Skip to content
August 2026 · updated 2026-08-25

Is LinkedIn Automation Safe? No, in Three Different Ways

LinkedIn automation is not safe, and the architecture you buy decides which clause of the User Agreement you are outside, what evidence you leave, and whose account absorbs the restriction.

Here's the trap. Two LinkedIn tools sit in front of you at $79 and $99 a month. One calls itself cloud-based, one needs a Chrome extension, and the cloud one reads as the grown-up option because somebody else runs the servers. So you buy that one, paste in a session cookie, and a machine in a data centre you have never seen starts acting as you on an account that is yours rather than your employer's, and that carries fifteen years of your network.

The problem is that the word on the pricing page is a marketing word and the thing underneath it is a wiring decision. LinkedIn's User Agreement bans every route these tools take, and it bans them in three separate clauses. One clause names browser plugins and add-ons. One names bots. One names copying cookies. Choosing between tools in the LinkedIn and social category does not move you inside the rules. It moves you between clauses.

That is a real cost and it lands on a person, not a company. A restricted LinkedIn profile takes the connection graph with it, and the graph is the only part of the stack you cannot repurchase. You will not learn which architecture you are buying from a pricing page, because the vendors that hold your session cookie are the ones least likely to print the word cookie.

Nothing on this page is a measurement. No ban rates, no restriction counts, no controlled comparison of one architecture against another. Every vendor claim is quoted with the date it was read, every legal fact carries a docket number you can pull yourself, and this is a description of published terms and public court records rather than legal advice. Where a question can only be answered by risking a live account, this page says so.

What follows: the three shapes and how to tell which one you are buying, the three User Agreement clauses that name them, what hiQ Labs v. LinkedIn actually held against what almost every ranking page says it held, five further enforcement dockets, LinkedIn's own published detection percentages, a ten-tool architecture table, a 25-minute audit you run before entering a card, and the answer to the question in the title stated flat.

So is LinkedIn automation safe?

No. Not one of the tools in this category is permitted by the platform it runs on, and the two vendors that state this most clearly are both selling the thing they are describing. HeyReach's own write-up of its 2026 takedown says it in one line: "LinkedIn's User Agreement explicitly bans software that automates connecting, messaging, liking, and commenting" [vendor], read 25 August 2026.

La Growth Machine's safety page says "LinkedIn does explicitly forbid the use of tools that perform automated actions without human intervention" [vendor], read 21 August 2026. Both sentences are true and both sit on the site of a tool that performs automated actions without human intervention.

What varies between the eleven tools on this page is not permission. It is exposure: which credential leaves your machine, which IP address the traffic arrives from, whether the tool acts while you are asleep, and what a restriction actually touches when one lands. Those four answers are fixed by the architecture, and the architecture is knowable from outside the product. You can usually establish it from three published pages in under half an hour.

There is one sanctioned path and it does none of what you want. LinkedIn Sales Navigator at $119.99 a month per seat [vendor, read 12 August 2026] is a research surface with deliberately restricted export.

Its API programme is closed: LinkedIn's own developer documentation states "We are not currently accepting new partners for access to the LinkedIn Sales Navigator API" [vendor, read 25 August 2026]. So no tool launched into this category can become an official partner today, however it markets itself, and none of the eleven below claims to be one.

The three architectures, and how to tell which one you bought

Architecture here means one thing: where the code that clicks the connect button is running, and whose credentials it is using when it clicks. Everything else on a LinkedIn tool's feature list sits downstream of that answer. There are three shapes and they are not close relatives.

Shape one: the browser extension

The code runs inside your own Chrome profile, on your own network, using the session you are already logged into. It works only while the browser is open and the tab is alive. Nothing leaves your machine except the results.

Dux-Soup, which has run this shape since 2015 and reports 300,000 users on its homepage [vendor, read 25 August 2026], puts the selling point plainly: "Dux-Soup works on your native LinkedIn, Recruiter or Sales Navigator account. With no third party access required, we guarantee optimal safety of your LinkedIn account." Read that as a vendor claim, not a finding. No vendor can guarantee the behaviour of somebody else's detection system.

Shape two: the cloud proxy holding your session

The code runs on the vendor's servers. To act as you it needs your session, which it takes either as an exported `li_at` cookie or, in at least one case, as your LinkedIn email and password. To stop your session appearing from a data centre in another country, the vendor assigns you an IP address that looks residential.

HeyReach describes its version in as many words: "HeyReach gives each LinkedIn account its own dedicated static residential proxy, a real IP address that never rotates and is never shared with another account" [vendor, read 25 August 2026].

The convenience is real. It runs while your laptop is shut, which is the whole reason agencies buy this shape. So is the exposure: a third party now holds a live credential to an account you personally own, and acts with it when you are not there to see what it did.

Shape three: the official API partner

The tool holds a signed agreement with LinkedIn and calls documented endpoints under the Sales Navigator Application Platform terms. No session cookie, no proxy, no ban exposure of the kind the other two carry, and no ability to send connection requests on your behalf at volume either, because the sanctioned surfaces are display modules, analytics exports and CRM sync rather than an automation bus [vendor, read 25 August 2026]. This shape is closed to new entrants and is not what anybody selling you LinkedIn outreach in 2026 is running.

Why LinkedIn's terms name all three, separately

Section 8.2 of the LinkedIn User Agreement is a list of things a member agrees not to do. Three of its bullets read as though they were drafted with these three architectures on the table, and they were separated on purpose, because they describe different acts. Quoted verbatim from the current text, read 25 August 2026:

  • The extension clause. "Develop, support or use software, devices, scripts, robots or any other means or processes (such as crawlers, browser plugins and add-ons or any other technology) to scrape or copy the Services, including profiles and other data from the Services". A Chrome extension is named inside the parenthesis.
  • The cookie clause. "Create a false identity on LinkedIn, misrepresent your identity, create a Member profile for anyone other than yourself (a real person), or use or attempt to use another's account (such as sharing log-in credentials or copying cookies)". Exporting your session cookie to a vendor is the example the clause gives.
  • The bot clause. "Use bots or other unauthorized automated methods to access the Services, add or download contacts, send or redirect messages, create, comment on, like, share, or re-share posts, or otherwise drive inauthentic engagement". This one covers the action itself, whatever the wiring.

Notice what that does to the usual pitch. The cloud tools sell themselves against extensions on the ground that an extension is the amateur option, and the extension tools sell themselves against the cloud on the ground that nothing leaves your machine. Both are describing a real difference. Neither is describing a safe harbour, because both are separately named, and the bot clause catches whatever the first two miss. Section 8.2 also survives termination of the contract, which the agreement states explicitly in its termination section.

ArchitectureWhich 8.2 clause names itCredential that leaves your machineWhose IP the action arrives fromRuns while you sleepBasis
Browser extension"browser plugins and add-ons"NoneYoursNo[vendor] LinkedIn UA 8.2, read 2026-08-25
Cloud proxy"copying cookies" plus the bot clauseSession cookie, or in one case email and passwordVendor-assigned, marketed as residentialYes[vendor] UA 8.2 plus vendor docs
Hybrid (extension captures, cloud acts)All three, in sequenceSession cookieMixed, and the mix is usually not publishedYes[arch] consequence of the two above
Official API partnerNone. Permitted under a signed agreementNoneVendor's, under contractYes[vendor] SNAP terms, read 2026-08-25

Whose account actually gets restricted?

Yours. This is the part the architecture debate tends to skip. Every one of these tools acts through a member account, and the member account is the unit LinkedIn restricts. The vendor's relationship with LinkedIn is separate, and a bad outcome for the vendor is not automatically a bad outcome for you.

The clearest documented example is HeyReach's own. Its company page and several executive profiles were removed or restricted on 25 March 2026, an account the company published itself and which this site corroborated against independent write-ups [vendor plus verified-secondary, 21 August 2026]. We covered the fallout for agencies running many client accounts in the agency tooling post.

HeyReach's framing of it is worth quoting because it is correct and against its own short-term interest: "A vendor page ban and an individual account restriction are two separate things. Your account's safety depends entirely on your own account's behavior, sending volume, pace, and consistency, not on what happens to HeyReach's brand presence" [vendor, read 25 August 2026]. Treat the second half as the vendor's position rather than an established fact, because nobody outside LinkedIn can see whether tool attribution feeds restriction decisions.

The inverse also happens, and it is the case that should worry a careful buyer more. On Hacker News item 37748263 (3 October 2023, 36 points, 65 comments) a user describes being permanently restricted after appeal, and in the thread adds: "Last month they restricted my account and they told me that I am using an automation tool. I said that I am not" [thread].

That is one person's account and not a finding of fact. It is still the cleanest illustration available of the asymmetry: the accusation arrives as an automated notice, the appeal is answered by another automated notice, and the burden of proving a negative sits with the member.

What hiQ v. LinkedIn actually decided

Almost every page ranking on scraping legality tells you hiQ won and public data is fair game. hiQ lost. It paid LinkedIn $500,000, accepted a permanent injunction barring it from LinkedIn for good, and stipulated that LinkedIn could establish liability under the Computer Fraud and Abuse Act. All of that is in docket 3:17-cv-03301 in the Northern District of California, before Judge Edward M. Chen, terminated 9 December 2022 [docket].

The confusion is understandable, because the case really did produce two pro-scraping appellate opinions. Both were about a preliminary injunction, decided on a standard the Ninth Circuit repeated roughly ten times in the 2022 opinion: whether hiQ had "raised serious questions going to the merits." The court's own conclusion is one sentence long: "We AFFIRM the district court's determination that hiQ has established the elements required for a preliminary injunction and remand for further proceedings" [docket, 31 F.4th 1180, 18 April 2022].

That is not a ruling that scraping is lawful. It is a ruling about who gets to keep operating while the case is tried, and the case then went the other way.

The same opinion flagged the door LinkedIn would later walk through: "Entities that view themselves as victims of data scraping are not without resort, even if the CFAA does not apply: state law trespass to chattels claims may still be available. And other causes of action, such as copyright infringement, misappropriation, unjust enrichment, conversion, breach of contract, or breach of privacy, may also lie." LinkedIn amended its counterclaims on 29 June 2022 and pleaded exactly those.

DateStepWhat it heldWhat it did not hold
2017-05-23LinkedIn cease-and-desist to hiQNothing. A letterNot a court finding of anything
2017-08-14N.D. Cal. grants preliminary injunction, 273 F. Supp. 3d 1099hiQ may keep scraping public profiles pending trialDid not decide the merits
2019-09-099th Cir. affirms, 938 F.3d 985Serious question whether CFAA reaches public pagesDid not decide whether hiQ breached the contract
2021-06-14Supreme Court GVRs in light of Van BurenJudgment vacated, sent backNot a reversal on the merits
2022-04-189th Cir. affirms again, 31 F.4th 1180Public profiles are not "without authorization" computersExpressly left trespass and contract claims open
2022-06-29LinkedIn files amended counterclaimsNothing yet. AllegationsNot an admission by hiQ
2022-10-27Summary judgment order, docket entry 404User Agreement "unambiguously prohibits" the scraping; hiQ liable for its contractors' fake accountsDid not resolve hiQ's waiver and estoppel defences
2022-12-08Consent judgment and permanent injunction, entry 406$500,000 to LinkedIn; permanent injunction; source code and data destroyedA settlement, so no judicial finding on the remaining claims

Three details from the record that no summary carries. The 27 October 2022 order found hiQ liable for breach through its contractors after quoting hiQ's own training document: "It is a good idea to make a fake account with a fake email, to deal with the possibility of being banned on LinkedIn."

The sanctions portion of the same order let the jury presume that "hiQ's scrapers made at least fifty billion requests on LinkedIn's servers." And in the 6 December 2022 stipulation hiQ agreed LinkedIn "has established that it has incurred a loss of at least $5,000 in a one-year period," which is the exact statutory threshold for a civil CFAA claim [docket].

A settlement is not an admission and a stipulation entered to close a case is not a judicial finding on the merits. What is a finding is the 27 October 2022 summary judgment order, and it went against hiQ on the contract question. If you take one thing from this section: the CFAA and the User Agreement are different instruments, and the tools discussed on this page operate logged in, which is the situation the Ninth Circuit expressly did not clear.

How often does LinkedIn actually sue?

Regularly, and at every layer of the stack. A CourtListener search of RECAP dockets with LinkedIn Corporation as plaintiff, run 25 August 2026, returns six actions of this type across twelve years [docket]. Two of them were still live when this was written, which means their contents are allegations and nothing more.

CaseDocketCourtFiledNaturePosture
LinkedIn Corporation v. Robocog Inc5:14-cv-00068N.D. Cal.2014-01-06Federal question, scrapingTerminated 2014-07-16 [docket]
LinkedIn Corporation v. Does 1 through 1005:16-cv-04463N.D. Cal.2016-08-08Federal question, unnamed scrapersTerminated 2020-05-21 [docket]
hiQ Labs, Inc. v. LinkedIn Corporation3:17-cv-03301N.D. Cal.2017-06-07Declaratory judgment, counterclaims for breachTerminated 2022-12-09, consent judgment [docket]
LinkedIn Corporation v. Mantheos Pte. Ltd.4:22-cv-00651N.D. Cal.2022-02-01Lanham Act 15:1125Terminated 2022-05-09 [docket]
LinkedIn Corporation v. TopSocial245:23-cv-00110N.D. Cal.2023-01-10Breach of contract, fraud, interferenceTerminated 2023-10-23 [docket]
LinkedIn Corporation v. Nubela Pte. Ltd.3:25-cv-00828N.D. Cal.2025-01-24Lanham Act 15:1125Open on the docket, allegations only [docket]
LinkedIn Corporation v. ProAPIs Inc.5:25-cv-08393N.D. Cal.2025-10-02Lanham Act 15:1125, three defendants servedLive, allegations only [docket]

The TopSocial24 complaint is the one worth reading, because it is the only one in the set that quantifies what LinkedIn thinks it is fighting. LinkedIn alleged the defendants "have created and used over 400,000 fake LinkedIn accounts" since 2021, that an investigation of one customer surfaced "over 24,000 fake accounts" linked to one defendant plus "16,000 additional fake accounts," and that a network of "154,000 fake accounts" was restricted as a result [docket, complaint filed 2023-01-10].

Those are allegations in a pleading rather than findings, and the case terminated on 23 October 2023 without a published merits ruling. What they establish is scale of intent, not proof: LinkedIn believed one operator was running a six-figure fake account estate, and pleaded it under contract and fraud rather than under the CFAA.

One sequence in that table is worth tracing. LinkedIn sued Nubela Pte. Ltd. on 24 January 2025. Nubela is the company behind Proxycurl, a LinkedIn data API. On 4 July 2025 the shutdown was posted to Hacker News as item 44466738, "LinkedIn Scraping Startup ProxyCurl Shuts Down" [thread, 5 points, no comments]. Filing to closure in a little over five months. The docket does not state a causal link and neither does this page, but the sequence is what a supplier-risk assessment is supposed to catch.

What LinkedIn's own enforcement numbers say

LinkedIn publishes a Community Report twice a year with the detection split, and it is the only first-party enforcement data in this market. For the period 1 July to 31 December 2025 it reports that "our automated defenses blocked 97.8% of the fake accounts we stopped," with 2.2% caught by manual investigation, and that "99.7% of the fake accounts were stopped proactively, before a member report" [vendor, read 25 August 2026]. For spam and scam content the same report gives 98.6% stopped automatically.

Read that as a statement about the shape of enforcement rather than about your account. Two things follow for a buyer. First, nearly all of it is model-driven, which means there is no human on the other side of the decision and, per the appeal experience in thread 37748263, often not one on the other side of the appeal either. Second, 99.7% proactive means detection does not wait for somebody to report you, so "nobody has complained about my outreach" carries no information.

The report's absolute counts are rendered as images for the recent periods, but the older ones survive in the page's alt text and give the order of magnitude: for January to June 2022, "16.4 million were stopped automatically at attempted registration. 5.4 million were restricted after registration and before members reported them. And 190,000 were restricted after members reported them." For July to December 2021 the same three numbers were 11.9 million, 4.4 million and 127,000 [vendor].

Against a member base the same report puts at "over 1.3 billion members in more than 200 countries," registration-time blocking is the dominant control and it fires before an account has done anything.

Metric, LinkedIn Community ReportValuePeriodWhat it constrains for a buyer
Fake accounts stopped by automated defences97.8% [vendor]Jul-Dec 2025No human reviews the initial decision
Fake accounts stopped proactively99.7% [vendor]Jul-Dec 2025Detection does not wait for a report
Spam and scam content stopped automatically98.6% [vendor]Jul-Dec 2025Message volume is scored separately from account behaviour
Blocked at attempted registration16.4 million [vendor]Jan-Jun 2022Burner accounts for testing mostly never open
Restricted after registration, pre-report5.4 million [vendor]Jan-Jun 2022The bucket an automated account lands in
Restricted after member reports190,000 [vendor]Jan-Jun 20223.4% of post-registration restrictions in that period
Restriction rate for accounts running automationNot stated publicly [not tested]n/aThe number every buyer wants and nobody publishes
Restrictions attributed to a named vendorNot stated publicly [not tested]n/aMakes tool-level ban-rate claims unverifiable

What Microsoft tells its shareholders about scraping

LinkedIn is a Microsoft segment and Microsoft is public, so the enforcement posture appears in a filing where a lawyer signed it. Microsoft's 10-K for fiscal year 2026, filed 29 July 2026 (CIK 0000789019), carries a risk factor headed "We may not be able to protect information in our products and services from use by others" [filing]. The body of it:

"LinkedIn and other Microsoft products and services contain valuable information and content protected by contractual restrictions or technical measures. In certain cases, we have made commitments to our members and users to limit access to or use of this information. Limitations on our ability to prevent third parties from scraping or gathering information or content through use of bots or other measures and using it for their own benefit due to, among other things, changes in the law, interpretations of law, or increasing use of agentic AI, could adversely affect our business, financial condition, and results of operations." Microsoft 10-K, FY2026, Item 1A.

That paragraph does work no vendor page can do. It tells you LinkedIn's blocking is not a policy mood that might relax. It is a position Microsoft has told the market it depends on, in the same document that reports LinkedIn revenue of $19,817 million for FY2026 against $17,812 million in FY2025 and $16,372 million in FY2024, growth of 11% [filing]. Anyone hoping enforcement softens is betting against a business line worth nearly $20 billion a year whose parent has flagged scraping as a named risk to it.

Two absences in the same filing are worth recording, because silence in a 10-K is a data point. A full-text search of Microsoft's EDGAR filings on 25 August 2026 returns zero hits for "fake accounts" in any 10-K and zero for "inauthentic" across all forms, against 42 hits for "scraping" across all forms [filing]. Microsoft discloses the commercial risk of losing control of the data. It does not disclose platform abuse volumes to investors, which is why the Community Report is the only place those numbers live.

How eleven LinkedIn tools actually reach your account

This is the table the category does not publish. Architecture is from each vendor's own site. Compliance wording is verbatim rather than paraphrased, because "safe", "compliant", "secure" and "approved" are four different claims and only the last would mean anything. Where a vendor states nothing, the cell says so, and the silence is a finding: two vendors document their credential handling in public, so the rest have chosen not to.

ToolArchitecture [vendor]Credential it takesDedicated IP claimCompliance wording, verbatimPublished limitsEntry price
ExpandiCloud proxyNot stated publiclyYes, country-selected"Expandi is not an official product published by LinkedIn" / "Use of Expandi is at your own risk"Warm-up 5 to 21 a day; steady-state preset not published$99/mo
HeyReachCloud proxySession cookie or email and passwordYes, static residential, non-rotating"LinkedIn's User Agreement explicitly bans software that automates connecting, messaging, liking, and commenting"40 a day max, 25 default, 200 a week$79/mo
DripifyCloud proxyNot stated publiclyYes, per its 2025 documentation"Advanced safety algorithms keep your LinkedIn automation secure and compliant"75 requests a day; 100 to 150 messages a day$59/seat/mo
La Growth MachineCloud proxyNot stated publiclyClaims dedicated and dynamic on the same page"LinkedIn does explicitly forbid the use of tools that perform automated actions without human intervention"None published [vendor]$70/seat/mo
PhantomBusterHybrid`li_at` session cookie, never the passwordNo, and states you mostly do not need oneNo compliance or approval claim made anywhere50 to 100 invites a week by account tier$69/mo
TaplioHybrid, extension requiredNot stated publiclyNo claimWorks through "native LinkedIn tools", a phrase it does not defineNone published [vendor]$39/mo
Dux-SoupBrowser extensionNone. Runs in your own sessionNot applicable"With no third party access required, we guarantee optimal safety of your LinkedIn account"Not stated publicly [vendor]Not in this directory
Meet AlfredCloud, self-described as "cloud-based sending"Not stated publiclyNot stated publicly"Smart limits, randomized human-like behavior, and cloud-based sending are built into every campaign""Smart limits", no numbers published [vendor]Not in this directory
CloselyCloud, architecture not statedNot stated publiclyNot stated publicly"Closely runs LinkedIn automation that mimics real behavior, smart limits, delays, and human-like timing"None published [vendor]$999/mo unlimited seats [vendor]
WaalaxyChrome extensionNone stated. Runs in your own browserNot applicable"Human-like timing that stays within LinkedIn's limits"Tier-gated invitation caps, numbers not published [vendor]Not in this directory
Sales NavigatorFirst-partyNone. It is LinkedInNot applicableNo automation permission granted to the seat holderNot applicable$119.99/seat/mo

Two patterns fall out of that table. The vendors that publish real numbers are the ones that publish weaker safety claims, and the vendors making the strongest safety claims publish no numbers at all. Meet Alfred sells "smart limits" without stating one. Closely sells "human-like timing" without stating a cadence.

PhantomBuster makes no safety claim and publishes an actual rate table [vendor, 21 August 2026], and its most useful line is structural: limits count per account, not per tool, so running three automations at 25 actions a week each shows LinkedIn 75 on one account rather than three tools each behaving moderately.

One vendor contradicts itself on the specific claim a buyer would use to choose. La Growth Machine's safety page promises "one IP, one user: guaranteed exclusivity" and, two sentences later, says its mobile proxies give you "a dynamic IP" [vendor, 21 August 2026]. Dedicated and dynamic are opposite claims about the same resource. Its homepage advertises 5G proxies while the safety page says 4G. Neither page is marked as superseding the other.

The 25-minute architecture audit, before you enter a card

You can settle the architecture question from published pages without a trial, a card or a risked account. Budget 25 minutes per vendor. You need a browser and the vendor's help centre, which is where the truth lives, because help centres are written by support staff answering real questions and marketing pages are not.

Step 1, five minutes: find the onboarding article

Search the vendor's help centre for "connect your LinkedIn account" or "add an account". Read the actual steps. If any step involves installing an extension whose only job is to export a value, or pasting a long string, or entering your LinkedIn password into the vendor's form, you are buying shape two. If the steps end with "pin the extension" and nothing is copied out, you are buying shape one.

Fail threshold: if the onboarding flow is not documented publicly at all, stop here. A vendor that will not show you how its own product connects before you pay has told you something.

Step 2, ten minutes: search for the three words

Search the whole vendor domain for "cookie", "proxy" and "IP address". Record how many pages return each and what they say. PhantomBuster names its credential and says you mostly do not need a proxy. HeyReach names its proxy type. Expandi, Dripify and La Growth Machine return nothing on the credential question.

Fail threshold: zero hits on all three words, combined with a product that runs while your laptop is off, means the tool holds a credential it has chosen not to describe. That is a documentation finding, not an accusation, and you can raise it with their sales team by quoting their own silence back.

Step 3, five minutes: read the compliance sentence literally

Copy the exact safety claim into a note. Then sort it into one of four buckets: approved (a signed relationship with LinkedIn, which none of these has), compliant (a claim about rules, which is checkable against section 8.2 and fails), safe (a claim about outcomes, unfalsifiable), or undetectable (a claim about somebody else's detection system, which the vendor cannot possibly know).

Fail threshold: any claim in the fourth bucket. A vendor promising it cannot be detected is describing the exact behaviour that gets accounts restricted and making a promise about a system it does not operate.

Step 4, five minutes: check the docket

Run the vendor's legal entity name through CourtListener's RECAP search. It is free and unauthenticated at five queries a minute. You are looking for LinkedIn Corporation as a plaintiff. Fail threshold: an open action. Note that the trading name and the legal entity often differ, which is why Proxycurl appears on the docket as Nubela Pte. Ltd. Search both.

What this audit cannot detect, and the limit is severe. It tells you what the vendor has written down. It cannot tell you what the software does. A tool documenting an extension-only architecture may still relay actions through a server, and nothing on a public page would show that. Confirming the actual behaviour needs network inspection on a live account, which is [not tested] here and which nobody in this market publishes.

So which one should you actually buy?

Decide what you are willing to lose first, then let that pick the architecture. There is no option in this category that LinkedIn permits, so the question is not which one is allowed. It is which failure you can absorb.

  • If the account is personally valuable, do not automate it. Free LinkedIn search plus manual sending runs a real motion at low volume and touches nothing section 8.2 names. We costed that stack at $17 a month, and its ceiling of roughly fifty messages a week is the price of not gambling fifteen years of graph.
  • If you automate on your own account, prefer the extension. It is still named in 8.2, so this is a smaller exposure rather than a compliant one. What it buys you is that no credential leaves your machine, the traffic arrives from the IP address that always sends your LinkedIn traffic, and nothing runs while you are asleep.
  • If you need volume across many accounts, you are buying cloud, so buy the one that documents the credential. On that test HeyReach and PhantomBuster are the only two that say in public what they take and what IP they use it from. Documentation is not safety. It is the only thing you can audit.
  • Never run automation on the account you also use by hand. Dripify warns about this on its own product, noting two simultaneous sign-ins can be flagged as suspicious [vendor]. Thread 32711372 (4 September 2022, 18 points) is the unautomated version of the same failure: a privacy-conscious user restricted three separate times purely for VPN and extension use, writing "I have read up on various triggers, and they keep shifting" [thread].
  • Buy the annual plan last. Every vendor here discounts an annual commitment, and an annual commitment on a product whose central risk is a permanent, unappealable restriction is the wrong shape of contract for the wrong shape of risk.

What breaks in month three

The first month works. That is the structural problem with this category and it is why the reviews skew positive: connection acceptance is highest when a dormant account suddenly becomes active, and detection is a function of sustained pattern rather than a single day. The failures cluster later and they arrive in four recognisable forms.

The soft restriction. Search results start returning fewer rows, connection requests stop converting, and nothing announces itself. This is the outcome nobody can measure from outside, because LinkedIn does not tell you it has happened and the tool reports the requests as sent. [not tested] here, and as far as this page can establish, not published by anyone.

The identity check. The account is restricted pending government ID. Thread 32711372's author names this as the reason he stopped: "Submitting an ID to LinkedIn is a no-go." For a cloud tool the trigger is mechanical. Your session appearing from a new address is exactly the geographic jump that thread describes triggering a restriction with no automation involved at all.

The vendor takedown. Your tool's company page and executives disappear, as HeyReach's did on 25 March 2026. Your account is untouched and your workflow is intact, but the vendor you depend on is now visibly in conflict with the platform it resells access to. Note that our own ledger flags a widely repeated claim that HeyReach pivoted away from LinkedIn within weeks as uncorroborated, and HeyReach has published continued LinkedIn operation since.

The permanent one. Thread 37748263 is what this looks like: "We've deemed the activity in your account is in violation of the LinkedIn User Agreement and Professional Community Policies. Your appeal has been denied, and your account has been restricted permanently." One commenter in that thread names the second-order cost better than any vendor page does: "If you are not on LinkedIn, you are simply not on the radar" [thread]. Both are individual accounts and not findings of fact. Both are also the reason to keep an export of your connections somewhere you control.

What the practitioner threads show that the vendors do not

The most useful thread in this market is Hacker News item 34583932, "Ask HN: LinkedIn sent me a cease and desist for my Chrome extension. Help?" (30 January 2023, 225 points, 146 comments). The poster built a general-purpose browser automation extension and listed LinkedIn among its examples. LinkedIn's letter, he reports, demanded he "cease and desist developing, offering, or using software or programs with features developed, marketed, or intended for automating activity on LinkedIn's website or app" [thread].

Two things make that thread worth citing rather than paraphrasing. First, it is an existence proof that the browser extension route draws enforcement, which settles the argument the cloud vendors and the extension vendors have been having with each other. Second, it contains the misreading and its correction in the same conversation, which is rarer than it should be.

The misreading, comment 34584741: "My understanding of the LinkedIn v HiQ case is that it's legal to scrape public pages no matter what is in the website terms." The correction, comment 34585253, from a commenter who identifies as "an attorney whose primary focus is in this area of law": "this interpretation of the LinkedIn v. hiQ case is categorically wrong."

He then supplies the summary himself, in comment 34585924: "Summary judgment was granted on behalf of LinkedIn against hiQ Labs for breach of contract... The parties settled their dispute with hiQ Labs agreeing to court-imposed injunction to never again scrape LinkedIn and by paying LinkedIn $500k. Despite the headlines, the final resolution of these disputes was a win for LinkedIn, not hiQ" [thread].

That is a self-identified attorney on a public forum rather than an authority, so it is not a finding of fact. It is checkable, which is better: the $500,000 and the injunction are in docket entry 406, and this page pulled that PDF rather than take his word for it. The reason to quote him at all is that a security team asked to approve a LinkedIn tool will find the misreading first, because it ranks. Have the docket number ready.

The misreading in the wild, dated: item 33566528, posted 11 November 2022, one week after the summary judgment order. Its title is "The hiQ vs. LinkedIn case update. Scraping public data is still legal" and its single comment reads "So, Linkedin's blog and a bunch of people on twitter are saying that LinkedIn won this case, but I doesn't seem to be true? Nothing changed really" [thread, 3 points, 1 comment]. LinkedIn had won the contract claim eight days earlier.

If you came here looking for a way around detection

Wrong page, deliberately. Nothing here tells you how to rotate a fingerprint, pace actions under a threshold, warm an account to look human, or defeat any check LinkedIn runs. Not because that is secret, but because publishing it would be writing an evasion guide, and the job here is to let a buyer see what they are exposed to rather than help anyone hide from a platform they signed a contract with.

The evasion framing is also bad commercial advice. Every threshold in circulation, including the roughly 100 connection requests a week this market has treated as the ceiling since 2021, was inferred by practitioners and published by nobody at LinkedIn [unverified-circulating]. Thread 32711372's author gave the general form in one line: the triggers "keep shifting". A motion built on an undocumented threshold set by an adversary who moves it has a hidden expiry date.

Why nobody can tell you a tool's real ban rate

One live example of why nothing on this page about any tool comes from a rival's site. Closely's own pricing FAQ, read 25 August 2026, states its unlimited-seat plan at $999 a month and in the same sentence names a competitor's figure at $1,999 [vendor].

This page carries the $999, because Closely is quoting its own rate to its own buyers in a currency for a stated period. It does not carry the other number, at all, because a competitor's comparison table is the one place a gated price tends to appear and that is exactly why it cannot be used.

The same rule bites harder on safety claims. Dux-Soup publishes a page headed "Is Dux-Soup's ban rate really 23%? No. Here's the evidence," responding to a restriction statistic circulating about its own product [vendor, read 25 August 2026].

This page reports neither the 23% nor the rebuttal as a fact about anything. The claim originates with a party selling an alternative, the rebuttal originates with the party selling the product, and no independent measurement of any vendor's restriction rate exists that we could locate. What the exchange does establish is that ban-rate figures circulate in this category as marketing artefacts, and a buyer who repeats one in a procurement document is repeating an advertisement.

Expandi's comparison table asserts Dripify has no dedicated IP. Dripify's own documentation says it does. Two vendors, one factual question, and the only version worth carrying is the one the vendor says about itself, dated. That is the whole method here and it is why several cells in the big table read "Not stated publicly" instead of a guess.

Is LinkedIn automation safe? The answer in as many words

No, and the useful version of the answer is that it is unsafe in three specific ways rather than one general way. A browser extension is named in section 8.2 by the phrase "browser plugins and add-ons", leaves no credential with anyone, and cannot act without you.

A cloud proxy is named by the phrase "copying cookies", holds a live credential to an account you personally own, and acts while you are asleep. A hybrid is named by both. The official API route is the only permitted one and it is closed to new entrants.

The legal position is not the reassuring one this market repeats. hiQ Labs won two preliminary-injunction appeals on a serious-questions standard about scraping public pages while logged out, then lost the contract question on 27 October 2022 and paid $500,000 with a permanent injunction on 8 December 2022. Every tool on this page operates logged in, which is the situation the Ninth Circuit expressly did not reach.

Meanwhile LinkedIn Corporation has filed six actions of this type since 2014, two of them open, and Microsoft's FY2026 10-K names its ability to stop scraping as a risk to a $19.8 billion revenue line.

So do this on Monday. Run the four-step audit above on whatever is top of your shortlist, budget 25 minutes, and write down the verbatim compliance sentence and which of the four buckets it falls into. If it lands in the fourth bucket, cross the vendor off. If the vendor holds a credential it has not documented, ask them in writing which one and keep the reply. And if the answer to "could I rebuild this network from scratch" is no, buy the $119.99 Sales Navigator seat and send the messages yourself.

Questions

Is a browser extension safer than a cloud LinkedIn tool?
It is a smaller exposure, not a compliant one. Section 8.2 of the User Agreement names "browser plugins and add-ons" explicitly, so the extension route is banned too. What it buys you is that no credential leaves your machine, the traffic arrives from your own IP address, and nothing runs while your browser is closed. Hacker News item 34583932 is an extension developer receiving a LinkedIn cease and desist, so the route draws enforcement as well.
Did hiQ win against LinkedIn, so scraping is legal?
No. hiQ won two preliminary-injunction appeals on a "serious questions going to the merits" standard, both about scraping public profiles while logged out. It then lost the contract question at summary judgment on 27 October 2022 and, on 8 December 2022, accepted a $500,000 judgment and a permanent injunction barring it from LinkedIn for good. Docket 3:17-cv-03301, N.D. Cal. Every automation tool operates logged in, which is the situation the Ninth Circuit expressly did not reach.
Can any LinkedIn automation tool be officially approved?
Not a new one. LinkedIn's developer documentation states "We are not currently accepting new partners for access to the LinkedIn Sales Navigator API", read 25 August 2026. A tool claiming partnership would need an agreement predating the freeze. None of the eleven tools on this page claims approval, and one states outright that it is not an official LinkedIn product.
If my tool's company page gets banned, is my account at risk?
They are separate enforcement surfaces. HeyReach's company page and executive profiles were removed on 25 March 2026 while its customers' accounts continued operating, and HeyReach states the two are unrelated. Treat that as the vendor's position rather than an established fact: nobody outside LinkedIn can see whether tool attribution feeds individual restriction decisions, and LinkedIn publishes no data that would settle it.
What does a LinkedIn tool actually take from me to work in the cloud?
Your session. PhantomBuster names it exactly, the `li_at` cookie, and states it never takes your password. HeyReach accepts either an exported cookie or your LinkedIn email and password. Expandi, Dripify and La Growth Machine publish nothing on the question. Given two vendors document it plainly, the silence from the others is a choice rather than an oversight.
Are the daily limits vendors publish LinkedIn's real limits?
No. LinkedIn publishes no official automation ceilings, which PhantomBuster says on its own site. Every number in circulation, including the roughly 100 connection requests a week this market has used as a ceiling since 2021, is inferred by practitioners and unverified. The one structural point worth keeping is PhantomBuster's: limits count per account, not per tool, so three tools at 25 actions a week each shows LinkedIn 75 on one account.
How do I check a vendor's architecture without paying?
Read the onboarding article in its help centre, then search its domain for "cookie", "proxy" and "IP address", then sort its compliance sentence into approved, compliant, safe or undetectable, then run its legal entity name through CourtListener's RECAP search for LinkedIn Corporation as plaintiff. About 25 minutes. It tells you what the vendor has written down, which is not the same as what the software does.
What happened to Aware, the LinkedIn signals tool?
It shut down. useaware.co now redirects to a Taplio page headed "Best Aware Alternative After Shutdown". Be careful searching: awarehq.com is a different company entirely, a Slack and Teams governance product now part of Mimecast, with no LinkedIn functionality. We found no first-party evidence for the Clay association our own directory slug implies, either.

Tools mentioned

All tools →

Sources

Source interests are labelled. Almost everything published about this subject is written by someone selling into it.

More from the blog

All posts →