The problem nobody documents
Every MCP tutorial ends at the handshake. You add the server, the tools appear, the model answers a question about your data, and the write-up stops there. Then you point the thing at LinkedIn and hit the part no README covers: outreach sends from somebody, and that somebody has a reputation, a connection graph and a history the platform is watching.
LinkedIn's User Agreement is explicit that you may not use bots or other automated methods to access the service. Enforcement is per account — a restriction, a checkpoint, sometimes removal. If the account carrying that risk is your own profile, you are betting a decade of professional network on an agent's judgement during an hour you were not watching. That is the whole argument for a separate sending identity, and it has nothing to do with what anyone is selling.
The honest version of the risk
Three options, honestly
| Your own profile | Buy an aged account | Rent a managed account | |
|---|---|---|---|
| What you get | The profile you already have | Ownership of an account with existing tenure | An operated account, replaced if it goes down |
| Time to first send | Immediate | Days — transfer, secure, warm up | Shortest — it arrives warmed |
| Who carries the risk | You, personally | You | The operator, contractually |
| If it gets restricted | You lose your network | You lose the asset you bought | It is replaced; the campaign moves |
| Infrastructure to run | Yours to arrange | Yours — proxy, browser profile, warm-up | Included by the operator |
| Best when | Never, for automation | You want to own it and can operate it | You want the campaign running, not a project |
Rent — the shorter path
Somebody else keeps the account alive, on its own residential IP, and swaps it when it stops working. For an agent setup that is the point: your failure mode becomes "the campaign pauses for a day" rather than "the project stops".
Rent a verified LinkedIn accountBuy — when you want to own it
An aged account with real tenure and a connection graph, transferred to you. No monthly line item, and no one to call either: warm-up, proxy, browser profile and recovery are yours.
Buy an aged account outrightWhat an agent-driveable account actually needs
Whichever route you take, the checklist is the same. An account that fails any of these will not survive sustained outreach, agent-driven or not:
- Tenure. An account created last week that starts sending invites today is the easiest pattern in the world to spot.
- A real connection graph. Existing connections make an invite look like networking rather than prospecting, and they widen who is reachable at all.
- Verification. LinkedIn's own identity and workplace verification sits on the profile as a trust signal a recipient can see.
- A dedicated residential IP with a stable geography. One account, one IP, one country — a profile that logs in from three continents in a day is a flag, and a shared IP inherits every other tenant's reputation.
- A coherent profile. Photo, headline, experience, some activity. It has to read as a person, because the recipient decides on that in two seconds.
- Pacing you cannot override. A weekly invite ceiling, a working-hours window and randomised gaps between actions — enforced by the system, not by the agent's good intentions.
How it wires into the MCP setup
Nothing about the account touches your MCP client. Credentials and infrastructure live in the workspace, and the agent only ever holds a workspace API key — so a leaked key exposes reads of your campaign data, never the LinkedIn login itself.
- In the workspace: the LinkedIn account is connected once, with its proxy, and the sending limits are set there.
- In the MCP client: only
Authorization: Bearer tcz_live_…— see step 0 of the Claude install. - In the tools: nothing account-shaped. No MCP tool can connect an account, read its credentials, change its proxy or raise its limits — see the tool reference.
Limits an agent has to respect
The caps live in the product and apply identically whether a person clicks send or an agent triggers the workflow: a per-sender weekly invite cap, a warm-up ramp for a new account, a working-hours window in the workspace timezone, a randomised gap between two actions on the same sender, and a review mode that by default holds every invite and message for a person to approve. No MCP tool can raise any of them — which is why sending is not exposed as a tool at all.
The practical implication for anyone building on this: your agent's job is deciding and summarising, not volume. If your plan needs more throughput, the answer is another account with its own caps, not a faster agent against one profile. That is the one scaling rule LinkedIn outreach has, and agents do not change it.
How to decide
- Testing the MCP setup this week? You do not need an account at all yet — the read tools return empty arrays and the handshake still works. Wire it up first.
- Running real outreach and want it working by Monday? Rent. It arrives warmed and somebody else owns the uptime.
- Building something you will run for a year, with the appetite to operate infrastructure? Buy, and budget the proxy, the browser profile and the warm-up time.
- Tempted to just use your own profile? Read the first section again.
Get the account your agent acts as
Managed and verified, on its own residential IP, replaced if it goes down — or bought outright if you would rather own it.
FAQ
Can my AI agent use my own LinkedIn profile?
Technically yes, and it is the option we would talk you out of. LinkedIn's User Agreement prohibits using software, bots or automated methods to access the service, and enforcement lands on the account — restriction or removal. On your personal profile that costs you your network and your history, not a campaign. Use an account you can afford to lose the same way you would not run a load test against your production database.
Do I need a separate account per agent?
Per sending identity, not per agent. One agent can operate several accounts, and an account can sit in several campaigns. What you should not do is run several unrelated outreach motions through one account and hope the volume looks human — the caps are per account, and that is where they bite.
Does TopClozer sell LinkedIn accounts?
No. We build the software and the MCP server. Accounts come from elsewhere — rented and managed, or bought outright — which is why this page links out instead of selling you something. It also means we have no reason to talk you out of the cheaper route if it fits.
Will a bought or rented account get restricted anyway?
It can. Anyone promising a zero-risk LinkedIn account is selling you something they cannot deliver: risk is reduced by age, a real connection graph, verification, a stable dedicated IP and conservative pacing, but no combination removes platform risk. The right question is not whether an account can be restricted — it is what happens to your campaign when one is, and whether it takes your personal profile with it.
What does the account cost?
Pricing lives with whoever supplies the account — see the rental and purchase pages linked above. We deliberately do not quote their numbers here; a second copy of someone else's price list only goes stale.