Hark's Browser Agent Puts LinkedIn API Limits in Focus

gtm-api.com explains where LinkedIn’s official API access ends and what agencies should check before trusting AI-led outreach.
Hark's Browser Agent Puts LinkedIn API Limits in Focus
Article by Ryan de Smidt
|

Hark's Handoff browser agent has put LinkedIn's API limits under fresh scrutiny.

That came into focus in August, when TechCrunch reported that Hark says Handoff can navigate sites without official APIs, including LinkedIn, by reading page structure and visual information.

AI is also becoming routine in sales workflows. LinkedIn and Ipsos found in 2025 that 88% of sales professionals used AI weekly and 56% used it daily, while agencies selling LinkedIn outreach are increasingly being offered agents that promise to handle the work.

The demo tends to run the same way, with a chat window, an instruction typed in plain English, and a connection request going out at the end of it.

Which API the agent just called is the question that decides whether the demo survives contact with LinkedIn.

It matters more than it sounds, because LinkedIn's own developer platform does not hand out the endpoints that demo appears to use.

This is not a gap in the documentation, because the endpoints are documented in detail. They are restricted.

gtm-api.com works in that gap by providing an account-based API and MCP server for AI agents.

Evgenii Salamatov, co-founder of gtm-api.com, says the distinction starts with what LinkedIn's official API was built to do.

"The official API is very good at the two jobs it was designed for, which are signing a member in and posting on their behalf," Salamatov says.

"It was never built to let software reach somebody else, and the parts that could have done that are shut."

YouTube channel, Tech With Tim, demonstrates how a browser-use AI agent can navigate websites, carry out actions and work with information through the browser:

What LinkedIn's Open Permissions Actually Cover

LinkedIn's access documentation describes Open Permissions as the only ones available to all developers without special approval.

There are three of them, and they belong to two products:

  1. Sign In with LinkedIn returns the member's name, photo and email address.
  2. Share on LinkedIn lets an application post, comment and like as the member who authorized it.

Both are scoped to that member's own presence on the platform. But neither provides open access for general prospecting or connection outreach to other members.

"You can build a very good publishing tool on the open permissions, and plenty of people have," Salamatov says.

"What you cannot build is outreach, because outreach is by definition an action aimed at a person who has not authorized your app."

YouTube channel, Learn21 Academy, explains how LinkedIn's developer API supports authenticated sign-in and posting through its standard developer products:

Three LinkedIn API Limits That Shape Outreach

The gap becomes clearest across three functions that outreach tools typically need.

1. Invitations

The Invitations API accepts a person, an email address or a phone number, and it sends a connection request.

Its documentation page carries the line that settles the matter. Usage of this API is restricted to approved partners, subject to limitations via API agreement.

2. Messaging

The Messages API reaches first-degree connections only, so it cannot open a conversation with a stranger even for an approved partner.

The same page rules out the use case directly, stating that member actions do not include an automated or scheduled event.

Neither endpoint is available through standard developer access. Access runs through a partner agreement, and the same restriction note sits on both pages.

For reference, LinkedIn's access documentation does list two permissions as closed outright, the Compliance pair, describing access to them as something that may not be requested.

3. People Search

LinkedIn does not offer an open, general-purpose people-search endpoint for prospecting.

LinkedIn's People API index lists profile retrieval and editing, contact details, a member's own connections, and a lookup that resolves an email address to a profile.

However, none of these provides an open member-search function for general prospecting.

A separate page, covering the closest thing to a lookup by name, adds the sentence that closes the loop, "You cannot 'browse members' by VanityNames."

"Those three pages are the whole business case for this category," Salamatov says.

"What a vendor does next is the only thing that separates one of us from another."

gtm-api.com demonstrates LinkedIn outreach actions available through a connected account, including connection requests, messages and InMails.

So What Is the Agent Actually Driving

The layer underneath is an account-based API.

It acts inside a LinkedIn account the customer owns and has connected, rather than querying a dataset about people.

The starting position needs saying plainly. LinkedIn's help center states that it does not permit third-party software that automates activity, and that accounts using it can be restricted.

Every tool in this category carries account risk that no vendor can remove. What separates them is what happens before an action fires.

Against those official API limits, gtm-api.com publishes the shape of its own alternative, with limits enforced on the server before the action leaves, per-action budgets set when an account connects, and an allowance the account earns over weeks.

"Anyone can wire up a send button, and it takes about a weekend," Salamatov says.

"The year goes into everything that stops the send button from being used stupidly, and that is the part worth not building yourself."

gtm-api.com shows how an existing LinkedIn account can connect to an API and MCP layer for AI-agent workflows:

Where MCP Comes In

Model Context Protocol (MCP) arrived in November 2024, when Anthropic published it as a standard for connecting AI assistants to the systems where data lives.

Nearly two years on, MCP has become a common way for major AI clients to connect to external tools and services.

The protocol's own documentation names Claude, ChatGPT, Visual Studio Code and Cursor among the applications that support it, and Google added remote MCP servers to the Gemini API's managed agents in July.

For an agency, the practical effect is small and specific.

An agent connected to a LinkedIn MCP server receives a typed list of the actions it is allowed to take and calls them by name.

In this setup, the agent gets no browser, no password and no free hand.

"The agent decides what to do, and the API decides what is allowed," Salamatov says. "Keeping those two jobs in separate systems is most of the safety story."

Anthropic explains how Model Context Protocol connects AI applications to external tools and data through a standardized interface:

What to Ask Before Buying One

Four questions separate the products in this category, and none of them are about the demo.

1. Whose account is it?

An agent acting inside an account the client owns is a different risk from a vendor's shared dataset, and the answer should be in writing.

2. Where do the limits live?

A cap the client's own code can raise is a suggestion.

3. What happens on a refusal?

The useful answer is that the action pauses and the account's allowance drops.

4. What does the log show?

Every action an agent takes should be visible afterwards, per account, with what was sent and when.

Microsoft Mechanics expands on this by explaining how identity, least-privilege access and layered security controls can reduce risk when AI agents interact with connected systems:

The Discipline Behind an Agent That Lasts

The category has spent a year selling autonomy. The products that survive contact with LinkedIn are the ones selling restraint.

An agent that can send 500 invitations is not an achievement, because LinkedIn was always going to respond to that volume.

An agent that will not send the sixth invitation today is a product decision somebody had to make on purpose.

Agencies buying in this market are choosing whose judgment sits between the instruction and the account, which is what decides whether the client still has an account next quarter.

👍👎💗🤯
Latest AI News
Receive our NewsletterJoin over 70,000 B2B decision-makers growing their brands