LinkedIn does have a messaging API, but it is restricted to approved partners and its own rules forbid automated or scheduled sends. Without partner status there is no open LinkedIn messaging API at all, because the only permissions any developer can switch on cover signing in and posting.

Reach is a LinkedIn tool that runs in your own browser, inside the LinkedIn session you are already logged into, and it does not send a message it drafted until a person has approved those exact words. It does not use LinkedIn's messaging API, and we say more about what that means below.

The question got a fresh look on 23 September 2026, when DesignRush published a piece on what LinkedIn AI agents actually run on. It was prompted by a browser agent that, according to DesignRush, TechCrunch reported in August could navigate LinkedIn without an official API. The article's point is simple. The official route is narrow, so most agents that message people on LinkedIn are using something else.

Does LinkedIn have a messaging API?

Three open permissions. None sends a message.

Yes, but almost nobody can use it. LinkedIn's own documentation for the Messages API opens with a note: "Usage of this API is restricted to approved partners, subject to limitations via API agreement."

What it does is also narrow. According to the same page, it lets members "create messages to one or more first-degree connections or reply to existing conversations." So even for an approved partner, it is a tool for messaging people you are already connected to. It is not a way to reach strangers.

What does the LinkedIn messaging API allow, and what does it forbid?

84 drafts stopped before sending

It allows a message that a member chose to send, at the moment they chose to send it. The requirements section is short and worth reading in full. The key lines, quoted from LinkedIn's page:

  • "A message must be associated with a specific member action. Member actions do not include an automated or scheduled event."
  • "Members must opt in to sending a message, as opposed to opting out of sending a message."
  • If an app offers a pre-prepared message, "the member must be able to edit the content" and "must take an affirmative action to send the message after you present the member with the draft."
  • "A message must be posted at, or around the time the member took action to send the message."

The page also bans incentives for sending or receiving messages, and HTML in the message body. Read together, the rules describe one thing. Software may help write the message, but a person sees the words first and decides to send them.

Which LinkedIn APIs can any developer use?

Your network answers fast

Only three permissions, and none of them sends a message. LinkedIn's Getting Access page says "Open Permissions are the only permissions that are available to all developers without special approval." They are:

  • profile - the signed-in member's name, headline and photo.
  • email - their primary email address.
  • w_member_social - "Post, comment and like posts on behalf of an authenticated member."

Everything else sits behind a partner program. The sales permissions need approval as a Sales Navigator Application Platform partner, and what that page lists for them is analytics, display, CRM data validation and matched public profiles. The compliance permissions, which can read messaging activity, are listed "for reference purposes only. Access is closed and may not be requested."

So if you are building an AI SDR, a campaign tool or an agent and you want it to send LinkedIn messages through an official, open API, that API does not exist.

So how do AI agents send LinkedIn messages without the API?

They act through a real member's account in some other way. DesignRush looks at browser agents that read the page like a person would, and at account-based APIs run by third parties. Extensions that work inside your own logged-in browser are the other common route. The article offers four questions for judging any of them: whose account is it, where do the limits live, what happens on refusal, and what does the log show.

LinkedIn's position on all of these is on its help page for prohibited software and extensions: "We don't permit the use of any third party software, including 'crawlers', bots, browser plug-ins, or browser extensions that scrape, modify the appearance of, or automate activity on LinkedIn's website." It adds that members who use such tools "risk having their accounts restricted or shut down."

That line covers Reach too. Reach is a Chrome extension working in your own session, and it is not an approved Messages API partner. No tool that sends on your behalf has LinkedIn's blessing. What you can choose is how the tool behaves, and we went through that in detail in LinkedIn automation without getting banned.

What the LinkedIn messaging API rules get right about automation

They describe a human in the loop, and that is a good standard for any tool, official or not. The draft is editable and the person has to act to send it. Reach builds its approval step on the same idea, and on our own account these rules were running when we checked on 28 September 2026:

  • The agent drafts, a person approves. Human approval is the default for personal nurture messages. Nothing drafted for one person goes out until someone clicks Approve.
  • The approval is bound to the words. If the text changed between what the approver saw and what would be sent, the approval is refused and has to be done again. Reach's rule for this is called "Words changed since shown."
  • A resume unlocks only what was approved. If a paused send is resumed by a person, it can only release the exact row that was approved, not anything else in the queue.
  • A rejected draft never goes anywhere. It is kept with the reason, as feedback for the next draft.

That last one is where the value is. In the 90 days to 28 September 2026, people on our account rejected 84 drafts before any of them was sent. One draft apologised for a "cut-off message the other day" that had never been cut off. The reviewer's note just says "the previous message isn't truncated." Sent to someone you know, that apology would have been a small lie with your name on it.

Being straight about the difference: LinkedIn's API rule says a message goes out "at, or around the time" the member acted. Reach queues approved messages and paces them, so an approved message can go out later than the click. The approval still binds to the exact words, but the timing rule is stricter than ours. You can see how Reach handles approvals, and the wider argument for keeping a person on the send button is in AI sales agent with a human in the loop.

Why the approval step matters most in your own network

Because that is where LinkedIn messaging actually happens, and where a bad message costs the most. The official Messages API only reaches first-degree connections. The people you already know are the ones LinkedIn built messaging for.

They are also the ones who answer. On our own account, 953 of the 3,929 people we have messaged at some point replied, which is 24%, with a median of under an hour to the reply. Most of those messages were written by hand: Reach sent 184 of 18,880 outbound messages in that history. A warm network replies fast, and it remembers a wrong message just as fast. There is more on that in warm outreach vs cold outreach.

Common questions

Is there a free LinkedIn API for sending messages?

No. The Messages API is restricted to approved partners, and the only open permissions cover sign-in, email and posting. None of them sends or reads messages.

Can the LinkedIn messaging API send automated or scheduled messages?

No. LinkedIn's documentation says "Member actions do not include an automated or scheduled event," and the member must take an affirmative action to send each message.

Does Reach use the LinkedIn messaging API?

No. Reach runs as an extension in your own logged-in browser session, and its server never calls LinkedIn. It is not an approved Messages API partner.

Is using a LinkedIn automation tool against LinkedIn's rules?

LinkedIn's help centre says it does not permit browser extensions or bots that automate activity, and accounts that use them can be restricted. Tools differ a lot in how they behave, so check where the limits live and whether a person approves each message.

Can ChatGPT or Claude send LinkedIn messages for me?

Not through an open LinkedIn API, because there isn't one. They need a tool in between that works in your account. With Reach, an agent in Claude or ChatGPT can draft messages through scoped tools, and a person still approves the words. See AI agent for LinkedIn.


Sources

Trend (opened and read, 2026-09-28)

  • DesignRush, Ryan de Smidt (Senior Editor), "What LinkedIn AI Agents Actually Run On", 23 September 2026. https://news.designrush.com/linkedin-ai-agents-official-api-mcp Opened via fetch on 2026-09-28 (the site returns 403 to plain curl, but the page loads). Used for: the date and framing (a browser agent, reported by TechCrunch in August per DesignRush, can navigate LinkedIn without an official API); the two routes it examines (browser agents, account-based APIs run by third parties); its four evaluation questions (whose account is it, where do the limits live, what happens on refusal, what does the log show). The TechCrunch piece itself was NOT opened, so it is only ever attributed "according to DesignRush". The third-party API vendor the article quotes is not named in the blog (no competitor recommended).

Primary sources (opened and quoted verbatim, 2026-09-28)

  • LinkedIn, Messages API (Microsoft Learn): https://learn.microsoft.com/en-us/linkedin/shared/integrations/communications/messages
  • "Usage of this API is restricted to approved partners, subject to limitations via API agreement."
  • "create messages to one or more first-degree connections or reply to existing conversations"
  • "A message must be associated with a specific member action. Member actions do not include an automated or scheduled event."
  • "Members must opt in to sending a message, as opposed to opting out of sending a message."
  • "the member must be able to edit the content ... and the member must take an affirmative action to send the message after you present the member with the draft"
  • "A message must be posted at, or around the time the member took action to send the message."
  • Also: no incentives to sender or recipients, no HTML.
  • LinkedIn, Getting Access to LinkedIn APIs (updated 2026-06-03): https://learn.microsoft.com/en-us/linkedin/shared/authentication/getting-access
  • "Open Permissions are the only permissions that are available to all developers without special approval."
  • Open permissions: profile, email, w_member_social ("Post, comment and like posts on behalf of an authenticated member.")
  • Sales permissions require SNAP partner approval: r_sales_nav_analytics, r_sales_nav_display, r_sales_nav_validation, r_sales_nav_profiles.
  • Compliance: "listed for reference purposes only. Access is closed and may not be requested."
  • LinkedIn Help, Prohibited software and extensions: https://www.linkedin.com/help/linkedin/answer/a1341387
  • "We don't permit the use of any third party software, including 'crawlers', bots, browser plug-ins, or browser extensions that scrape, modify the appearance of, or automate activity on LinkedIn's website."
  • members using such tools "risk having their accounts restricted or shut down."

First-party (Reach MCP, run 2026-09-28)

  • get_draft_feedback (sinceDays 90): 84 feedback rows, all decision "rejected". One rejected draft opened "Apologies for the cut-off message the other day. My system seems to have glitched."; decisionReason "the previous message isn't truncated". Recipient not named anywhere.
  • get_results: overall contacted 3,929, replied 953, replyRate 0.243, medianHoursToReply 0.9. Caveat verbatim: "Reach sent 184 of 18880 outbound messages in this history — the rest were sent by hand on LinkedIn." Exclusion keyword (addcomposites) already applied.
  • get_gates: running on this account - "approval-draft-changed" (Words changed since shown - stops "Approving text different from what the approver actually saw"), "lease-human-resume-snapshot" (Resume must match approval - stops "A human resume unlocking anything but the exact approved row").

Feature (shipped)

  • docs/STATE-OF-THE-SYSTEM.md: "Outbound autonomy is policy-controlled and human approval remains the default for nurture/content work"; safety invariant 8 "Approval receipts bind to the exact approved content"; invariant 1 "Server code never calls LinkedIn".

Internal links (all returned 200 on 2026-09-28)

Other Blogs

2024-03-26
Operational Optimization
AI-Driven Insights for Modern HR Management

Artificial Intelligence (AI) is transforming industries, and Human Resource Management (HRM) is no exception. But how exactly is AI reshaping HR practices? Let’s delve into the key trends, benefits, and future directions of AI in HRM.

Read More
2024-03-26
Human-in-the-Loop Workflows
The Importance of Human Intervention in AI-Driven Workflows

LLMs are designed to predict the next word or sequence based on vast amounts of training data. This predictive capability, while powerful, is inherently prone to errors

Read More
2024-03-26
Human-in-the-Loop Workflows
Enhancing the Reliability of GPT-Assisted Market Research through Human-in-the-Loop Methodologies

The rapid advancements in artificial intelligence, particularly with Large Language Models (LLMs) like GPT (Generative Pre-trained Transformer), have revolutionized market research.

Read More
2024-03-26
Operational Optimization
Leveraging Human-in-the-Loop AI for Reliable Supply Chain Innovation

The emergence of generative AI tools like ChatGPT has sparked tremendous excitement and opened up a world of possibilities for how businesses operate. While the potential applications for AI in the supply chain are

Read More
2024-03-26
Human-in-the-Loop Workflows
Sales Enablement with Human-in-the-Loop AI

In today's fast-paced business environment, advancements in artificial intelligence (AI) have significantly transformed the sales landscape.

Read More
2024-03-26
AI Strategy and Consultation
How Human-in-the-Loop AI Enables Customer Engagement and Marketing

In the fast-paced world of digital marketing, businesses are constantly seeking innovative ways to engage with their customers and stay ahead of the competition. Generative AI, such as GPT, has emerged as a powerful tool

Read More
2024-06-06
AI-Powered Solutions
Strategic Approaches to Leveraging AI Innovations

2024 brings transformative trends that will shape the future of technology and business. From multimodal AI to ethical AI development, understanding these trends is crucial for staying competitive. Discover how open-source frameworks are democratizing AI, how customization enhances user experiences, and why edge AI is revolutionizing data processing. 🚀 To dive deeper into these insights and strategic approaches, click on "Read more" below: Key Takeaways: Multimodal AI: Integrates text, image, and audio data for improved accuracy. Open Source AI: Accelerates innovation and reduces costs. Customization: Tailors AI solutions to specific needs for better outcomes. Edge AI: Enhances performance and privacy in real-time applications. AI in Cybersecurity: Protects against sophisticated threats. Ethical AI: Ensures transparency, fairness, and compliance. Stay ahead of the curve by leveraging these AI and machine learning trends in 2024. Embrace the future of technology and drive innovation in your business! 💼💡

Read More
Quick Contact