholder and the client config block hardcodes the author's own machine path. It also writes to the endpoint LinkedIn's own documentation titles as legacy and says is replaced. | |
| LinkedIn Profile Analyzer MCP (rugvedp/linkedin-mcp) ↗ | Sixteen months idle. The whole server is one 6 KB file with five tools, four of which read a local JSON file that the fifth overwrites — fetching a second profile destroys the first one's data, because the filename is hardcoded. The README is wrong in three checkable places: it states a Python floor the MCP SDK does not support, documents a result limit twice the one the code enforces, and the repository description says it "interacts with LinkedIn's API" when it calls a paid third-party scraper. Two code paths throw uncaught on ordinary inputs. Its authentication story is the clearest of any excluded server, and it still is not worth a page. |
Commit dates read from the GitHub API on 20 September 2026. An excluded server is not a bad one in every case — two of these are competent code aimed at an API that does not return what their documentation says it does — but none of them is something a reader should wire into a client today.
The questions people arrive with, answered directly
Is there an official LinkedIn MCP server?
No. We looked for one published by LinkedIn or by Microsoft on 20 September 2026 and found none. The check covered five published places: LinkedIn's developer product catalogue, which lists no MCP product among its consumer, marketing, sales, talent, plugin and regulatory entries; the LinkedIn API documentation on Microsoft Learn, whose six business lines contain no MCP section; the README of the microsoft/mcp repository, which names thirty-one Microsoft servers and no LinkedIn one; the MCP Registry, where a search for "linkedin" returns third-party entries and none under a com.linkedin or com.microsoft name; and GitHub's own search, which finds no repository matching "mcp" in the linkedin organisation. It stops where publication stops: a partner-only or unannounced integration would appear in none of them. What does exist is 13 servers built by other people, 6 of them published by the vendor of the product the server drives. A vendor's own server means that company maintains it and answers for it. It does not mean LinkedIn sanctions what it does, and on this page those are kept apart.
What is the best LinkedIn MCP server?
The wrong question, and the one every other list answers. These are not 13 versions of one product; they are 5 different relationships with LinkedIn, and the tool count on a README tells you nothing about which of them you can live with. Decide what you are willing to hand over — nothing at all, a data vendor’s API key, a LinkedIn developer app, or a live session on your own account — and the shortlist is usually two or three. Compare tool counts after that, not before.
Can Claude connect to LinkedIn?
Through an MCP server, yes: Claude Desktop and Claude Code take one from a config file, and Claude on the web takes a remote one as a custom connector. There is nothing to connect to on LinkedIn’s side — LinkedIn ships no MCP server and no connector. Claude also cannot read a LinkedIn URL you paste, because LinkedIn’s robots.txt blocks every major assistant crawler outright and separately shuts the two AI search crawlers it does allow out of public profiles, people search and the guest people directory. What a server does is hand Claude a tool that fetches the page, instead of asking Claude to open it.
Can an MCP server send LinkedIn messages or connection requests?
Several can, and none of them does it through a route LinkedIn opened for that purpose. LinkedIn's Messages API exists but is restricted to approved partners, and its own documentation says a message must be tied to a member action, where "member actions do not include an automated or scheduled event". The Invitations API is partner-gated too and appears on no self-serve permission list. So every server here that sends a message or an invitation is driving a signed-in browser or replaying a session cookie, and the activity reaches LinkedIn as yours. 8 of the 13 write to LinkedIn at all; 5 never write to it.
Will using a LinkedIn MCP server get my account restricted?
It can, and the risk is not spread evenly. Section 8.2 of the User Agreement, effective 3 November 2025, prohibits using bots or other automated methods to access the service, add or download contacts, send or redirect messages, or create, comment on, like, share or re-share posts — and enforcement lands on the account rather than on the software. LinkedIn's prohibited-software page says a member who uses them risks having the account restricted or shut down. 4 of the 13 servers here put no LinkedIn account behind them at all, which is the only arrangement that takes the question off the table. This page does not tell you to run the others. It tells you what each one holds.
Is there a free LinkedIn MCP server?
Several, and "free" covers two different arrangements. Some are MIT or Apache-2.0, run on your own machine, and cost nothing beyond the LinkedIn account you point them at. Others are free software with a running bill attached — a scraper API charged per record, a dedicated proxy per connected account, an AI provider key. The hosted services are paid outright, though one of them publishes a permanently free tier for a single connected account. Every price on a profile page here is the vendor’s own figure, in the vendor’s currency, with the day it was read; none of it is LinkedIn’s price.
Can an MCP server use my Sales Navigator seat?
3 of the 13 have tools that target Sales Navigator, and every one of them requires you to already hold a seat. None supplies one. One of them builds a Sales Navigator search URL from a plain-English description and states the prerequisite in its own README: "an active Sales Navigator subscription to open the resulting URL... LinkedIn redirects to an upsell page otherwise." A Core seat is $119.99 a month, last read from LinkedIn on 12 September 2026. There is no API route to buy instead: LinkedIn's Sales Navigator API page says it is not accepting new partners, so each of them drives the seat through a session.
Which MCP clients can run these — Claude Desktop, Claude Code, Cursor, VS Code?
Every one of the 13 names Claude Desktop or Claude Code as a supported client. Most also name Cursor. ChatGPT appears on several, usually the hosted ones, because a remote Streamable HTTP endpoint is easier for a connector than a local process is. VS Code takes MCP servers as well, under a servers key rather than mcpServers — the single commonest reason a working block stops working when it is moved. Each profile page lists the clients the project itself names and the config block it publishes for them, rather than one written here.
Choose the credential first, the server second
4 of the 13 put no LinkedIn account behind them and cannot get one restricted. 8 drive a live session and can. That decision is upstream of every feature comparison, and the directory is sorted for it.