LinkedIn MCP Server uses browser automation against an authenticated LinkedIn account., Tools can read profile, company, job, feed, inbox, and conversation data available to the authenticated session., Some tools can initiate social or messaging actions, such as sending messages or connection requests, so require explicit human confirmation before any account-write action., The server stores browser profile state locally and provides logout/profile management options that can clear authentication state., Respect LinkedIn account rules, rate limits, consent boundaries, and workplace policies before scraping, messaging, or automating professional-network workflows.
Privacy notes
LinkedIn profile data, search queries, company data, job details, inbox metadata, conversation text, feed posts, messages, connection notes, browser cookies, prompts, and tool outputs may be visible to the MCP client and model provider., LinkedIn data can include personal information, employment history, contact details, recruiting plans, sales targets, private messages, and relationship context., Treat the persisted browser profile as sensitive account state and avoid exposing it through logs, screenshots, shared volumes, or untrusted containers.
Author
Daniel Sticker
Submitted by
oktofeesh1
Claim status
unclaimed
Last verified
2026-06-05
Decision playbook
Review trust signals before you adopt
Signals are present but mixed. Use the checklist below to confirm the source and operational safety for your environment.
Compare context
Selected
0
Current score
63
Baseline
—
Delta
No baseline selected
No major trust-signal divergence detected in the current selection.
Source and provenance checks
Needs review
Confirm ownership and provenance before trusting install instructions.
Source link availableRequired
Open the canonical repository and verify ownership.
Done
Source provenance statusRequired
Marked as source-backed.
Done
Metadata reviewed
No reviewed flag detected in metadata.
Pending
Safety and privacy checks
Complete
Validate risk disclosures before installation or API wiring.
Safety notes presentRequired
Review the listed safety guidance before running commands.
Done
Privacy notes presentRequired
Review data handling notes before connecting accounts or secrets.
Done
Trust level risk gateRequired
Trust level does not block evaluation.
Done
Package and install checks
Needs review
Check package metadata and artifact integrity signals.
Install payload available
Install or copy payload is available for review.
Done
Package verification flag
No package verification flag provided.
Pending
Checksum metadata
No checksum provided for downloaded artifact.
Pending
Compare-driven decision checks
Needs review
Use compare context to validate trade-offs before adoption.
Compare tray has multiple entries
Add at least one more entry to compare trust differences.
5 safety and 3 privacy notes across 6 risk areas. Review closely: credentials & tokens, network access, third-party handling.
6 areas
SafetyGeneralLinkedIn MCP Server uses browser automation against an authenticated LinkedIn account.
SafetyCredentials & tokensTools can read profile, company, job, feed, inbox, and conversation data available to the authenticated session.
SafetyNetwork accessSome tools can initiate social or messaging actions, such as sending messages or connection requests, so require explicit human confirmation before any account-write action.
SafetyLocal filesThe server stores browser profile state locally and provides logout/profile management options that can clear authentication state.
SafetyNetwork accessRespect LinkedIn account rules, rate limits, consent boundaries, and workplace policies before scraping, messaging, or automating professional-network workflows.
PrivacyThird-party handlingLinkedIn profile data, search queries, company data, job details, inbox metadata, conversation text, feed posts, messages, connection notes, browser cookies, prompts, and tool outputs may be visible to the MCP client and model provider.
PrivacyData retentionLinkedIn data can include personal information, employment history, contact details, recruiting plans, sales targets, private messages, and relationship context.
PrivacyLocal filesTreat the persisted browser profile as sensitive account state and avoid exposing it through logs, screenshots, shared volumes, or untrusted containers.
Safety notes
LinkedIn MCP Server uses browser automation against an authenticated LinkedIn account.
Tools can read profile, company, job, feed, inbox, and conversation data available to the authenticated session.
Some tools can initiate social or messaging actions, such as sending messages or connection requests, so require explicit human confirmation before any account-write action.
The server stores browser profile state locally and provides logout/profile management options that can clear authentication state.
Respect LinkedIn account rules, rate limits, consent boundaries, and workplace policies before scraping, messaging, or automating professional-network workflows.
Privacy notes
LinkedIn profile data, search queries, company data, job details, inbox metadata, conversation text, feed posts, messages, connection notes, browser cookies, prompts, and tool outputs may be visible to the MCP client and model provider.
LinkedIn data can include personal information, employment history, contact details, recruiting plans, sales targets, private messages, and relationship context.
Treat the persisted browser profile as sensitive account state and avoid exposing it through logs, screenshots, shared volumes, or untrusted containers.
Prerequisites
Python 3.12 through 3.14 available to the MCP client runtime.
uvx available for package execution.
LinkedIn account access for the workflows you want Claude to perform.
One-time browser login, including any LinkedIn two-factor, mobile confirmation, or captcha challenge.
Local storage available for the persisted LinkedIn browser profile and Patchright browser cache.
LinkedIn MCP Server connects MCP clients to LinkedIn through an authenticated
browser session. It can inspect people profiles, the authenticated user's own
profile, sidebar profile recommendations, inboxes, conversations, companies,
company posts, employees, people search, job search, job details, and feed
content. It also exposes action-oriented tools for messages and connection
requests that should stay behind explicit approval.
The upstream README documents uvx, Docker, MCPB, and Streamable HTTP setup
paths. The supported PyPI package is linkedin-scraper-mcp, which exposes both
linkedin-scraper-mcp and linkedin-mcp-server console scripts.
These sources were reviewed on 2026-06-05. Prefer the live repository and
PyPI metadata for current package version, command name, Python requirement,
dependencies, authentication behavior, supported tools, and setup guidance.
Features
Read LinkedIn person profiles with selectable sections.
Read the authenticated user's own profile.
Search people by keyword, location, connection degree, and company.
Inspect company profiles, company posts, employees, and company search.
Search jobs and retrieve job details.
Read recent feed posts from the authenticated account.
Read inbox and conversation data available to the session.
Send messages or connection requests when explicitly approved.
Reuse a persisted browser profile after interactive login.
Restart the MCP client after adding the server. On first use, complete the
interactive LinkedIn login flow in the browser window before retrying LinkedIn
tools.
Use Cases
Ask Claude to inspect a LinkedIn profile before a recruiting or sales call.
Search for people by company, location, keyword, or connection degree.
Research company profiles, posts, employees, and open roles.
Summarize job details for a candidate or hiring workflow.
Review inbox or conversation context before drafting a reply.
Draft a connection note or message for human approval before sending.
Safety and Privacy
LinkedIn automation operates through a real authenticated account. Keep message
sending, connection requests, and other account-write actions behind explicit
human confirmation. Avoid broad scraping, high-volume automation, or workflows
that violate LinkedIn rules, workplace policy, or recipient consent.
The persisted browser profile, cookies, LinkedIn messages, profile data,
company research, job searches, feed content, and relationship context are
sensitive. Treat local profile directories and mounted volumes as account
secrets, and avoid sharing logs or screenshots that expose LinkedIn session
state.
Duplicate Check
No stickerdaniel/linkedin-mcp-server entry, linkedin-scraper-mcp package
entry, or matching source URL was found in content/mcp.
Show that LinkedIn MCP Server is listed on HeyClaude. Paste this Markdown into your README — it renders the badge and links back to this page.
[](https://heyclau.de/entry/mcp/linkedin-mcp-server)
How it compares
LinkedIn MCP Server side by side with 3 alternatives on trust, install, platform support, and disclosed safety notes — all from reviewed registry metadata.
2 trust signals differ across this comparison (Source provenance, Submitter).
DataForB2B remote MCP server exposing people and company search, enrichment, and agentic discovery over 800M+ profiles and 75M+ companies via streamable HTTP.
✓LinkedIn MCP Server uses browser automation against an authenticated LinkedIn account.
Tools can read profile, company, job, feed, inbox, and conversation data available to the authenticated session.
Some tools can initiate social or messaging actions, such as sending messages or connection requests, so require explicit human confirmation before any account-write action.
The server stores browser profile state locally and provides logout/profile management options that can clear authentication state.
Respect LinkedIn account rules, rate limits, consent boundaries, and workplace policies before scraping, messaging, or automating professional-network workflows.
✓People search and enrichment tools can return emails, titles, and employer metadata; handle as regulated personal data.
Agentic search may issue broader queries than manual filters; review results before automated outreach.
Bearer tokens grant billable API access; store them in MCP headers or env vars, not in chat.
Do not use exported contact data for unsolicited outreach that violates local privacy laws.
✓send_message and related tools can deliver content to other agents or channels.
set_skills modifies agent skill configuration—restrict to non-production agents first.
✓Email tools can send outbound mail from your `@agenttrust.ai` address.
Messaging tools can contact other agents and escalate to humans via HITL flows.
Drive tools upload, download, and delete files—confirm destructive operations.
Ed25519 signing keys are generated locally; back up `~/.agenttrust` before rotation.
Privacy notes
✓LinkedIn profile data, search queries, company data, job details, inbox metadata, conversation text, feed posts, messages, connection notes, browser cookies, prompts, and tool outputs may be visible to the MCP client and model provider.
LinkedIn data can include personal information, employment history, contact details, recruiting plans, sales targets, private messages, and relationship context.
Treat the persisted browser profile as sensitive account state and avoid exposing it through logs, screenshots, shared volumes, or untrusted containers.
✓Search filters, domains, and profile identifiers are processed by DataForB2B and its data vendors.
API keys are credentials; rotate them if exposed in logs, issues, or shared connector configs.
Data is sourced from publicly available and verified sources per DataForB2B compliance statements.
✓Messages, channel metadata, and agent lists enter MCP client context and vendor logs.
Store Bearer tokens in secret managers—not repository files.
✓Email bodies, attachments, messages, and uploaded files are processed by AgentTrust.
Signing keys and API keys are stored locally with 0600 permissions but still require host protection.
Outbound email from address is enforced server-side to your agent's `@agenttrust.ai` identity.
Prerequisites
Python 3.12 through 3.14 available to the MCP client runtime.
uvx available for package execution.
LinkedIn account access for the workflows you want Claude to perform.
One-time browser login, including any LinkedIn two-factor, mobile confirmation, or captcha challenge.
DataForB2B API key with an active credit plan from https://dataforb2b.ai.
Claude Pro, Team, or Enterprise with Connectors support, or another MCP client with remote HTTP transport.
Compliance review for GDPR and CCPA obligations when exporting people or company data.
Understanding that each successful search or enrichment consumes credits.
AgentDM account at agentdm.ai.
OAuth client setup or API key for Bearer authentication.
Review of which agents and channels the MCP client may message.
AgentTrust account with a registered agent and API key (`atk_...`).
Node.js for the `@agenttrust/mcp-server` npm package.
Claude Desktop, Claude Code, Cursor, or another MCP client with stdio transport.
Optional interactive setup via `npx @agenttrust/mcp-server init` for Ed25519 signing keys.
Install
uvx linkedin-scraper-mcp@latest
claude mcp add --transport http dataforb2b https://mcp.dataforb2b.ai/mcp