Zevari

Remote MCP server for LinkedIn sales workflows: research prospects, draft outreach, classify LinkedIn inbox replies, prepare campaigns, and stage sensitive LinkedIn actions behind review gates.

Documentation

LinkedIn MCP: the execution layer for outbound

A LinkedIn MCP exposes LinkedIn as tools an agent can call: search, score, draft, send, comment, classify. Zevari is the hosted LinkedIn MCP. Connect Claude Code, Codex, ChatGPT, Grok Bot in Cursor, or any MCP client - or REST. The endpoint is free to add; Operator is the platform subscription. Every write is staged for your approval before it sends. No browser cookies. No bans.

LinkedIn MCPREST APIClaude Code, Codex, CursorApproval gatesNo cookies

claude mcp add zevari https://mcp.zevari.ai/mcp

Run that, complete OAuth, and your agent has 189 LinkedIn and GTM tools. Prefer to script it yourself? Hit the same engine over our REST API from your own code.

Your agent discovers Zevari's LinkedIn tools through MCP.

Zevari loads workspace context, Voice DNA, and safety rules.

Outbound is drafted, staged, and approved before anything sends.

What is a LinkedIn MCP

MCP gives an agent hands. A LinkedIn MCP gives it LinkedIn.

MCP (Model Context Protocol) is the open standard that lets an agent call tools. A LinkedIn MCP exposes LinkedIn as tools: search profiles, score a prospect, draft a connection note, send a message, comment on a post, classify an inbox reply. Without one, an agent can find the needle in the haystack - it just cannot reach in and pull it out. Zevari is the hosted reach: free to add the endpoint, Operator for the platform, and every write approved by you.

This is what the GTM-engineering crowd means by outbound-as-code. Your ICP is config. Your sequences are defined once and advanced on a schedule. Your voice is trained, not templated. The whole motion runs from inside Claude Code, Codex, ChatGPT, Grok Bot, or your own code over REST - and a human signs off before anything touches your account. We call the category the LinkedIn execution layer. The slot was empty, or filled by cookie-scraping tools that admit ban risk. Zevari fills it safely.

How Zevari connects an agent to LinkedIn

Hosted, nothing to babysit

Zevari is hosted. There is nothing to self-host, no scraper to babysit, no cookie to refresh. Add one MCP endpoint, authorize through OAuth, and your agent has 189 LinkedIn and GTM tools. Engineers who prefer to drive it from their own stack call the 109 public REST endpoints.

If the first step in your stack is contact-data enrichment, read the MoltSets for LinkedIn guide and the developer workflow for turning verified emails, mobiles, companies, and LinkedIn URLs into safe Zevari campaigns.

One thing raw Claude Code cannot do alone: persistent scheduling. Claude runs when you run it, then forgets. Zevari holds state on our infrastructure - campaigns advance, warm-up sequences fire, the inbox gets classified - while your agent sleeps. Your agent sleeps; your pipeline does not.

A real session

You: Find 15 founders who posted about hiring an SDR in the last 30 days.

Agent: Searches signals, ICP-scores each 1 to 5 with reasons, returns 15.

You: Build a 3-step warm-up campaign for the 4s and 5s. Voice-match it.

Agent: Drafts notes in your Voice DNA, stages a warm-up plus connect sequence.

You: Approve.

Agent: Executes within your weekly ceiling, on a human-paced schedule.

You never leave Claude. You approve from the chat, from Slack, or from a digest. It does the things you would have to do, and you stay in control of every one.

What your agents can do

Real tools your agent calls, not a roadmap

The tool surface is 189 functions. You do not call them by hand - you tell your agent what you want and it orchestrates. No prompting expertise needed; just talk to it.

Voice DNA

Drafts trained on your sent messages, so outreach sounds like you, not a template and not generic AI. Another version of you that does not read like a robot.

Signal-based targeting

Finds people who posted about a topic in the last 30 days, ICP-scores each one 1 to 5 with written reasons, and reaches intent instead of a static list - the needle, not the haystack.

Campaigns and sequences

Multi-step LinkedIn campaigns your agent builds and advances on a schedule. Set the sequence once; targets move through it while you work on something else.

Inbox Radar

Classifies replies by intent and stages drafts for your approval, so you triage and qualify the inbox against your ICP without reading every DM by hand.

Warm-by-default

Reactions, comments, and profile views before the connection ask. Higher accept rates, lower ban risk, and you show up warm instead of cold-blasting strangers.

Hosted state

Persistent scheduling on our infrastructure - the one thing raw Claude Code or Codex cannot hold alone. Campaigns advance and the inbox gets classified while your agent sleeps.

Install for Claude Code, Codex, ChatGPT, and Grok Bot

One endpoint, a token or OAuth, and you are live

Claude Code is the fastest path and the one most operators run daily. Codex and ChatGPT connect with a bearer token. Grok Bot in Cursor uses the same hosted MCP endpoint as any other MCP client. Every MCP client gets the same 189 tools and the same safety model; custom code can use the 109 REST endpoints. Per-client install guides:

LinkedIn MCP for Claude

One command, then OAuth - the daily-driver path.

LinkedIn MCP for Codex

Bearer-token connection via the Codex MCP config.

LinkedIn MCP for ChatGPT

Connect through the bearer-token integration.

LinkedIn MCP for Grok Bot

Connect Grok Bot in Cursor as an MCP client to the same hosted endpoint.

LinkedIn MCP prompts

Copy-paste prompts that drive real outbound sessions.

MoltSets for LinkedIn

Use verified contact data as input, then let Zevari handle LinkedIn enrichment and approval-gated action.

Is a LinkedIn MCP safe? Will it get me banned?

"I don't want to be banned" is the first thing every buyer says, and it is the right question. Most Claude-to-LinkedIn bridges are browser-cookie automation - LinkedIn sees the logs and bans the account. Zevari was built to be the safe one: every write staged for approval, session-based connection with no stored cookies, enforced weekly ceilings (Free 40, Premium 150, Sales Navigator 200), working hours, behavioral pacing, duplicate checks, and burst caps. A year of refinement, zero ban incidents.

Read the full safety model

FAQ

LinkedIn MCP questions

What is a LinkedIn MCP?

MCP (Model Context Protocol) is the open standard that gives an agent hands. A LinkedIn MCP exposes LinkedIn as tools an agent can call: search profiles, score a prospect, draft a connection note, send a message, comment on a post, classify an inbox reply. Zevari is the hosted LinkedIn MCP. The endpoint is free to add; Operator is the platform subscription. Every write is staged for your approval. Connect Claude Code, Codex, ChatGPT, Grok Bot in Cursor, or any MCP client - or call the same engine over REST.

What is the difference between the MCP and the REST API?

Same engine, two front doors. Connect over MCP from Claude Code, Codex, or any MCP client and your agent orchestrates the 189 MCP tools for you. Or call our REST API directly from your own code when you want to script the motion yourself - most engineers prefer the API path. Both run the identical safety model and approval gates.

Will this get my LinkedIn account banned?

No. Zevari uses session-based connection with no stored browser cookies, enforces weekly connection ceilings, paces actions to human working hours with burst caps, and stages every write action for your approval. After a year of refinement it has zero ban incidents. Read the full safety model at /safety.

How many connection requests and messages can I send per week?

It depends on your LinkedIn plan, and Zevari enforces the ceiling for you: Free 40, Premium 150, Sales Navigator 200 per week. You do not need Sales Navigator to start - it only raises the ceiling.

Is there a warm-up sequence before outreach?

Yes. Zevari is warm-by-default - it can react to, comment on, and view a prospect's profile before sending the connection ask, which raises accept rates and lowers risk.

Which clients can I run Zevari in?

Any MCP client. Zevari works in Claude Code, Cowork, Claude Desktop, Codex, ChatGPT, and Grok Bot in Cursor, and you can also call the REST API from your own code. Operators most often run it in Claude Code. If you do not, connect OpenClaw, ChatGPT, Grok Bot in Cursor, Hermes, or your own code over MCP or REST - same Operator subscription.

Can I run LinkedIn outbound via Grok Bot?

Yes. Grok Bot in Cursor is an MCP client, not xAI Grok. Connect it to the same hosted Zevari endpoint (or REST). Same approval gates: every send is staged for you to approve. Same Operator subscription. Not a Grok-only product.

Do I need to use the same email for Claude and Zevari?

Your Claude account and your Zevari workspace are two separate things. Use a consistent login so the OAuth handshake completes cleanly - mismatched emails are the most common setup snag.

Can it post content, and do I approve it first?

Yes. Zevari drafts content in your Voice DNA and posts only after you approve. Approval-gated, always - the same as every other write action.

Is Zevari affiliated with LinkedIn?

No. Zevari is independent and is not affiliated with, endorsed by, or sponsored by LinkedIn Corporation. LinkedIn is a trademark of LinkedIn Corporation.

Run LinkedIn outbound as code

Connect over MCP or the REST API. The endpoint is free to add; Operator hosts campaigns, Voice DNA, and state that keeps running when your agent is not.

Connect to Claude Code

You run Claude Code or Codex. Get the hosted LinkedIn MCP, all 189 MCP tools, and the full safety model, self-serve. Connect over MCP for Claude Code and Codex, or call our REST API from your own code.

Connect to Claude Code

Connect your agent

OpenClaw, ChatGPT, Grok Bot in Cursor, Hermes, or your own code. Same hosted layer over MCP or REST. You connect it. You approve every send.

Connect your agent

Zevari - the LinkedIn execution layer for outbound. Your agent sleeps; your pipeline doesn't.