Creating the LinkedIn app
LinkedIn only issues tokens to an app, and an app's Client Secret cannot ship inside an npm package. So you create your own app, once. It is free and needs no review.
-
A LinkedIn Page. LinkedIn attaches every app to a Company Page. Any page you administer works. If you have none, create one: it can stay empty, and nothing is posted to it.
-
The app. At linkedin.com/developers/apps/new, give it a name (say, "My MCP"), pick the page, upload any logo and accept the terms.
-
Its products. In the app's Products tab, request:
- Share on LinkedIn, which grants
w_member_socialto create, edit and delete your posts; - Sign In with LinkedIn using OpenID Connect, which grants
openid profileto know who signed in.
Both are granted at once.
- Share on LinkedIn, which grants
-
The redirect URL. In the Auth tab, under OAuth 2.0 settings, add this Authorized redirect URL:
http://localhost:3769/callbackIt is where LinkedIn sends you back after you sign in, to the page
linkedin mcp configserves. Another port works too (linkedin mcp config --redirect-port <port>), as long as both say the same. -
The credentials. In the same Auth tab, copy the Client ID and the Primary Client Secret.
Then run linkedin mcp config --web: paste both, press Save and sign in with LinkedIn, and allow the app on
LinkedIn's page. The Client Secret and the token are saved on your computer only, readable by you alone (see
Configuration).
Renewing the sign-in
A LinkedIn member token lasts 60 days, and LinkedIn gives ordinary apps no refresh token. When it runs out,
the tools answer "not signed in" and your agent tells you to run linkedin mcp config --web again. That takes a
click, since the app is already saved. linkedin mcp status shows how many days are left.
If LinkedIn does give your app a refresh token (an option it enables for some partners), the server refreshes the token by itself.
Limits
- 150 posts a day per member, and 100,000 calls a day per app.
- The token can post only as you, never as a page or another member.
- To revoke the app's access, remove it at linkedin.com/psettings/permitted-services.