Your LinkedIn account is safe with LinkMCP.
You’re about to connect your LinkedIn account to a third-party tool. That deserves a straight answer about what happens to your data, your credentials, and your account. Here it is.
The short version
Your password is never stored. It’s used once to establish a session, then discarded. We couldn’t retrieve it even if we wanted to.
Your LinkedIn session is managed on dedicated infrastructure separate from LinkMCP. We never hold your raw LinkedIn tokens.
Every action is rate-limited by default. We ship in Cautious mode – the most conservative setting – so your account behaves like a normal human user.
Every action is logged. A full, immutable audit trail records what happened, when, and why.
How connecting works
Here’s exactly what happens when you link your LinkedIn account:
You enter your credentials.
You type your LinkedIn email and password into LinkMCP’s connection page. This happens over HTTPS – your credentials are encrypted in transit from the moment you hit “Connect.”
We forward them to our session infrastructure. Immediately.
Your credentials are forwarded in a single API call to a dedicated session management layer that handles LinkedIn connections. This is the only time your password exists in our system – in memory, in transit, for the duration of that one request.
LinkedIn may ask for verification.
If you have 2FA enabled (and you should), LinkedIn will ask for a verification code, an authenticator app code, or an in-app approval. You complete that step directly. This is a good thing – it means even if someone had your password, they couldn’t connect without your second factor.
The session is established.
A session token is established with LinkedIn – the same kind of token your browser creates when you log in and check “remember me.” This token is managed on dedicated session infrastructure, isolated from LinkMCP’s application layer. LinkMCP stores only an internal reference ID to your connection. Not the token. Not your password. A reference.
Your password is gone.
At this point, your LinkedIn credentials exist nowhere in our system. Not in a database. Not in a log file. Not in a backup. Gone.
Why not LinkedIn’s official API?
This is the right question to ask. Here’s the honest answer.
LinkedIn’s official API (OAuth) gives access to posting and basic profile reads. That’s it. No messaging. No connection requests. No engagement data. No prospecting. No search.
Every LinkedIn tool that offers these capabilities – Dux-Soup, PhantomBuster, HeyReach, Lemlist, Expandi, Waalaxy, all of them – uses session-based access. It is the industry standard for full-featured LinkedIn automation, and it has been for years.
We didn’t choose this approach to cut corners. We chose it because the alternative is a tool that can only do 10% of what you need.
The important difference is how that session is managed. Most tools embed a browser extension or run headless browsers with your credentials baked in. LinkMCP uses dedicated infrastructure that specializes in secure session management – with proper token isolation, monitoring, and rotation.
What protects your account
Your password is never stored
This isn’t a policy. It’s how the code works. Your credentials pass through to our session infrastructure in a single HTTPS request and are never written to disk, database, or log. There is no mechanism to retrieve them after the connection is established.
Conservative rate limits, on by default
LinkMCP ships with four safety tiers. The default – and the one most users stay on – is Cautious.
| Tier | Multiplier | What it means |
|---|---|---|
| Cautious | 25% of base limits | The safest setting. Your account barely moves. |
| Moderate | 50% of base limits | Still well within safe territory. |
| Aggressive | 80% of base limits | Closer to LinkedIn’s thresholds. |
| Disabled | No limit | Not recommended. You’re on your own. |
You choose your tier from the dashboard and can change it at any time – no lock-in.
Automatic pacing. Every action has a minimum gap before it can fire again, plus a per-minute burst cap. There’s also a 1-second global cooldown between any two actions and a hard cap of 15 total actions per minute across your entire account.
| Action | Min. gap | Max per minute |
|---|---|---|
| Send connection request | 20 s | 2 |
| Create post | 30 s | 1 |
| Send message | 10 s | 3 |
| Send InMail | 30 s | 1 |
| Comment on post | 10 s | 3 |
| React to post | 10 s | 3 |
| Respond to connection request | 10 s | 2 |
| Search people | 5 s | 3 |
| Search Sales Navigator | 5 s | 3 |
| Get connections | 5 s | 5 |
Daily limits. On top of pacing, each action type has a daily ceiling (reset at midnight UTC). The numbers below are the base limits – your safety tier multiplier is applied on top. There’s also an account-wide daily cap of 500 total actions before the tier multiplier.
| Action | Base daily limit |
|---|---|
| Send connection request | 80 |
| Send message | 100 |
| Send InMail | 40 |
| Create post | 50 |
| Comment on post | 100 |
| React to post | 100 |
| Respond to connection request | 100 |
| Search people | 300 |
| Search Sales Navigator | 300 |
| Get connections | 100 |
So in Cautious mode, you’re limited to 20 connection requests per day, 25 messages, and 125 total actions across everything. That’s how a careful human uses LinkedIn.
Fail-closed by design. If the safety system itself is ever unavailable, all rate-limited actions are paused – not allowed through unchecked. We’d rather temporarily block your actions than risk your account.
Full audit trail
Every action LinkMCP takes on your behalf is recorded in an append-only audit log: what tool was called, what parameters were used, when it happened, and the outcome. Admins can view and search this log at any time. Entries cannot be modified or deleted.
Your 2FA works with us, not against us
If you have two-factor authentication enabled on LinkedIn, it stays active. When you connect your account, LinkedIn will prompt you for your second factor just like it would for any new login. LinkMCP fully supports 2FA, OTP codes, authenticator apps, and LinkedIn’s in-app approval flow.
This means even in the unlikely event that your LinkMCP session were compromised, an attacker could not change your LinkedIn password, email, or security settings without your second factor.
Session tokens expire
LinkedIn sessions don’t last forever. They expire periodically, and when they do, you’ll need to reconnect. This is by design – it means access is never permanent. You’re always in control of whether LinkMCP stays connected, and you can disconnect at any time from your dashboard.
Passwordless login for LinkMCP itself
LinkMCP doesn’t use passwords at all for its own authentication. You log in with a one-time verification code sent to your email. These codes are SHA-256 hashed before storage, expire in 10 minutes, and are deleted immediately after use. There is no password to steal.
Token security
API tokens (Personal Access Tokens) used to connect AI clients to LinkMCP are hashed before storage. We never store them in plaintext. The token is shown to you exactly once at creation time. Each token has a configurable expiry and can be revoked instantly.
Infrastructure security
LinkMCP is hosted on an ISO 27001 certified public cloud. All data is encrypted at rest, and all communication – between services, between you and LinkMCP, and between LinkMCP and LinkedIn – uses TLS encryption.
Nothing happens on your account without you
LinkMCP never acts on its own. Every action on your LinkedIn account is initiated by you or your AI assistant during a conversation. There is no background automation, no scheduled sequences, no actions running while you’re away.
Actions you can initiate
- Read your messages and conversations
- Send messages and connection requests
- View profiles and company pages
- Create posts, comments, and reactions
- Search for people
What LinkMCP can never do
- Act without you in the loop. Every action is requested by you or your AI assistant during an active conversation. Nothing runs in the background.
- Change your password or email. Session tokens don’t have this level of access.
- Access your LinkedIn account settings. We interact with LinkedIn the same way you do in your feed – not through admin-level access.
- Mass-export your network. Rate limits prevent bulk scraping. Actions are throttled to look like normal human usage.
- Act without a trace. Every action is audit-logged. Nothing happens silently.
Things you can do right now
Enable 2FA on LinkedIn.
If you haven’t already, turn on two-factor authentication in your LinkedIn security settings. It protects your account whether you use LinkMCP or not – and it means a session token alone can never be used to take over your account.
Review your active sessions.
LinkedIn lets you see all active sessions in Settings > Sign in & security > Where you’re signed in. You can revoke any session at any time.
Disconnect when you want.
You can disconnect your LinkedIn account from LinkMCP at any time from your dashboard. The session is terminated immediately.
Use a strong, unique LinkedIn password.
This is good practice regardless. If your LinkedIn password is the same as your email password, change it before connecting anything.
Frequently asked questions
No. LinkMCP’s default Cautious mode keeps all activity well within LinkedIn’s acceptable thresholds – just 20 connection requests per day, 25 messages, and a hard cap of 125 total actions. Every action is paced with mandatory cooldowns (see the tables above). Your account behaves like a careful human user, not a bot. And if the safety system ever goes down, actions are paused entirely rather than allowed through.
No. Your password is forwarded to our session infrastructure in a single API call and is never stored anywhere in our system. After the initial connection, only an internal reference ID exists – and that’s not your password or your raw session token.
An attacker would find hashed tokens and an internal connection reference ID. They would not find LinkedIn passwords (never stored), raw LinkedIn session tokens (managed on separate infrastructure), or plaintext API keys. Our authentication system uses SHA-256 hashing, short-lived JWTs, and refresh token rotation with automatic theft detection – if a stolen refresh token is reused, all sessions for that user are immediately revoked.
The codebase is currently private. We plan to publish security-relevant components for independent review.
No. Your data flows through LinkMCP to serve your requests and is not sold, shared, or used for any other purpose.
LinkMCP stores your account information (email, organization), an internal reference ID for your LinkedIn connection, synced conversation data (so your AI assistant can reference past messages), and audit logs. No other data obtained through your LinkedIn account is stored.
Browser extensions run in your browser and typically have broad permissions to read and modify pages. LinkMCP is a server-side application – it doesn’t inject anything into your browser or modify LinkedIn’s interface. Your LinkedIn credentials are handled server-to-server, not through browser-level access.
Our commitment
We built LinkMCP for our own use before opening it to others. Our own LinkedIn accounts are connected to it every day. The security measures described on this page aren’t marketing claims – they’re the system we trust with our own professional reputations.
If you have security questions that aren’t answered here, email us at security@linkmcp.io.