MCP servers for LinkedIn sales, and what each one hands over to do it
LinkedIn's own API cannot search people, cannot send a connection request, and forbids the automated send on the one messaging endpoint it has. Its Sales Navigator programme is closed to new partners, and the data programme that is open says in writing that its member data may not be used for sales. So there is no sanctioned route to prospecting, and every server below reaches LinkedIn some other way — that route, not the tool count, is what you are choosing between. 12 of the 13 servers here do some part of sales work. 4 do the research half with no LinkedIn account of yours behind them. 7 can write to a person, and they are exactly the servers this directory rates High account exposure — the group has nothing else in it.
- Checked against
- learn.microsoft.com ↗
- Last read
LinkedIn publishes an API for sellers in the sense that it publishes a door with no handle on this side
6 rules decide the whole page, and every one of them is LinkedIn's own text, read on 20 September 2026. Taken together they close the sanctioned route to each of the three things sales work is made of — finding a person, opening their profile, and writing to them. A server that does any of those is therefore not using LinkedIn's API, whatever its README calls itself, and the question becomes which substitute it uses and who carries the consequence.
Nothing on the public access list lets an application search members or read an arbitrary member's profile. That single gap is what separates the official servers in this directory from every other one. LinkedIn on getting API access ↗
It is restricted to approved partners, and the documentation states that "A message must be associated with a specific member action. Member actions do not include an automated or scheduled event." The member must be able to edit any prepared draft and take an affirmative action to send. The only message type is member-to-member; there is no InMail. The accurate statement is not that LinkedIn has no messaging API, but that the one it has is partner-gated and prohibits the thing an agent would do with it. LinkedIn’s Messages API documentation ↗
The Invitations API is the endpoint that sends a connection request — a POST to /v2/invitations, on behalf of the authenticated member only — and its documentation opens with one note: "Usage of this API is restricted to approved partners, subject to limitations via API agreement." No invitation permission appears anywhere on the access page, whose self-serve list is profile, email and w_member_social. LinkedIn’s Invitations API documentation ↗
The Sales Navigator API page carries a note above everything else: "We are not currently accepting new partners for access to the LinkedIn Sales Navigator API. We periodically review our onboarding capacity and will update this page if availability changes." Its display services also render LinkedIn's own interface inside a partner application rather than handing over data. LinkedIn’s Sales Navigator API page ↗
The page is titled "Restricted Uses of LinkedIn Marketing APIs and Data" and scopes itself to the Marketing API Platform, so this is a rule about that programme rather than about LinkedIn data in general. It says member data "shouldn't be used for advertising, sales, or recruiting use cases (including to identify sales or marketing prospects or prospective talent for hire, for lead creation, to enhance customer data in a CRM or marketing automation platform, to build an audience list, or for ad targeting purposes)", and lower down adds account-based marketing and sending mass messages. It also says member data "can't be exported, distributed, or otherwise transferred from your application (including to your customers)". Restricted Uses of LinkedIn Marketing APIs and Data ↗
LinkedIn's prohibited-software page bars "bots or other unauthorized automated methods to access the Services, add or download contacts, send or redirect messages, create, comment on, like, share, or re-share posts, or otherwise drive inauthentic engagement", and states that members who use them risk having their accounts restricted or shut down. LinkedIn’s prohibited-software page ↗
We found no MCP server published by LinkedIn or by Microsoft as of 20 September 2026. The search behind that sentence, and what it could not cover, is set out on the page on whether an official LinkedIn MCP server exists. The restricted-use rule above is narrower than it sounds and worth reading in its own words: it governs the Marketing API programme rather than LinkedIn data in general, which is exactly why the ads server in this directory is no help to a seller.
The research half of sales has a route that risks nothing of yours. The writing half has none.
This is the shape of the category, and the reason a single ranked list would mislead. Building a list and briefing yourself on an account can be done by servers that hold no LinkedIn credential at all; the moment a tool has to write to a named person, it needs a signed-in session on your account, and there is no version of that which LinkedIn has sanctioned. The sets below are counted from the registry, and a server that does two jobs is in both.
Read profiles, companies, posts and jobs into an assistant as structured data. Bright Data MCP (LinkedIn tools) turns profile, company, job, post and people-search URLs into structured JSON on a data vendor's key. Anysite MCP Server does it at volume with server-side filtering and CSV export. Subio Scrape reads only what LinkedIn serves a signed-out visitor, for nothing, and stops at the first refusal instead of pushing through it. None of these can be traced back to a LinkedIn account, because none of them holds one.
Account and person research is where a model earns its place, and it is the one sales task that needs no write path. Insaight is built for exactly this: it briefs you on a person or a company, mines a post's comment thread for people who engaged, and keeps a local ledger of what you sent and what replied — with no send path anywhere in it. The cost is per record through Apify rather than per seat, and the output is a brief you act on by hand.
Writing to people: messages, connection requests, invitations. Where the account risk lives. This is not a coincidence of scoring: the exposure rule in the registry rates a server High when it writes to LinkedIn over a route LinkedIn does not sanction, and there is no other route to a message or an invitation. All 7 High-exposure servers in the directory are in this group, and the group has nothing else in it. What differs between them is the guardrail, not the legal position.
One server in the directory does no part of sales work: LinkedIn Ads MCP Server, which runs on LinkedIn’s Marketing API. It is the only server here on a fully sanctioned route, and it is still no use to a seller — the restricted-use page above says member data from that programme may not be used to identify prospects, build an audience list or enrich a CRM. A sanctioned API and a usable one are different things, and this is the clearest case of it in the directory.
The second column is the decision; the rest of the row is detail
One row per server that does any part of sales work, in the directory's own order — from the route that holds nothing of yours to the route that holds a live session on your account. The exposure column is derived from two things only, the credential and whether the server writes to LinkedIn, so anyone who disagrees with a rating can re-derive it.
| Server | What it hands LinkedIn | Which job | Sales Navigator | Writes to LinkedIn | Account exposure |
|---|---|---|---|---|---|
| Subio Scrape | No account No credential of any kind. It sees only what LinkedIn serves a signed-out visitor. | Profile and company data | None | None | Low |
| Bright Data MCP (LinkedIn tools) | Vendor API key A Bright Data API token. No LinkedIn account, login or cookie is involved. | Profile and company data | None | None | Low |
| Anysite MCP Server | Vendor API key An Anysite API key or OAuth token. No LinkedIn login, cookie or grant is involved anywhere in the MCP path. | Profile and company data | None | None | Low |
| Insaight | Vendor API key An Apify API token. No LinkedIn credentials of any kind. | Profile and company data | None | None | Low |
| eliasbiondo/linkedin-mcp-server | Browser session Your own LinkedIn account, signed in by hand in a browser window the server opens. No API key, no OAuth, no pasted credential. | Profile and company data | None | None | Medium |
| stickerdaniel/linkedin-mcp-server | Browser session Your own LinkedIn account, through a browser the server drives. No API key and no LinkedIn API. | Profile and company data, Messaging and connections | None | 2 actions | High |
| La Growth Machine MCP | Browser session A browser sign-in to La Growth Machine, not to LinkedIn. LinkedIn is reached through an identity already connected inside the workspace. | Messaging and connections | Builds the search URL only | 3 actions | High |
| Linked API MCP | Browser session Two vendor-issued API tokens, not LinkedIn credentials. You sign in to LinkedIn once, by hand, inside the vendor's cloud browser. | Profile and company data, Sales Navigator, Messaging and connections | Dedicated tools, your seat | 15 actions | High |
| gtm-api/linkedin-mcp | Browser session OAuth to the vendor for interactive clients, or a vendor bearer token for headless ones. LinkedIn is connected separately, inside the vendor dashboard. | Profile and company data, Sales Navigator, Messaging and connections | Dedicated tools, your seat | 19 actions | High |
| LinkedGrow | Browser session An API key for the MCP server. LinkedIn itself is connected separately, by entering the account's email and password in the application. | Messaging and connections | None | 5 actions | High |
| southleft/linkedin-mcp | Four credentials at once. Posting and analytics run on your own LinkedIn developer app; messaging, connections and search run on a session taken from a signed-in browser. | Profile and company data, Messaging and connections | None | 23 actions | High |
| linkedincli | A session from your own logged-in browser, replayed against LinkedIn's internal API. No OAuth, no API key, no developer app. | Profile and company data, Messaging and connections | None | 17 actions | High |
Read the row for stickerdaniel/linkedin-mcp-server and the row for linkedincli together, because both are free to run on a LinkedIn account of your own and they differ in the thing that matters: the first sends a message only when an explicit confirm flag is set, the second has no rate limiting, no dry run and no confirmation step across its 17 LinkedIn write actions. Full records, including where each one keeps your session, are on their profiles.
Paying for Advanced to feed an agent buys the agent nothing
The Sales Navigator tools in these servers are lead search, account search, profile and company reads, and Sales Navigator messaging. That is the Sales Navigator Core feature set — 50 InMail credits, the advanced lead and account search, saved lead lists and real-time alerts. What the step to Sales Navigator Advanced adds is TeamLink warm-intro paths, Smart Links, shared lists and activity writeback to the CRM, at $40 a seat a month more. 0 of the 13 servers in this directory reach TeamLink or Smart Links in any form, so the case for Advanced is a case about how a team shares its pipeline rather than about what an agent can call — and Core against Advanced is where that case is made and priced.
Each of these servers checks that the connected account already holds a subscription and fails otherwise. La Growth Machine MCP is the blunt case: its own documentation says a Sales Navigator search URL needs “an active Sales Navigator subscription to open the resulting URL... LinkedIn redirects to an upsell page otherwise.” The agent does not change what you are entitled to see.
gtm-api/linkedin-mcp registers an InMail send, and its own record notes that it spends the account's own credits. That allowance is finite and it expires: Sales Navigator Core grants 50 a month, unused credits lapse after 90 days, and a credit comes back only if the recipient replies within 90 days. An agent that sends faster does not get more — what a credit is and what it costs is the page that prices it.
A single Sales Navigator search returns at most 2,500 results, however it is called. A server that runs the search through a browser gets the same 2,500. This is the figure that decides whether a territory can be worked as one list or has to be split into several searches, and it is on the Sales Navigator limits page with the rest.
Account IQ, Lead IQ and Message Assist are LinkedIn's, they are gated by tier, and no server in this directory calls them — a server driving the interface sees whatever your seat renders. Which Sales Navigator tier unlocks which AI feature carries LinkedIn's published position and the three help articles that contradict it; what LinkedIn's own AI does across every product is the wider map.
A pipeline is sized by the account, and an agent does not enlarge the account
These apply on every plan, free or paid, and they apply whether the action comes from your hand or from a tool call. They are the reason a plan that reads well can still be unexecutable: a sequence built for two hundred invitations a week does not fail at the two-hundredth, it fails at the ceiling and takes the account with it.
| Limit | The ceiling | What it means for an agent |
|---|---|---|
| Connection invitations | ~100 per week | Applies on every plan including Recruiter Corporate. LinkedIn adjusts it per account based on acceptance rate, so a low-acceptance account gets less, never more. |
| InMail credit expiry | 90 days | Unused credits expire. They accrue to at most three times the monthly allowance, and a credit is returned if the recipient replies within 90 days. |
| Commercial use limit | Monthly search cap | Free accounts hit a monthly ceiling on profile searches. Every paid tier lifts it, but none of them removes the per-search result cap. |
| Profiles per search | 1,000 / 2,500 | Regular LinkedIn search stops at 1,000 results; Sales Navigator stops at 2,500, paginated 25 at a time. Both are per search, not per day. |
| Connection note | 300 characters | Enforced by LinkedIn and raised by no plan. A model handed no character budget writes past it, and LinkedIn truncates without warning rather than refusing. |
The invitation figure is the one to plan from: roughly 100 a week on every plan, adjusted downwards per account by acceptance rate, never upwards by an upgrade. Every figure here is dated and sourced on the LinkedIn limits page, and the safe-limits calculator turns them into a weekly number for one account. If you want the whole prospecting week sized against them rather than a server compared, the prospecting workflow is the page that does it.
Both blocks are the project's own, and they differ in what ends up on your disk
Each block below is copied unedited from the page named under it, because a config tidied by a third party is one the maintainer never ran. Read them side by side: one writes two long-lived vendor tokens into your config file, the other writes a URL and holds everything, including the LinkedIn session, on the vendor's machines. Neither block contains a LinkedIn credential, and in both cases the LinkedIn account is connected separately, by hand, inside the vendor's own browser.
Linked API MCP
The local form. Two vendor tokens sit in the env block in plaintext; the hosted form documented on the same page puts both of them in the endpoint URL instead, where they reach shell history and any proxy log in between. Neither token is a LinkedIn credential — you sign in to LinkedIn by hand, once, inside the vendor cloud browser that then holds the session.
{
"mcpServers": {
"linkedapi": {
"command": "npx",
"args": ["-y", "@linkedapi/mcp"],
"env": {
"LINKED_API_TOKEN": "{YOUR_LINKED_API_TOKEN}",
"IDENTIFICATION_TOKEN": "{YOUR_IDENTIFICATION_TOKEN}"
}
}
}
}Copied from the Linked API installation docs ↗, read 20 September 2026. The file it goes in and the key it uses differ by client: Claude Desktop, Claude Code and Cursor read an mcpServers object, VS Code reads a servers key, and a block pasted under the wrong key fails without saying so. The directory carries the four client shapes.
gtm-api/linkedin-mcp
A URL and nothing else: the consent flow runs in the browser on the first tool call, and no key is written to disk. The LinkedIn account is connected separately in the vendor dashboard, which means the session, the message history and the scraped data live on the vendor infrastructure rather than yours.
{
"mcpServers": {
"gtm-api": {
"url": "https://mcp.gtm-api.com/mcp"
}
}
}Copied from the gtm-api README ↗, read 20 September 2026. The file it goes in and the key it uses differ by client: Claude Desktop, Claude Code and Cursor read an mcpServers object, VS Code reads a servers key, and a block pasted under the wrong key fails without saying so. The directory carries the four client shapes.
The questions people arrive with, answered directly
Is there an MCP server for Sales Navigator?
3 of the 13 servers in this directory touch Sales Navigator, and none of them is LinkedIn's. 2 carry tools written for it, Linked API MCP and gtm-api/linkedin-mcp, and a third, La Growth Machine MCP, only turns a plain-English description into a Sales Navigator search URL that you open yourself. Every one of them requires you to already hold the subscription, and none of them reaches LinkedIn's Sales Navigator API, because that programme is closed: its own page says LinkedIn is not currently accepting new partners. They drive the interface with a signed-in session instead. A Core seat is $119.99 a month, read from LinkedIn on 12 September 2026.
Can an MCP server build a lead list for me?
Yes, and this is the half of sales work with a route that risks nothing of yours. 4 servers return profile, company, job and post data while holding no LinkedIn credential at all — Bright Data MCP (LinkedIn tools) and Anysite MCP Server on a data vendor's key, Insaight through Apify, Subio Scrape by reading only what LinkedIn serves a signed-out visitor. What you are buying there is somebody else's relationship with LinkedIn rather than your own exposure, and the bill is per record rather than per seat. The result is a list of people, not a list of people you have contacted: nothing in that group can write to anyone.
Can an agent send LinkedIn connection requests and messages for me?
7 of the 13 can, and not one does it through a route LinkedIn opened. LinkedIn's Messages API is why people assume otherwise. It is restricted to approved partners, and the documentation states that "A message must be associated with a specific member action. Member actions do not include an automated or scheduled event." The member must be able to edit any prepared draft and take an affirmative action to send. The only message type is member-to-member; there is no InMail. The accurate statement is not that LinkedIn has no messaging API, but that the one it has is partner-gated and prohibits the thing an agent would do with it. The Invitations API that sends a connection request is partner-gated on the same footing and appears on no self-serve permission list. So every server here that writes to a person is driving a signed-in browser or replaying a session cookie, and the activity reaches LinkedIn as yours. Every one of those 7 is rated High account exposure, and no other server in the directory is. LinkedIn's prohibited-software page bars "bots or other unauthorized automated methods to access the Services, add or download contacts, send or redirect messages, create, comment on, like, share, or re-share posts, or otherwise drive inauthentic engagement", and states that members who use them risk having their accounts restricted or shut down.
Which Sales Navigator tier do these servers need?
The subscription, not a particular tier. Both servers with dedicated tools drive lead search, account search, profile and company reads and Sales Navigator messaging — which is the Sales Navigator Core feature set, $119.99 a month or $1,079.88 a year at US list. What the step up to Sales Navigator Advanced buys is TeamLink warm-intro paths, Smart Links, shared lists and activity writeback to the CRM, at $40 a seat a month more, and 0 of the 13 servers in this directory reach TeamLink or Smart Links in any form. Paying for Advanced to feed an agent buys the agent nothing; the case for Advanced is a case about how a team shares its pipeline, and it is made on the Core-against-Advanced comparison rather than here.
Does an MCP server raise the limit on how many people I can contact?
No, and the ceilings it cannot lift are the ones that size a pipeline. Invitations run at roughly 100 a week on every plan including the ones LinkedIn will not print a price for, and LinkedIn adjusts that figure down for accounts whose invitations are not accepted. A single search returns at most 2,500 results on a Sales Navigator seat however you paginate it. A connection note is 300 characters and truncates without warning. Sales Navigator Core grants 50 InMail credits a month and unused ones expire after 90 days. All four are member-side limits, so they hold whether or not a server is involved.
Is there a free MCP server for sales prospecting?
For research, yes, with different bills attached. Subio Scrape is MIT-licensed, runs locally and costs nothing, and can see only signed-out pages. Bright Data MCP (LinkedIn tools) publishes a free monthly request allowance and charges beyond it. Insaight is free software over a metered Apify account. For outreach there is no free answer worth the name. gtm-api/linkedin-mcp has a no-cost tier for one connected account with its daily activity capped; past that, both hosted Sales Navigator servers bill per connected account. The free-to-run ones are free because you are supplying the LinkedIn account they drive, which is the expensive part. Every vendor price on a profile page here is that vendor's own figure in its own currency with the day it was read, and none of it is LinkedIn's.
What is the safest way to put LinkedIn data in front of a model for sales?
Structurally rather than carefully: hold no LinkedIn credential. 4 of the 13 servers put no account of yours behind them, so there is nothing for LinkedIn to restrict — the exposure moves to a vendor's contractual position rather than disappearing. The moment a server needs your session, the User Agreement clause and the enforcement that follows it are yours. A separate answer, if installing anything is the problem: the prompt and context-file toolkit does the research half by pasting text, with no server and no account behind it.
Do any of these work with Claude, Cursor or ChatGPT?
Each of them names its own clients and each profile page lists them from the project's documentation rather than from a guess. Both servers with dedicated Sales Navigator tools publish a remote Streamable HTTP endpoint, which is the shape a ChatGPT or Claude connector takes most easily; the free research and session-based ones are local stdio processes launched from a config file. Claude Desktop, Claude Code and Cursor all read an mcpServers object; VS Code reads a servers key instead, which is the commonest reason a working block stops working when it is moved.
Nothing on this page certifies a server as safe or compliant, because nothing in LinkedIn's documents supports that phrase. Section 8.2 of the User Agreement prohibits automated access by any means and prohibits scraping by any means, the enforcement lands on the account rather than on the software, and this site sold LinkedIn account rental until 10 September 2026 and no longer does. The exposure rating exists so that clause is in view while the choice is being made.
Decide the route before the tool
4 of the 13 servers research LinkedIn with no account of yours behind them and nothing for LinkedIn to restrict. 7 write to a person from a live session, and every one of them is rated High exposure. That split is upstream of every feature comparison, and it does not move.