Is LinkedIn automation against LinkedIn's terms of service?
Yes. LinkedIn's User Agreement section 8.2 prohibits bots and unauthorised automated methods, and every third-party outreach tool sits against that clause, ours included. What the clause does not say is that using one gets you banned. Enforcement is behavioural and it arrives as a ladder, not a switch.
The clause, quoted rather than paraphrased
Section 8.2 of the LinkedIn User Agreement lists what members agree not to do. Two items are the ones that matter here. Item 2: "Develop, support or use software, devices, scripts, robots or any other means or processes (such as crawlers, browser plugins and add-ons or any other technology) to scrape or copy the Services". Item 13: "Use bots or other unauthorized automated methods to access the Services, add or download contacts, send or redirect messages, create, comment on, like, share, or re-share posts, or otherwise drive inauthentic engagement".
Section 3.4 is the enforcement half: "LinkedIn reserves the right to restrict, suspend, or terminate your account if you breach this Contract or the law or are misusing the Services".
Read those plainly. Automated invitations and automated messaging are named. So is automated commenting and liking, which is worth saying out loud because we ship a commenting tool and a reaction tool. Any vendor telling you their product is terms-compliant is either reading a different agreement or hoping you will not open it.
Why "against the terms" and "you will get banned" are different sentences
The User Agreement is the ground LinkedIn stands on when it acts. It is not a description of when it acts. LinkedIn does not run a clause checker; it runs behavioural detection, and it scores patterns: session origin and IP reputation, activity clustered at identical times, volume that keeps climbing while acceptance rate falls, and browser extensions that modify the page in the member's own session.
That is why two accounts running the same weekly volume can end the quarter in completely different places, and why the useful question is not whether a clause exists. It is which of those signals your setup produces.
It also cuts the other way, and honest vendors should say so: nothing in this makes you safe. LinkedIn can act under 3.4 at its sole discretion, including for reasons that have nothing to do with you or with us.
What enforcement actually looks like when it arrives
It is laddered, and the first rungs are survivable. Almost nobody goes from healthy to permanently closed without passing signals they chose to ignore, and the single most expensive mistake is continuing after the first warning.
If you are weighing this decision, weigh it against the middle of this ladder rather than the bottom. The realistic bad month is an invitation restriction: invites stop, the rest of the account keeps working, and you lose your outbound channel for a stretch. The realistic bad year is a permanent closure, and it is rare enough that treating it as the base case will stop you doing outbound at all.
What raises your risk, roughly in order
Architecture first. A browser extension that injects scripts into linkedin.com is the one category the platform can detect directly rather than inferring, and it is named in the clause above. Tools built that way carry a structurally higher floor than tools that do not touch your browser.
Then pace against account age. A two-week-old account sending at a three-year-old account's volume is the most reliable way to get flagged, at volumes nobody would call aggressive. There is no published numeric limit to stay inside, which is exactly why age matters more than any number.
Then acceptance rate. Falling acceptance with rising volume is close to a definition of the behaviour the scoring is built to catch, and it is the signal most tools ignore entirely because the fix is to send less.
Then feed activity at machine scale. Bulk liking and bulk commenting is cheap to detect and, in our reading, the worst risk-to-return trade in the category. We ship comment and reaction tools because a human approving one comment on one post is a different act from a loop running a thousand, but the tools are there to be used at human scale.
What we do about it, and what we will not promise
Caps are enforced server-side, not typed into a settings field you can raise. A new seat runs 20 invitations a day and 80 a week, with a warm-up ramp that multiplies those by 0.5x in week zero and 0.75x in week one before reaching full volume. You cannot type over it, and neither can your agency.
Every visible action passes a human approval gate. Creating a sequence sends nothing. Enrolling people queues drafts. Any reply stops the remaining follow-ups in that thread instantly. There is no browser extension, because the architecture is the risk.
What we will not do is put a number on your safety that we have not measured. Our ban rate is in its measuring window and the page says measuring rather than showing a figure we cannot defend. Several vendors in this category advertise a ban rate with no methodology, no denominator and no date. That is marketing, and you should discount it accordingly.
Accounts that qualified under the original founding offer may have a conditional service-credit guarantee described in section 8 of our terms. It is not a shield against restriction or a refund, and it does not apply to every new account.
How to actually decide
Three questions settle it for most people. How old and how valuable is the account? A primary profile with a decade of relationships and inbound is a different bet from a second account you opened for prospecting.
Could you absorb a month without invitations? If your pipeline has one channel and it is this one, the middle of the ladder is your real downside, not the bottom.
Is it your account or someone else's? Running a client's seat changes who carries the consequence, and that is worth its own conversation before the first invite goes out.
If the answer to those is that you are not comfortable, the honest recommendation is to not use any tool in this category, ours included. The category does not have a compliant option, and anyone offering you one is selling.
The enforcement ladder, in the order it arrives
| Stage | What happens | Typical recovery |
|---|---|---|
| Warning | An in-product notice that automated activity was detected, account otherwise untouched | Stop, and it usually ends there |
| Invitation restriction | Invites are blocked, messaging and the rest of the account keep working | Commonly days to a few weeks |
| Temporary account restriction | Account locked pending review, often with an identity check | Identity verification plus a waiting period |
| Permanent closure | Account closed | Appeal, with a narrow success path |
Questions people ask next
Does LinkedBoost violate LinkedIn's terms of service?
LinkedIn's User Agreement section 8.2 prohibits bots and unauthorised automated methods for sending messages, adding contacts, and commenting or liking posts. LinkedBoost automates those actions with your approval, so it sits against that clause, as does every tool in this category. We state this in our own terms rather than leaving you to find it.
Can LinkedIn tell which tool I am using?
Sometimes directly, particularly browser extensions that modify the page inside your session. More often it infers from behaviour: timing that is too regular, activity outside human hours, and volume that keeps climbing while acceptance falls.
What happens first if LinkedIn flags my account?
Usually a warning, then an invitation restriction where invites stop but the rest of the account works. Continuing after the warning is what escalates it. Stopping at the warning usually ends it.
Is there a LinkedIn outreach tool that is terms compliant?
Not for outbound. LinkedIn's self-serve APIs cover sign-in and sharing; there is no official endpoint for invitations, member messaging or people search. Any vendor claiming compliance for automated outreach is claiming something the platform does not offer.
Why this page exists: Asked verbatim, twice, in a founder community drop (Sep 2026) and unanswered on site at the time; plus the safety keyword cluster (linkedin automation ban, is linked helper safe, linkedin connection request limit).
LinkedBoost is the LinkedIn MCP server: your agent sources, drafts, sends and works the inbox, inside caps the server enforces rather than suggests.
Related answers
No. LinkedIn restricts accounts for behaving like automation, not for using it. The tool is invisible to the platform; the pattern is not. Mechanical timing, around-the-clock activity, and volume that ignores falling acceptance are what get scored.
Almost nobody is banned for using a tool. Accounts get restricted for a pattern: volume on a young account, mechanical timing, identical copy at scale, falling acceptance that nobody slowed down for, and "I don't know this person" reports. Enforcement arrives as a ladder, and the first rung is survivable.