---
name: linkedin-oauth-app
description: Creates or signs in to a LinkedIn developer account and registers a LinkedIn app to obtain OAuth2 client ID and client secret — covering the mandatory LinkedIn Page association and super-admin app verification, the per-Product access requests that actually unlock scopes, exact-match redirect URLs, 60-day tokens and programmatic refresh tokens, and a safe credential handoff. Use when asked to get LinkedIn OAuth credentials, set up a LinkedIn developer app, apply for the Advertising API / Community Management API / Marketing Developer Platform, rotate a LinkedIn client secret, or fix a LinkedIn error like `Invalid scope`, `Redirect_uri doesn't match`, or a connection that dies every 60 days. For any other vendor's developer portal, use that vendor's skill instead.
---

# LinkedIn OAuth2 App Registration

Get a working LinkedIn OAuth2 client — a developer app, a verified LinkedIn Page association, the right Products,
redirect URLs, scopes, client ID and client secret — for a platform that connects many customers' LinkedIn accounts.

Two things about LinkedIn are unlike every other portal in this repo, and both are gates rather than fields.

**First: the app is worthless until a human who is not you approves it.** A LinkedIn app must be associated with a
LinkedIn **Page**, and that Page's **super admin** must verify the app through a one-time URL you generate and send
them. You cannot self-approve, you cannot skip it, and the link expires in 30 days. If nobody on your side is a super
admin of a real company Page, the run stops here — and a fake Page is a documented rejection reason.

**Second: scopes are not something you choose — they are granted by Product.** Creating the app gives you almost
nothing. Each API family (Sign In with LinkedIn using OpenID Connect, Share on LinkedIn, Advertising API, Community
Management API, Lead Sync, Conversions, Events Management, Matched Audiences, Talent, Sales Navigator, Messages) is a
**Product** you add on the app's Products tab. Three are self-serve; the ones a data connector actually needs require
an **application and review** by LinkedIn, and the scope strings only appear on your Auth tab *after* approval. A
scope you have not been granted fails at the authorize step with `Invalid scope`, not at save time. §4 is the section
that decides whether this project ships this month or next quarter.

Plan for the review calendar, not the form.

## Inputs to collect before you start

Ask in one batch. Never invent.

| Input | Notes |
| --- | --- |
| **App name**, description, app logo | Shown on the member consent screen |
| **LinkedIn Page** to associate | Must be a real company Page you control (§2) |
| **Who is the Page super admin** | They must click your verification link (§3) |
| **Privacy policy URL**, terms URL | Required on the app form |
| **Redirect URLs** | Every callback host your platform serves (§5) |
| **Which Products / scope set** | What the connector actually calls (§4, §6) |
| **New app or edit to an existing one** | New credentials orphan existing connections (§1) |
| **Is server-side token refresh required?** | Blocking — needs MDP approval (§8) |
| **Business/legal details** | Legal name, registered address, website, business email — the access forms ask |

## Quick Start

1. Confirm a **new app** is needed rather than an edit — existing connections are bound to the current client ID (§1).
2. Sign in to the Developer Portal with a LinkedIn member account; make sure a LinkedIn Page exists (§2).
3. Create the app, associate the Page, then **get the Page super admin to verify it** (§3).
4. Add the **Products** you need and file the access requests — the long pole (§4).
5. Add **every** redirect URL, exactly (§5).
6. Confirm the granted scopes on the Auth tab and send exactly those in `scope` (§6).
7. Capture client ID and client secret from the Auth tab (§7).
8. Settle the token story: 60-day access tokens, programmatic refresh tokens only for approved partners (§8).
9. Verify end-to-end with a real member outside your own org (§9).
10. Hand the credentials over — never commit them (§10).

## Platform state (verified 2026-09-20 — re-verify before trusting)

- **Developer portal**: `https://www.linkedin.com/developers/apps`. An app page has **Settings**, **Auth**,
  **Products** and **Analytics** tabs. Settings holds the Page association and the **Verify** button; Auth holds
  client ID, client secret, redirect URLs and the list of **currently granted** scopes; Products is where you add and
  apply for API access; Analytics shows per-endpoint rate limits and the refresh-token quota table.
- **Page association and super-admin verification are required**, and LinkedIn documents company Page verification as
  a prerequisite for applying to Products. "Do not use a fake company page." The verification URL is generated under
  Settings → Verify → **Generate URL**, sent to the super admin out of band; they have **30 days**. A denial
  **invalidates every link generated by any developer on that app**, so coordinate before sending.
- **Self-serve Products (Open Permissions)** — no review: *Sign In with LinkedIn using OpenID Connect* (`profile`,
  `email`, plus `openid`) and *Share on LinkedIn* (`w_member_social`).
- **Review-gated Products**: Advertising API, Community Management API, Lead Sync API, Conversions API, Events
  Management API, Matched Audiences API (all "open to all approved developers", i.e. an application). **Audience
  Insights** and **Media Planning** are restricted to developers LinkedIn qualifies case by case. **Company
  Intelligence API** is not accepting new applications. **Compliance** (`r_compliance`, `w_compliance`) is closed and
  cannot be requested. **Messages API** usage is "restricted to approved partners, subject to limitations via API
  agreement". Talent (RSC, Apply Connect, Apply with LinkedIn, Premium Job Posting) and Sales Navigator (SNAP) are
  separate partner applications made off-portal.
- **Access tiers**: Advertising API and Community Management API each start at **Development** tier and require a
  separate upgrade request for **Standard**. Development tier is genuinely limiting — see §4.
- **Tokens**: access tokens are issued with a **60-day** lifespan. **Programmatic refresh tokens are available to
  approved Marketing Developer Platform (MDP) partners only**; by default they are valid **365 days** and that TTL is
  *not* extended by use. Without them, "refreshing" means sending the member back through the authorize URL, which is
  only silent while they are still logged in to linkedin.com and their current token has not expired.
- **Legacy Sign In with LinkedIn was deprecated on 1 August 2023.** New work uses `openid profile email` and the
  userinfo endpoint, not `r_liteprofile` / `r_emailaddress` and `/v2/me`.
- **Marketing versioned APIs sunset on a rolling schedule** — version `202510` sunsets 15 October 2026. The API
  version is a request header, not part of registration, but a connector pinned to an old version breaks on that date
  independently of anything in this skill.

If the portal does not look like this, stop and report what you actually see rather than clicking on.

## 1. Decide: reuse the existing app, or register a new one

A new app means a **new client ID, and every existing member authorization is bound to the old one** — every customer
re-authorizes. It also means starting the Page verification and every Product review again from zero, which on
LinkedIn is weeks, not minutes.

Reuse the existing app for: adding a redirect URL, adding a Product or scope, rotating a compromised secret, or
diagnosing an authorization failure. Register a **new** app only when the user explicitly wants one — a replacement
for a compromised app, a separate app for a separate product line, or a deliberate split of Development-tier testing
from production. Say which path you are taking before you touch anything.

One LinkedIn-specific wrinkle: **changing the scope set forces every member to re-consent**, and requesting a
different scope than previously granted **invalidates the member's existing access tokens**. Adding a Product is
therefore a customer-visible event too, just a cheaper one than a new client ID.

## 2. Account and Page: what must exist first

- **A LinkedIn member account.** Apps are owned by a member, not by an organization, and team members are added to
  the app afterwards. Use a durable account, not a personal one belonging to someone who may leave.
- **A LinkedIn Page** for your company. Create one first if it does not exist; the app form asks for it by name and
  API Products available to individual developers must have a default Page associated.
- **A Page super admin who will cooperate.** This is the one person who can unblock §3. Identify them by name before
  you create anything.
- **Business details** — legal name, registered address, website, business email. The Product access forms ask.

Hand control back to the user for anything only they can do: LinkedIn login and 2FA, creating or claiming the Page,
accepting the API Terms of Use, and the super-admin click in §3. Do not retry a blocked step in a loop.

**If this session has no browser automation** (the usual case for a CLI or cloud run), do not pretend to click. Hand
the user an exact, ordered click path with the literal values to paste — the redirect URLs from §5 and the scope list
from §6 — then continue once they report back with the client ID and the granted-scope list from the Auth tab.

## 3. Create the app and get it verified

**Create**: `https://www.linkedin.com/developers/apps/new`. Fill in app name, the **LinkedIn Page**, privacy policy
URL, and app logo. Accept the API Terms of Use. The app exists immediately — and does nothing yet.

**Verify** (the human gate):

1. Open the app → **Settings** tab → **Verify**.
2. In the *Verify company* dialog, click **Generate URL**, then **Copy URL**.
3. Send that URL to the Page **super admin** (email or LinkedIn message). Tell them what they are approving; the
   approval screen shows them your name, photo, title, company and the app details.
4. They have **30 days**. On approval the app shows as verified in Settings.

Three things worth knowing before you send it:

- A **denial invalidates all links generated by any developer on that app**, not just yours. Agree with the super
  admin first; one reflexive "deny" costs the whole team a regeneration cycle.
- Verification is a prerequisite for the Product access forms in §4, so a delay here delays everything downstream.
- Do not associate a Page you do not control to get unblocked. Fake Pages are a stated rejection reason and put the
  app itself at risk.

Also on Settings: add the teammates who should administer the app, so the run does not depend on one person's login.

## 4. Products and access requests — this is the gate

Scopes come from Products. On the app's **Products** tab you add a Product; self-serve ones enable immediately,
review-gated ones open an access form and then wait. **The scope strings appear on your Auth tab only after the
Product is granted.** Until then, sending that scope in the authorize URL returns `401 Invalid scope`.

| Product | How you get it | Scopes it grants (as LinkedIn spells them) |
| --- | --- | --- |
| **Sign In with LinkedIn using OpenID Connect** | Self-serve | `openid`, `profile`, `email` |
| **Share on LinkedIn** | Self-serve | `w_member_social` |
| **Advertising API** | Apply on the Products tab; review | `r_ads`, `rw_ads`, `r_ads_reporting`, `r_basicprofile`, `r_organization_admin`, `r_organization_social`, `rw_organization_admin`, `w_organization_social`, `w_member_social`, `r_1st_connections_size` |
| **Community Management API** | Apply; review + app screen recording + test credentials | `r_organization_social`, `r_organization_social_feed`, `w_organization_social`, `w_organization_social_feed`, `rw_organization_admin`, `r_organization_followers`, `r_basicprofile`, `w_member_social`, `w_member_social_feed`, `r_member_profileAnalytics`, `r_member_postAnalytics`, `r_1st_connections_size` |
| **Lead Sync API** | Apply; review | `r_marketing_leadgen_automation`, `r_ads`, `r_events`, `r_liteprofile`, `r_organization_admin` |
| **Conversions API** | Apply; review | `rw_conversions`, `r_ads`, `r_liteprofile` |
| **Events Management API** | Apply; self-serve on request | `r_events`, `rw_events` |
| **Matched Audiences API** | Apply; requires Advertising API first | `rw_dmp_segments` |
| **Audience Insights / Media Planning** | Restricted; qualification survey, case by case | app-level permission; `rw_media_plans` for saved media plans |
| **Messages API** | Approved partners only, under an API agreement | `r_messages`, `w_messages` — **not obtainable self-serve** |
| **Talent (RSC, Apply Connect, Apply with LinkedIn, Premium Job Posting)** | Off-portal partner application | Per program |
| **Sales Navigator (SNAP)** | Off-portal partner application | `r_sales_nav_analytics`, `r_sales_nav_display`, `r_sales_nav_validation`, `r_sales_nav_profiles` |
| **Compliance** | **Closed** — cannot be requested | `r_compliance`, `w_compliance` |

Before you file anything, read LinkedIn's **API and data restrictions** page (linked in §References). Applications
are rejected for restricted use cases, and that rejection costs a full cycle.

**Tiers are a second gate that people forget.** Both big Products start at Development tier:

- **Advertising API — Development**: unlimited *read* on ad accounts you administer; *edit* on at most **five** ad
  accounts; creation of exactly **one** test ad account through the API. Standard tier (unlimited edit, unlimited ad
  account creation) is a separate request through the Developer Support Portal, **with a video demonstrating your
  platform creating, editing or optimizing LinkedIn campaigns**. A multi-tenant connector cannot run on Development
  tier past its sixth customer.
- **Community Management API — Development**: **500 API calls per app per 24h**, **100 API calls per member per
  24h**, **BATCH_GET is not allowed at all**, and social-action webhook push notifications are **disabled**. You are
  expected to finish the integration within **twelve months**. Standard tier removes the restrictions and needs a
  form, a screen recording and test credentials.

Two things to stop and ask about rather than guess: the business/legal details on the access forms, and the demo
video and test credentials. Those are the user's to provide.

### Product fact — what this platform's connector needs

As of 2026-09-20, **Unified.to's LinkedIn connector requests**, depending on which objects a customer enables:

- Login / identity: `openid`, `profile`, `email`
- Advertising objects (ad accounts, campaigns, campaign groups, ads, creatives, targeting): `r_ads`, `rw_ads`
- Ad reporting: `r_ads_reporting`
- Organization pages, posts and social engagement: `r_organization_social`, `w_organization_social`,
  `rw_organization_admin`
- Member profile: `r_basicprofile`
- Messaging: `r_messages`, `w_messages`

Which implies, at minimum: **Sign In with LinkedIn using OpenID Connect** (self-serve) for the identity scopes;
**Advertising API** for `r_ads` / `rw_ads` / `r_ads_reporting` / `r_basicprofile`; **Advertising API and/or Community
Management API** for the `*_organization_*` scopes; and, for messaging, an **approved-partner agreement covering the
Messages API** — `r_messages` and `w_messages` appear in no self-serve or marketing Product, so the messaging objects
simply will not authorize without that partnership. The connector also exchanges and refreshes tokens server-side
with `client_id` + `client_secret` (form-encoded POST), which means it depends on **programmatic refresh tokens** and
therefore on MDP approval (§8); it pins a dated `LinkedIn-Version` request header and `X-RestLi-Protocol-Version:
2.0.0`, and pages with `start`/`count` over `elements` at up to 100 per page.

Treat that list as a starting point, not gospel: **confirm the current scope set and the messaging/MDP status with
the connector's owner** before filing access requests, and request only the scopes the customer's enabled objects
need. LinkedIn asks for the least number of scope permissions, and a broad ask is a slower review.

## 5. Redirect URLs

Add every callback host your platform serves, on the app's **Auth** tab under *Redirect URLs*. For Unified.to these
are one per data center; confirm the current list with the platform owner rather than assuming:

```
https://api.unified.to/oauth/code          # us (default)
https://api-eu.unified.to/oauth/code       # eu
https://api-au.unified.to/oauth/code       # au
https://api-dev.unified.to/oauth/code      # dev
```

LinkedIn's rules, which are stricter than they look:

- **HTTPS and absolute.** `https://dev.example.com/auth/linkedin/callback`, never a bare path.
- **Query parameters are ignored** — a registered `…/callback?id=1` is stored as `…/callback`. Do not try to encode
  tenant or state in the registered URL; that is what `state` is for.
- **No `#` anywhere.** A URL containing a fragment is invalid.
- **Exact match at authorize time.** The `redirect_uri` you send must match a registered value exactly; a mismatch is
  `401 Redirect_uri doesn't match` when a customer clicks connect, not when you save the app.
- The same `redirect_uri` must be sent **again** on the token exchange, and it is a required parameter there. Omitting
  it returns `400 invalid_request "A required parameter redirect_uri is missing"`.

## 6. Scopes

`scope` is URL-encoded and space-delimited on the authorize URL. Three rules do most of the damage:

1. **Only request scopes your Auth tab shows as granted.** Anything else is `401 Invalid scope`. The Auth tab is the
   source of truth, not this document and not the Products table.
2. **Consent is all-or-nothing.** If you request several scopes the member must accept all of them; they cannot pick.
   Request the minimum set for what the customer actually enabled.
3. **Changing the set re-consents everyone.** If your app's scopes change, members must re-authenticate, and
   requesting a different scope than previously granted invalidates the previously issued access tokens.

For identity, use the OpenID Connect trio — `openid` (returns the ID token), `profile` (id, name, picture), `email`
(primary address) — and read the member from `GET https://api.linkedin.com/v2/userinfo` or the ID token, validating
against LinkedIn's discovery document and JWKS. Do **not** build new work on `r_liteprofile` / `r_emailaddress` and
`/v2/me`: that product was deprecated on 1 August 2023. Note that `email` and `email_verified` are documented as
**optional** in the userinfo response — handle their absence.

Watch for the two legacy scopes that are still live inside newer Products: Lead Sync and Conversions grant
`r_liteprofile`, which is not the same thing as the OIDC `profile`. If you use those Products, you will hold both.

## 7. Capture the credentials

App → **Auth** tab → *Application credentials*: **Client ID** (also called the API key or consumer key) and
**Client Secret** ("Primary Client Secret"). The same tab lists the OAuth 2.0 scopes currently granted — capture that
list verbatim, because it is what §6 must match.

Endpoints (the same for every app; there is no per-tenant host):

- Authorize: `GET https://www.linkedin.com/oauth/v2/authorization`
- Token and refresh: `POST https://www.linkedin.com/oauth/v2/accessToken`, `Content-Type:
  application/x-www-form-urlencoded`
- API base: `https://api.linkedin.com`
- OIDC discovery: `https://www.linkedin.com/oauth/.well-known/openid-configuration`; JWKS:
  `https://www.linkedin.com/oauth/openid/jwks`

Also capture: the app's LinkedIn Page, the verification status, the Products granted and their **tier**, and the
authorization **code** lifetime (30 minutes, single use) if you are debugging an exchange.

LinkedIn warns explicitly: never pass the client secret in a URL or query string, and never post it in a support
forum or chat. Rotating the secret breaks every token exchange and refresh until the new value is deployed — existing
access tokens keep working until they expire, which makes the breakage look intermittent. Never rotate without
explicit go-ahead and a cutover plan.

Report the secret once so the user can paste it into their secret store, say plainly that it is now in the transcript
and can be rotated, then move on.

## 8. Token lifetimes and refresh

This is where LinkedIn connectors die quietly, sixty days after a successful launch.

| Fact | Consequence |
| --- | --- |
| Access tokens are issued with a **60-day** lifespan (`expires_in`, e.g. `5184000`) | A connector that never refreshes loses every connection two months after onboarding |
| **Programmatic refresh tokens are for approved MDP partners only** | Without MDP, there is no server-side refresh at all |
| Default programmatic refresh token TTL is **365 days**, and using it does **not** extend that TTL | Even a perfect refresh loop forces re-authorization once a year |
| Refreshing returns a new access token with a fresh 60-day TTL and the **remaining** refresh TTL | Track `refresh_token_expires_in` and warn customers before it hits zero |
| Without programmatic refresh, "refresh" means re-running the authorize URL | Silent **only** while the member is still logged in to linkedin.com *and* the current token has not expired — otherwise they see the consent screen again |
| LinkedIn "reserves the right to revoke Refresh Tokens or Access Tokens at any time" | The documented expectation is to fall back to the full OAuth flow and show the login screen. Build that path |
| Refresh-token minting has a **daily per-app quota**, resetting 00:00 UTC | The Analytics tab shows percent of quota used and a Throttled / Not Throttled flag. A mass re-refresh can throttle the whole app |

Refresh request: `grant_type=refresh_token`, `refresh_token`, `client_id`, `client_secret`, form-encoded, to the same
`/oauth/v2/accessToken` endpoint. An expired or revoked refresh token returns `400 invalid_request "The provided
authorization grant or refresh token is invalid, expired or revoked"` — the only fix is re-authorizing the member.

**Ask early whether MDP approval exists or is in flight.** If it does not, say so plainly: the app will register
fine, every connection will work for 60 days, and then all of them will fail at once. That is a finding to report,
not a step to work around.

Also plan for rate limits, since they shape the same loop: limits apply **per application** and **per member per
application**, reset at midnight UTC, and return **429**. Standard limits are not published — look them up per
endpoint on the app's **Analytics** tab, which only lists endpoints you have called at least once today. Developer
admins get an email alert at **75%** of an application-level quota, delayed 1–2 hours; member-level breaches do not
alert at all.

## 9. Verify end-to-end

Testing with your own account inside your own Page proves less than it looks — you are an admin of everything.

1. Use the portal **Token Generator** (`/developers/tools/oauth/token-generator`) first to confirm the app and its
   granted scopes work at all, before blaming your own code.
2. Then run the real flow through your platform's connect URL with a **different member**, one whose LinkedIn roles
   match a customer's (a Page `ADMINISTRATOR`, or an ad account `ACCOUNT_MANAGER` / `CAMPAIGN_MANAGER`).
3. Confirm the token response carries `refresh_token` and `refresh_token_expires_in`. **If those fields are absent,
   the app does not have programmatic refresh tokens** — stop and go back to §8.
4. Force a refresh, and check that the new response's `refresh_token_expires_in` has *decreased* rather than reset.
5. Make one real read call against `https://api.linkedin.com` with the version and protocol headers the connector
   sends, not a bare `/v2/me`.
6. Paste the token into the **Token Inspector** to confirm the scopes and TTL are what you expect.

| Symptom | Cause |
| --- | --- |
| `401 Invalid scope` at authorize | Scope not granted to the app — the Product is missing or still under review (§4) |
| `401 Redirect_uri doesn't match` | Redirect URL not registered exactly; or a `#`, or you relied on a query string LinkedIn stripped (§5) |
| `401 Client_id doesn't match` | Wrong client ID for this environment |
| `400 invalid_request "…redirect_uri is missing"` | Redirect URI omitted on the **token exchange**, where it is also required (§5) |
| `400 invalid_redirect_uri "…does not match authorization code. Or authorization code expired…"` | Different `redirect_uri` on exchange than on authorize, or the code is past its 30-minute single-use life |
| Token response has no `refresh_token` | App is not approved for programmatic refresh tokens (§8) |
| All connections fail about 60 days after launch | No refresh path — access tokens expired (§8) |
| All connections fail about a year in | Refresh token hit its 365-day fixed TTL; members must re-authorize (§8) |
| Members suddenly re-prompted for consent | The app's scope set changed (§6) |
| Previously working tokens stop working after a scope change | Requesting a different scope than granted invalidates earlier tokens (§6) |
| `429` on a working integration | Per-app or per-member daily limit; check the Analytics tab (§8) |
| Refresh calls throttled but API calls fine | Daily refresh-token minting quota exhausted; resets 00:00 UTC (§8) |
| Edits work for a few customers and fail for the rest | Advertising API **Development** tier — 5 ad accounts (§4) |
| `BATCH_GET` requests rejected outright | Community Management **Development** tier (§4) |
| Auth works but the customer sees no data | Member lacks the Page or ad account **role**; scopes never exceed what the member may do |
| App verification never completes | Super admin has not clicked, or denied — which invalidates all generated links (§3) |

## 10. Hand off — never commit the secret

- **Do not** write the client secret into source control, a test, a fixture, a committed `.env`, a ticket, a PR body,
  or a chat channel. Values go to the user, for the secret store or console.
- If a code change is needed (a redirect host, a scope list, a refresh path, a version header), keep it secret-free
  and say what the human must set out of band.
- Close with: app name and client ID; the associated LinkedIn Page and its verification status; where the secret was
  delivered; the Products granted, still pending, and their **tier**; the exact scope strings on the Auth tab; the
  registered redirect URLs; the refresh-token position (MDP approved, applied for, or not available) and what that
  means for connection lifetime; and anything left for the user to do.

## Stop and ask

Hand back to a human rather than guessing when: no LinkedIn Page exists, or no super admin will verify the app
(§3) — this cannot be worked around, and a fake Page is a rejection reason; a Product access form asks for business,
legal, compliance or volume claims, a demo video, or test credentials (§4); the connector needs `r_messages` /
`w_messages` or any Talent or Sales Navigator scope, which require a partner agreement negotiated off-portal; the
platform has no programmatic refresh tokens and the user has not accepted 60-day connection lifetimes (§8); someone
proposes registering a new app for a live integration, which re-authorizes every customer (§1); a Development-tier
limit means the current plan cannot serve the intended customer count (§4); or the portal does not match the
**Platform state** section above.

## References

Official LinkedIn / Microsoft Learn docs only — every URL below verified to resolve on 2026-09-20.

- Authenticating with OAuth 2.0 overview — https://learn.microsoft.com/en-us/linkedin/shared/authentication/authentication
- Authorization Code Flow (3-legged OAuth) — https://learn.microsoft.com/en-us/linkedin/shared/authentication/authorization-code-flow
- Getting access to LinkedIn APIs (Products and partner programs) — https://learn.microsoft.com/en-us/linkedin/shared/authentication/getting-access
- Programmatic refresh tokens — https://learn.microsoft.com/en-us/linkedin/shared/authentication/programmatic-refresh-tokens
- Token introspection — https://learn.microsoft.com/en-us/linkedin/shared/authentication/token-introspection
- Developer portal tools (token generator, inspector, refresh-token quota) — https://learn.microsoft.com/en-us/linkedin/shared/authentication/developer-portal-tools
- Rate limiting — https://learn.microsoft.com/en-us/linkedin/shared/api-guide/concepts/rate-limits
- Error handling — https://learn.microsoft.com/en-us/linkedin/shared/api-guide/concepts/error-handling
- Securing applications (client secret handling) — https://learn.microsoft.com/en-us/linkedin/shared/api-guide/best-practices/secure-applications
- Marketing quick start (apply for API access) — https://learn.microsoft.com/en-us/linkedin/marketing/quick-start
- Increasing access — permissions table and access tiers — https://learn.microsoft.com/en-us/linkedin/marketing/increasing-access
- API and data restrictions (read before applying) — https://learn.microsoft.com/en-us/linkedin/marketing/restricted-use-cases
- Community Management app review — https://learn.microsoft.com/en-us/linkedin/marketing/community-management-app-review
- Page and ad account roles — https://learn.microsoft.com/en-us/linkedin/marketing/getting-started
- Marketing API versioning and sunset schedule — https://learn.microsoft.com/en-us/linkedin/marketing/versioning
- Sign In with LinkedIn using OpenID Connect — https://learn.microsoft.com/en-us/linkedin/consumer/integrations/self-serve/sign-in-with-linkedin-v2
- Legacy Sign In with LinkedIn (deprecated 2023-08-01) — https://learn.microsoft.com/en-us/linkedin/consumer/integrations/self-serve/sign-in-with-linkedin
- Messages API (approved partners only) — https://learn.microsoft.com/en-us/linkedin/shared/integrations/communications/messages
- Recruiter System Connect (Talent) — https://learn.microsoft.com/en-us/linkedin/talent/recruiter-system-connect
- Send an app verification request for a LinkedIn Page — https://www.linkedin.com/help/linkedin/answer/a1665329
- Approve or deny an app verification request — https://www.linkedin.com/help/linkedin/answer/a1669245
- Associate an app with a LinkedIn Page — https://www.linkedin.com/help/linkedin/answer/a548360
- Create a LinkedIn Page — https://www.linkedin.com/help/linkedin/answer/a543852
- Developer Portal — My apps — https://www.linkedin.com/developers/apps
- Create a new app — https://www.linkedin.com/developers/apps/new
- OAuth token generator — https://www.linkedin.com/developers/tools/oauth/token-generator
- OAuth token inspector — https://www.linkedin.com/developers/tools/oauth/token-inspector
- OIDC discovery document — https://www.linkedin.com/oauth/.well-known/openid-configuration
- OIDC JWKS — https://www.linkedin.com/oauth/openid/jwks
- LinkedIn Developer Support Portal — https://www.linkedin.com/help/linkedin/ask/dsapi
- API Terms of Use — https://www.linkedin.com/legal/l/api-terms-of-use
- Talent Solutions partner application — https://business.linkedin.com/talent-solutions/ats-partners/partner-application
- Sales Navigator (SNAP) partner application — https://business.linkedin.com/sales-solutions/partners/become-a-partner
- LinkedIn Marketing Partners — https://business.linkedin.com/marketing-solutions/marketing-partners
- LinkedIn Developer Solutions — https://developer.linkedin.com/
