Skip to content
Field guide - 2026

Best LinkedIn MCP Servers (2026): 5 Connectors Compared

The best LinkedIn MCP server in 2026 depends on one question: do you need to read LinkedIn or send on it? For research, a data server or a self-hosted open-source server is enough. For sending, pick a hosted connector with no cookie injection that stages every send for a human to approve. That is Zevari, which we make. Every server here is third-party and unaffiliated with LinkedIn.

Most "LinkedIn MCP" lists are thin. They rank servers by GitHub stars and call it research. This one is built from the only thing that matters once you wire an MCP into Claude and start sending: does it act, and does it act without getting your account banned?

We make one of the tools on this list - Zevari. We will tell you exactly where it wins and exactly where the others are the better pick, because if you choose wrong you churn, and a churned reader is worse for us than an honest one.

The why

Why you would want a LinkedIn MCP in the first place

Claude can research a prospect better than most SDRs. It can find the needle in the haystack. But out of the box it is, in one customer's words, "handicapped - it couldn't connect directly to LinkedIn, it can't operate LinkedIn." An MCP (Model Context Protocol) server is the bridge: it gives your Claude agent hands. Search profiles, read posts, score prospects, draft messages, run campaigns, triage the inbox - from inside the AI you already think with, instead of tabbing out to a browser tool.

The catch is that LinkedIn's own API is restrictive enough that most "MCP servers" only read. The ones that write usually do it by driving a browser session with your cookies - which is the exact mechanism that gets accounts flagged. So the real spectrum is not "which server has the most tools." It is read-only vs write-enabled, and within write-enabled, cookie-based vs session-based, autonomous vs approval-gated.

The shortlist

The 20-second version

Zevari is a write-enabled LinkedIn connector with session-based access, approval-gated actions, and zero recorded ban incidents to date. Those operating constraints make the trade-offs on this list concrete rather than theoretical.

Read + safe write, approval-gated, no cookies, hosted

Zevari - the one built for outbound you actually send.

Read-focused / research helpers

CClarity, ConnectSafely - good for enrichment and lookups, not for running campaigns.

Toolkit / platform aggregator

Composio - LinkedIn is one connector among hundreds; great if you are wiring many tools, thin if LinkedIn is the job.

Open-source GitHub servers

Maximum control, zero support, and you own the ban risk. For engineers who want to read the code and run it themselves.

The full list

Five entries, reviewed fairly

Each gets: what it is, who it is for, where it is strong, where it is weak, and the verdict.

1

Zevari

The approval-gated LinkedIn MCP, with a full outbound team behind it

What it is
A hosted LinkedIn MCP connector - no browser extension, no cookie injection - with a full outbound department for LinkedIn and email behind it. Claude, Codex, ChatGPT, or any MCP client gets 190 MCP tools for search, signals, campaigns, inbox, and content, driving the same six specialists (Prospecting, Signals, ICP Scoring, Voice Writer, Follow-up, Reply Qualifier) that run in the Zevari app. Every write action (message, connection request, comment, post) is staged for a human to approve before it sends, and state lives on our infrastructure, so campaigns and schedules persist between sessions.
Who it is for
Anyone whose job is sending, not just reading. The engineer who drives outbound from Claude Code, Codex, or their own code, and the founder or agency owner who would rather let the six specialists run it from the app. Same plan either way: $87 a month or $497 a year (save 52%), extra LinkedIn accounts $37 a month.
Where it is strong
It is the only server on this list built to safely write at scale. Voice DNA trains on your sent messages so drafts sound like you, not merge-tag mail. Signal-based targeting finds people who posted about your topic in the last 30 days and scores each one against your ICP as a Strong fit, Moderate fit, or Weak fit, with written reasons. Campaigns and multi-step sequences are built and advanced by Follow-up, or by your agent. Inbox Radar classifies replies by intent and stages drafts. It warms by default - comments, reactions, profile views before the ask. And the safety model is published as numbers, not adjectives: weekly connection ceilings (150 on Free* and Premium, 200 on Sales Navigator), daily caps on all actions, working hours, behavioral pacing, duplicate checks, burst caps, a year of refinement, zero ban incidents.
Where it is weak (honestly)
It is opinionated about LinkedIn. It does not try to be a general agent toolkit - if you want one connector among two hundred, that is Composio, not us. It is one LinkedIn account per workspace (sub-accounts at $37 each), so multi-client setups need a workspace per client - deliberate, but worth knowing. And the surface is broad enough that some non-technical buyers tell us "you can do so much, you need guidance" - which is why the app lets the six specialists run it while you only review.
Verdict
If you intend to run real outbound from Claude and the sentence "I don't want to be banned" is anywhere in your head, this is the entry to start with. Drive it from Claude Code or Codex, or let the six specialists run it in the app - every send waits for your approval either way, until a specialist has earned autopilot.
2

CClarity

Research and enrichment helper

What it is
A LinkedIn-data MCP server focused on lookups and enrichment - pulling profile and company data into your agent's context so it can research and personalize.
Who it is for
Engineers who want Claude to read LinkedIn well - enrich a list, research an account, pull context before a meeting - and who handle the actual sending somewhere else.
Where it is strong
Clean for the read path. If your workflow is "research and enrich, then export," a focused data server does that job without the weight of a full outbound engine.
Where it is weak (honestly)
It is not built to run safe, approval-gated outbound campaigns at scale. There is no Voice DNA, no signal-based campaign engine, no staged-write approval surface, no published ban-safety mechanics. When the job moves from "read about them" to "send to them, safely, every day," you outgrow it.
Verdict
A reasonable read/enrichment pick. We share a buyer, not a category - if your need is research, it may be all you need. The moment you need to send and not get banned, you are in write-enabled territory.
3

ConnectSafely

Lightweight, safety-conscious connector

What it is
A lighter-weight LinkedIn MCP server that leans on a careful, limits-aware posture for basic LinkedIn actions from an agent.
Who it is for
Engineers who want a small, comprehensible connector for light LinkedIn tasks and are comfortable owning the operational details themselves.
Where it is strong
Simplicity. A smaller surface is easier to reason about, and a safety-first framing is the right instinct - bans are the real risk, and any tool that takes that seriously is starting from the right place.
Where it is weak (honestly)
Light means light. You do not get a campaign engine, signal-based targeting, ICP scoring with reasons, Inbox Radar, or Voice DNA - and "safety-conscious" as a posture is not the same as published, enforced ceilings with a year of zero-incident production behind them. For one-off actions, fine. For a daily outbound motion, you will hit the ceiling of what a light connector can carry.
Verdict
A sensible minimalist option for light, careful use. If outbound is your actual job, you will want the heavier, receipt-backed engine.
4

Composio

The platform aggregator

What it is
Not a LinkedIn tool - a tool-integration platform that exposes hundreds of app connectors (LinkedIn among them) to agents through MCP, with auth and orchestration handled centrally.
Who it is for
Engineers building agents that touch many SaaS apps and want one integration layer for all of them. LinkedIn is one line item in a much larger build.
Where it is strong
Breadth and plumbing. If you are wiring Claude into Salesforce, Gmail, Slack, Notion, and LinkedIn at once, a single aggregator with managed auth is a genuinely good architectural call. That is real value, and it is value Zevari does not try to provide.
Where it is weak (honestly)
LinkedIn is a connector, not a craft. You will not get Voice DNA, signal-based ICP scoring, warm-by-default sequencing, a staged-write approval model purpose-built for LinkedIn, or published ban-safety mechanics - because that depth only exists in a tool whose entire reason to live is LinkedIn. A generic connector that "can call the LinkedIn API" is not the same thing as a system designed so you don't get your account banned doing it.
Verdict
The right choice when LinkedIn is one of many integrations. The wrong choice when LinkedIn outbound is the job - then you want depth, not breadth, and the two stack fine together.
5

Open-source GitHub LinkedIn MCP servers

DIY, self-hosted, you own the risk

What it is
A handful of community MCP servers on GitHub that wrap LinkedIn actions. Quality ranges from solid read-only research tools to ambitious projects that drive a logged-in browser session to send.
Who it is for
Engineers who want to read the source, self-host, and own every part of the stack - and who treat the LinkedIn account risk as theirs to manage.
Where it is strong
Control and cost. The code is in front of you, you can fork it, and there is no subscription. For a read-only research server you run yourself, that is a clean, cheap, transparent setup.
Where it is weak (honestly)
Two things. First, the write-enabled ones almost universally do it through browser automation with your cookies - which is precisely the mechanism behind the after-stories we hear constantly: "my account kept getting banned with the virtual assistants - LinkedIn just sees logs." Second, there is no one to call. No hosted state (so your agent can't keep persistent schedules), no support, no safety SLA, no approval surface unless you build it. You are the maintainer, the on-call, and the one whose account is on the line.
Verdict
Great for engineers who want a read-only server they fully control. Genuinely risky as a write-enabled outbound engine - the ban risk is real and it lands on your account, not a vendor's.

At a glance

The honest comparison

Every tool here does a real job for a real buyer. The column that decides it for an outbound team is the one most lists skip: can it write safely, and can it prove it?

Zevari

Primary job
Outbound department + MCP
Write to LinkedIn?
Yes - full campaigns
Connection model
Hosted, no cookie injection
Approval gate
Every write staged
Published ban-safety
Yes - numbers published, zero incidents in a year
Hosted state
Yes
Best for
Running real outbound from Claude

CClarity

Primary job
Research / enrichment
Write to LinkedIn?
Read-focused
Connection model
Data API
Approval gate
n/a
Published ban-safety
No
Hosted state
No
Best for
Enriching and researching

ConnectSafely

Primary job
Light connector
Write to LinkedIn?
Limited
Connection model
Limits-aware
Approval gate
Partial
Published ban-safety
Posture, not published numbers
Hosted state
No
Best for
Light, careful actions

Composio

Primary job
Many-app toolkit
Write to LinkedIn?
Via generic connector
Connection model
Managed auth
Approval gate
n/a
Published ban-safety
No
Hosted state
Platform-level
Best for
LinkedIn as one of many integrations

OSS GitHub

Primary job
DIY, self-hosted
Write to LinkedIn?
Some, via browser/cookies
Connection model
Often cookie-based
Approval gate
Build it yourself
Published ban-safety
No
Hosted state
No
Best for
Engineers who want full control, read-only

The decision

How to actually choose

Answer one question first: are you reading or sending?

If you are reading - researching accounts, enriching lists, pulling context - a focused data server (CClarity), a light connector (ConnectSafely), or a self-hosted OSS read-only server is plenty, and probably cheaper.

If you are building an agent that touches many apps and LinkedIn is one of them, Composio is the clean architectural answer.

If you are sending - running outbound, campaigns, follow-ups, the inbox - the question collapses to safety. A write-enabled server that drives your browser with cookies is the model behind most ban stories. A session-based, approval-gated, hosted server with published limits is the model built so that doesn't happen. That is the entry Zevari is on this list to be.

Safety

"I don't want to be banned." That is the whole game.

The number one fear in LinkedIn outbound is the ban. Cookie-based browser automation - how most write-enabled servers touch LinkedIn - is exactly what triggers it. Zevari was built for this: session-based, approval-gated, paced, and capped, with the limits published as numbers. A year of refinement. Zero ban incidents.

Read the full safety model
Every write action - message, connection request, comment, post - is staged for your approval before it touches your account.
Hosted connector. No browser extension, no cookie injection.
Weekly connection ceilings enforced by the platform: 150 on Free* and Premium, 200 on Sales Navigator.
* Free accounts: LinkedIn caps connection requests that carry a note at 5 a month. The weekly ceiling covers requests sent without a note, and Premium and Sales Navigator accounts get a far larger allowance for requests with a note. Most outreach uses a note, so Premium or Sales Navigator is the practical choice for real outbound - the full explanation is on /safety.
Daily caps on all actions, working hours, behavioral pacing, duplicate checks, and burst caps - a year of refinement, zero ban incidents.

Two ways in

For the engineer, and for the owner

Same approval-gated engine on both lanes. Reach Zevari over MCP for Claude Code and Codex, or our REST API from your own code.

For the engineer ($87 a month)

Skip the evaluation theater. Connect Zevari to Claude Code or Codex, get 190 MCP tools for search, signals, campaigns, inbox, and content, and drive the six specialists with human approval gates already wired in. Hosted state keeps your campaigns and schedules alive between sessions - the persistent scheduling Claude Code or Codex can't do alone. Sub-accounts are $37 each. 7-day free trial, cancel anytime.

Connect to Claude Code

For the owner (let the team run it)

Rather not operate an MCP client? The same six specialists, Prospecting, Signals, ICP Scoring, Voice Writer, Follow-up, and Reply Qualifier, run your LinkedIn and email outbound from the Zevari app. Sends wait for your approval by default. One plan, $87 a month or $497 a year (save 52%).

Build my AI team

FAQ

The questions buyers ask

What is a LinkedIn MCP server?

An MCP (Model Context Protocol) server is a bridge that gives a Claude agent hands on LinkedIn - the ability to search profiles, read posts, score prospects, draft messages, run campaigns, and triage the inbox from inside Claude instead of from a browser tool. Without one, Claude can research LinkedIn but cannot operate it. Several exist in 2026, all built by third parties; this page compares five.

Is there an official LinkedIn MCP server?

Every server on this list, Zevari included, is built by a third party and is not affiliated with, endorsed by, or sponsored by LinkedIn. So judge a LinkedIn MCP connector on what you can verify: how it connects (hosted, or a browser session driven with your cookies), whether it can write or only read, and whether a human approves each send.

Which is the best LinkedIn MCP server in 2026?

For sending, Zevari: a hosted connector with no cookie injection that stages every send for your approval, publishes its limits, and has a year of production with zero ban incidents. For research only, a focused data server or a self-hosted open-source read-only server is enough. The deciding question is whether you need to read LinkedIn or send on it.

Will a LinkedIn MCP server get my account banned?

It can, and that is the most important question on this page. Most write-enabled servers - especially open-source ones - drive a logged-in browser session with your cookies, which is the mechanism behind most ban stories ("LinkedIn just sees logs"). Zevari is a hosted connector with no browser extension and no cookie injection, stages every write action for human approval, and enforces weekly connection ceilings (150 on Free* and Premium, 200 on Sales Navigator), daily action caps, working hours, behavioral pacing, duplicate checks, and burst caps - a year of refinement with zero ban incidents.

Do most LinkedIn MCP servers only read, or can they write?

Most only read, because LinkedIn's API is restrictive. The ones that write usually do it through cookie-based browser automation, which carries ban risk. Write-enabled, approval-gated, session-based servers are rare - Zevari is built specifically to write safely.

Can I use a LinkedIn MCP server without LinkedIn Sales Navigator?

Yes. You can start without it. Sales Navigator only raises your weekly connection limit (to 200 versus 150 on Free* and Premium) - it is not required to run a LinkedIn MCP server like Zevari. The weekly figure covers connection requests sent without a note: LinkedIn caps requests that carry a note at 5 a month on a free account, and gives Premium and Sales Navigator a far larger allowance, so Premium or Sales Navigator is the practical choice for real outbound (see /safety).

Are open-source LinkedIn MCP servers safe to use?

Read-only ones are generally fine and give you full control of the code. Write-enabled open-source servers are the risk: they typically send through browser automation with your cookies, there is no hosted state or support, and the ban risk lands entirely on your account. If you send at any real volume, a hosted server with published safety limits and an approval gate is the safer call.

I'm not technical. Can I still use a LinkedIn MCP server?

Yes. You do not need an MCP client at all. Zevari's six specialists run LinkedIn and email outbound from the Zevari app, and you review sends in minutes a day. $87 a month, or $497 a year (save 52%), with a 7-day free trial.

Start with the one built to send, safely

Same approval-gated engine on both lanes. Reach Zevari over MCP for Claude Code and Codex, or our REST API from your own code.

You run Claude Code or Codex

Give your agent hands on LinkedIn - signal-based, ban-safe, in your voice. Connect over MCP for Claude Code and Codex, or call our REST API from your own code.

Connect to Claude Code

Let the team run it

Don't run Claude Code or Codex? The same six specialists, Prospecting, Signals, ICP Scoring, Voice Writer, Follow-up, and Reply Qualifier, run your LinkedIn and email outbound from the Zevari app. Sends wait for your approval by default.

Build my AI team

Zevari - a full outbound department for LinkedIn and email, running today.