Connect LinkedIn
One LinkedIn connection covers your company Pages and, when your administrator has switched it on, LinkedIn ad accounts.
Connecting has two parts. An administrator sets up one LinkedIn developer app for the installation, on the LinkedIn app page. Then each person connects their own LinkedIn login, on the LinkedIn connection page.
For the administrator: set up the app
LinkedIn opens its Page and advertising APIs only to registered companies, after it reviews the app. So this setup has a wait in the middle: you ask for a product, and LinkedIn answers in its own time. Nobody can connect until it has approved one.
The LinkedIn app page lists these steps too, under What to collect, with the exact values for your installation.
Create the LinkedIn app
You need a LinkedIn Page for your company first. The app is tied to one Page, and a super admin of that Page has to approve it. If there is none yet, create a Page.
In the LinkedIn developer portal, create an app:
- App name: anything that does not use the names LinkedIn or Microsoft, or parts of them such as "Linked" or "In". LinkedIn rejects an app that uses them.
- LinkedIn Page: your company's Page.
- Privacy policy URL: the LinkedIn app page gives you the address to copy.
- App logo: you can download one from the LinkedIn app page.
Verify the app with the Page
On the app's Settings tab, press Verify next to the Page. LinkedIn gives you a link. Send it to a super admin of the Page, who opens it and approves. LinkedIn explains this in its help on verifying an app.
Ask for the Advertising API
On the Products tab, request Advertising API and fill in its form. It asks for a business email address, your company's legal name, address and website, and the privacy policy.
This one product is enough to start. Besides advertising, it covers posting to your Page and reading its posts.
LinkedIn reviews the request and decides. Approval puts the app in LinkedIn's Development tier, which reads every ad account you manage and changes up to five. In that tier you also name the ad accounts the app may change: on the Products tab, under the Advertising API, use View Ad Accounts, Add Ad Account, with each account's id from Campaign Manager. LinkedIn's page on what each tier allows has the rest.
Register the redirect address
- On LinkedIn app, copy the Redirect URL.
- In the developer portal, on the app's Auth tab, under OAuth 2.0 settings, Authorized redirect URLs for your app, add that exact address.
The redirect address is the address of your installation followed by /oauth/linkedin/callback.
The redirect address must be localhost or HTTPS
LinkedIn wants an HTTPS address, or plain HTTP only to this machine. An installation that listens on this machine only is given to LinkedIn under the name localhost by itself: the page shows http://localhost:8765/oauth/linkedin/callback. For any other address, set an HTTPS public address first: see Server settings.
Enter the client id and secret
Both are on the app's Auth tab in the developer portal. The secret is hidden until you press the eye icon.
- Open LinkedIn app.
- Under Credentials, fill in Client ID and Client secret (LinkedIn calls it the Primary Client Secret).
- Press Save credentials.
The heading then shows Set. A field you leave blank keeps what is already stored. If you change the client id later, everyone has to connect LinkedIn again.
The API version
API version, in the same section, is a year and a month, such as 202609. LinkedIn publishes a new version every month and retires each one after about a year. Calls that name a retired version fail, and the refusal then tells you to raise the API version.
So raise it at least once a year. LinkedIn lists the current version. Type it and press Save credentials. It takes effect at once.
Switch on the Advertising API
Once LinkedIn has approved the Advertising API, the app's Auth tab lists its OAuth 2.0 scopes. Check that the list includes every permission the LinkedIn app page shows. With every switch off, the sign-in asks for:
r_basicprofile
rw_organization_admin
r_organization_social
w_organization_socialThen, to use LinkedIn ad accounts:
- On LinkedIn app, under Advertising API, tick Ask for the Advertising API permissions when people connect.
- Press Save.
The sign-in then also asks for r_ads, r_ads_reporting and rw_ads. People already connected have to reconnect to grant them. It is off by default.
What LinkedIn Ads may spend is set on Safety limits, by currency. Nothing can be changed on an ad account until a limit is set there for its currency. See Limits and switches.
Further products and their switches
Three more things are separate LinkedIn products. You apply for each one on its own in the developer portal, and each adds its own permission to the sign-in. Their switches are on LinkedIn app, under LinkedIn Ads. All are off by default, and each is asked for only while the Advertising API switch is on as well.
| Switch | LinkedIn product | What the sign-in also asks for |
|---|---|---|
Leads: ask for r_marketing_leadgen_automation | Lead Sync API | r_marketing_leadgen_automation |
Conversions: ask for rw_conversions | Conversions API | rw_conversions |
Matched audiences: ask for rw_dmp_segments | Matched Audiences API | rw_dmp_segments |
Do not turn a switch on before LinkedIn has approved its product
LinkedIn refuses the whole sign-in when it is asked for a permission the app does not have. It does not skip the one permission: nobody can connect at all, and people who reconnect are locked out. This holds for the Advertising API switch, these three and the Comments switch. If it happens, turn the switch off again and save.
After you turn one on, people already connected reconnect to grant the new permission.
All three handle people's details: a lead is a person's name and contact details, and the other two send customer records to LinkedIn. Read Contact data first.
Comments
Reading comments and replying as a Page uses the posting permissions that everyone already grants, if LinkedIn accepts them for comments. LinkedIn's own pages name two other permissions for comments, r_organization_social_feed and w_organization_social_feed, which come with its separate Community Management API product.
If replies are refused for a missing permission, and your app has that product, tick Ask for the Community Management comment permissions when people connect under Comments and press Save. It is off by default, and the warning above applies to it.
The LinkedIn app page notes that the Community Management API can be requested only on a new app that has no other product. LinkedIn decides how that is done; its developer support is linked from the same page.
For everyone: connect your account
You connect your own LinkedIn login. The AI client can then act for the company Pages that login administers, and everything it does is recorded under your username.
Before you connect
- You need an admin role on each company Page. A Page super admin gives you one under the Page's Settings, Manage admins. A super admin or a content admin can post. A role you asked for yourself counts only once it is approved. See LinkedIn's help on Page admin roles.
- Ad accounts come from Campaign Manager. When LinkedIn Ads is on, you reach the ad accounts you have a role on in Campaign Manager. A Viewer can read reports but cannot change campaigns.
- Sign in with the LinkedIn account that holds those roles. LinkedIn has no company account: roles belong to people.
Connect
- Open LinkedIn connection.
- Press Connect LinkedIn.
- Sign in at LinkedIn and allow the request. LinkedIn asks for every permission at once. You cannot untick one: you allow all of it, or nothing is connected.
- LinkedIn sends you back to a page that says "LinkedIn connected". Go back to the management page.
The status now shows Connected, and the page says who you are connected as.
If the sign-in fails with "invalid scope"
LinkedIn has not approved the app for one of the permissions the server asks for. You cannot fix this yourself: tell your administrator.
Test the connection
Press Test connection. The page answers "Working" and lists:
- each company Page, with its id, your roles on it, and whether you may post;
- when LinkedIn Ads is on, each ad account, with its currency, its status, your role, and whether you may change it.
If it says your login "holds no approved admin role on a company Page", ask a super admin of the Page for a role, then test again.
If your connection lacks a permission that the installation asks for, the page lists each missing one and offers Reconnect LinkedIn.
You can also ask your AI client:
Which LinkedIn Pages can you post to?
How long the connection lasts
LinkedIn connections renew themselves, up to a limit:
- The server renews the connection by itself while you use it. You do nothing.
- LinkedIn ends the sign-in one year after you signed in, however often it is used. LinkedIn connection shows the date.
- In the last 30 days, the status shows Sign in again soon and the server sends you a notification, once. Press Reconnect LinkedIn to start a new year.
If LinkedIn gave your administrator's app nothing to renew with, the page says so instead: the connection then lasts until the date shown, and the warning comes 7 days before it.
After a connection ends, LinkedIn tools are refused and posts waiting in your queue for LinkedIn fail until you reconnect.
Disconnect
Disconnect removes your LinkedIn connection from this server. It also deletes what was kept from that connection: what the server watched for you on LinkedIn and the figures it kept, the stored reports that hold LinkedIn figures, your alert rules on LinkedIn accounts, and your lead feeds and export marks for LinkedIn. Nothing changes on LinkedIn.
For refusals after you are connected, see Troubleshooting.