Engineering

LinkedIn API restrictions in 2026: what you can't build, and what you can't keep

LinkedIn has an API, it is free, and the review is only the first gate. The restrictions that bind you after approval - no social feeds, no member data for sales, and a 24 or 48 hour clock on most of what you receive - are what actually shape the integration. The access map and the full retention table.

LinkedIn has an API. It is free, and it is gated by a review — both of those are well covered, including by us. What almost nobody writes down is the third thing: the list of things you are not allowed to build with it, and the data you are not allowed to keep. Those two lists are where approved integrations quietly go wrong, because they bind you after LinkedIn has already said yes.

This page is the access map and the restriction list. For what it costs and what the rate limits are, see LinkedIn API pricing in 2026.

Last verified: October 2026, against LinkedIn's developer documentation on Microsoft Learn. Every claim below links to its source page.

Which LinkedIn APIs exist, and which you can simply switch on

LinkedIn's Getting Access page is blunt about the default:

Most permissions and partner programs require explicit approval from LinkedIn. Open Permissions are the only permissions that are available to all developers without special approval.

There are exactly three open permissions. Everything else in the catalog sits behind a form, a partner programme, or a door that is shut.

Programme

How you get it

What it grants

Sign In with LinkedIn using OpenID Connect

Self-serve in the Developer Portal

profile, email

Share on LinkedIn

Self-serve in the Developer Portal

w_member_social — post, comment and like as the authenticated member

Community Management API

Access request form, reviewed; two tiers

Organic posting, comments and analytics for profiles and Company Pages: w_organization_social, r_organization_social, rw_organization_admin and others

Advertising API

Access request form, reviewed; two tiers

Campaign management; prerequisite for Matched Audiences, Audience Insights and Media Planning

Events Management, Lead Sync, Conversions, Matched Audiences

Apply through the standard process

Open to all approved developers

Audience Insights, Media Planning

Qualification criteria evaluated by LinkedIn

Restricted; judged case by case with no fixed timeline

Company Intelligence API

Closed to new applicants

LinkedIn: "not currently accepting new applications"

Compliance

Cannot be requested

r_compliance, w_compliance — listed for reference only

Sales Navigator (SNAP)

Become a SNAP partner

Sales Navigator analytics, display and CRM validation

Talent: Recruiter System Connect, Apply Connect, Apply with LinkedIn, Premium Job Posting

Talent Solutions partner application

ATS and recruiting integrations

Two rows deserve emphasis because developers lose weeks to them. The Compliance permissions are documented but unobtainable — LinkedIn says access "is closed and may not be requested." And the Company Intelligence API is a private programme available only to developers approved before it shut. A documented endpoint is not an available endpoint.

If you only need to post to the profile of whoever signs in, you are done at row two: w_member_social is self-serve and needs no review. Posting to a Company Page is what pulls you into the Community Management review, because that needs w_organization_social, which the permissions table only grants on approval.

What you are not allowed to build

LinkedIn's restricted use cases page is the single most important document in this stack, and the one least likely to be read before an application is submitted. It opens by telling you the stakes: "Failure to comply with the terms will result in loss of API access."

The restrictions that most often collide with a product idea:

  • No social feeds. None of the data from the Community Management APIs can be used in a social feed use case — LinkedIn's own example is displaying a feed of company updates on the company's website or intranet. This kills the most common "embed our LinkedIn posts" feature request outright.
  • No sales, recruiting or advertising use of member data. Member data cannot be used to identify prospects or prospective hires, create leads, enhance CRM records, build audience lists, target ads, run account-based marketing, or send mass messages.
  • No export. Member data "can only be displayed via your application" and cannot be exported, distributed or transferred out of it — explicitly including to your own customers. A CSV export button on a comments view is a violation.
  • No enrichment. Member data cannot be combined with your data, other LinkedIn data, or third-party data to create, supplement, verify or append to profiles, leads or reference tables.
  • Limited audience. Data obtained to manage a specific Page or profile may only be shown to people associated with that Page or profile. In a multi-tenant product, that is an authorisation rule you have to build.
  • No headless or shared accounts. Do not create fake profiles to manage accounts, and do not use one individual profile to manage multiple customers' accounts.

Read together, these define the API narrowly: it exists to let a member or a Page manage their own presence through your tool. Anything that treats LinkedIn as a data source rather than a publishing surface is outside the grant, however technically easy it is.

What you are not allowed to keep

This is the part that shapes your database schema, and it is the part that surprises people. LinkedIn's Data Storage Requirements put a clock on most of what you receive. The durations are not advisory.

Data

Allowed storage or caching

Authenticated member's person ID, URN and basic profile

No restriction

Other members' person ID and URN

No restriction

Other members' profile data — e.g. someone who commented on a Page post you manage

24 hours, caching only; storing it is not permitted

Members' social activity data — posts, shares, likes, comments, mentions and their metadata

48 hours

Organisations' social activity data

Six weeks; six months if that organisation authenticated into your app

Organisation profile data

Eight weeks if the organisation authenticated into your app; otherwise not allowed, except name and logo URL for 30 days

Page admin and reporting data (followers, visitor and social-action summaries)

One year

IDs and URNs for organisations, posts, social actions and ad objects

No restriction

LinkedIn standardised lists (industries, functions, skills, locations)

One year, excluding Bing Maps location data, which may not be stored

Three consequences worth designing around. First, a comment inbox cannot be a persistent inbox: the member's comment text goes at 48 hours and the commenter's profile fields at 24, so you re-fetch rather than archive. Second, the identifiers are exempt — you may keep person URNs indefinitely, which is what makes re-fetching workable. Third, when two rules touch the same field, LinkedIn resolves it against you:

If there's any conflict between these requirements and the requirements in the terms, the requirements that are more restrictive or more protective of the data apply. Similarly, if a given data field is encompassed by two or more of the following requirements, the shortest storage/caching duration shall apply.

Note also what the retention rules do not cover: data your own clients give you directly, rather than data retrieved through the API, is outside these requirements. The same field can be free or clocked depending on where it came from, so provenance has to be a column, not a comment.

Where access breaks after you apply

A rejection burns the app, not just the application

This is the costliest sentence in the Community Management App Review documentation:

If your application is rejected, review the qualifications, create a new app, and submit a new Development tier access request form. You won't be able to re-apply for Development tier access with your existing app.

So a rejection means a new client ID, which means re-verifying the app against your LinkedIn Page and re-issuing credentials to anything already pointing at the old one. The avoidable rejection reasons are mundane and listed up front: a personal email address rather than a business one ("Personal email addresses won't pass the vetting process"), an unverified app, or a product name containing any part of the LinkedIn or Microsoft marks — LinkedIn calls out "Linked" and "In" specifically.

Standard tier wants a narrated video of your product

Development tier is not production. The access tier table caps it at 500 API calls per app and 100 per member in any 24 hours, blocks every endpoint with BATCH_GET entirely, disables push notifications for social-action webhooks, and gives you twelve months to finish building. Standard tier lifts the caps, and getting it requires a downloadable, high-resolution, preferably narrated screen recording demonstrating specific test cases for each use case you declared — Page Management, Brand Engagement, Page Analytics, Executive Management or Employee Advocacy. For Page Management, for example, you must show the full OAuth flow, a user posting to their Page, a member's comment appearing in your app, and exactly which profile fields of that commenter you display.

LinkedIn publishes no review timeline for either tier, and reserves the right not to upgrade you even if you meet the requirements. Do not put a date on it in your launch plan.

Page permissions are not an API operation

You can read which Pages a member administers through /organizationAcls, and a member's token only works for Pages where they hold a qualifying role such as ADMINISTRATOR. What you cannot do is fix it when they don't:

Access to a Company Page cannot be granted or updated through the API. Please use the UI tool to grant, update, or remove access.

Every onboarding flow therefore needs a dead end that sends the user to LinkedIn's own interface to get themselves added as an admin, then come back. Build that screen; you will need it.

Versions sunset on a published date

LinkedIn ships monthly API versions and retires them on announced dates. As of October 2026 the live deprecation notice across the Marketing documentation is that version 202510 will be sunset on October 15, 2026, with the migration status table tracking the rest. A Linkedin-Version header you hardcoded last year is a scheduled outage.

If LinkedIn is one network of several

Everything above is the cost of owning the LinkedIn integration directly, and that is often the right call: it is free, and nothing sits between you and the platform. It gets harder to justify when LinkedIn is one of five or six networks you publish to, because each of the others has its own version of this page. Our rundown of which platforms let you publish through their API covers how the approval step differs across them.

Outstand is a social media api that covers that surface through one interface. For LinkedIn specifically, the LinkedIn API page documents what we support — text, images, video and article cards to profiles and Company Pages, comments, post analytics and inline mentions — and the LinkedIn configuration docs cover connecting an account. If your users are AI agents rather than people, the LinkedIn MCP server exposes the same operations as tools.

One thing to be clear about, because it is the honest version of the pitch: a managed layer changes who holds the reviewed app and who maintains the version cadence and the token refresh. It does not exempt you from the restriction list. If you store member comment text that reached you through our API, the 48-hour rule is still about your database. If you need the OAuth screen and the app to be yours, Outstand supports bringing your own LinkedIn app, in which case the review above is yours to pass.


FAQ

Does LinkedIn have an API?

Yes — several, under the Marketing API Program umbrella plus separate Sales, Talent and Learning partner programmes. Three permissions are self-serve (profile, email and w_member_social); everything else requires approval, and a few programmes, including Compliance and Company Intelligence, are closed to new applicants entirely.

What are the LinkedIn API restrictions?

Two kinds. Use-case restrictions ban social feeds, any sales, recruiting or advertising use of member data, exporting member data out of your app, combining it with other data, and managing multiple customers through one personal profile. Storage restrictions cap most member data at 24 or 48 hours. Breaking either costs you access, not just the feature.

How long can I store LinkedIn data?

It depends on the field. Person IDs and URNs have no limit; other members' profile data may be cached 24 hours and not stored; member social activity 48 hours; organisation activity six weeks, or six months if that organisation authenticated into your app; Page admin and reporting data one year. Where rules overlap, the shortest duration applies.

Can I display LinkedIn posts on my website?

No, if the data comes from the Community Management APIs and the posts are a feed. LinkedIn names "a feed of LinkedIn company updates on the company's website or intranet" as a prohibited use case.

What happens if my Community Management API application is rejected?

You cannot re-apply with the same app. LinkedIn requires you to create a new developer application and submit a fresh Development tier request, which means a new client ID and re-verification against your LinkedIn Page.

Is the LinkedIn API free, and what are the rate limits?

It is free — LinkedIn publishes no per-call fee or licence fee for any product in the catalog — and the limits are daily ceilings per app and per member that reset at midnight UTC. Both are covered in detail in LinkedIn API pricing in 2026.