Safe LinkedIn automation: how LiHelper keeps your account safe

What runs on our servers, what runs in your own browser, what never leaves it — and what LiHelper refuses to do, in plain words.

Safe LinkedIn automation means a tool that never holds your login, never acts as you from a server, and never does more in a day than a person would. LiHelper is built on those three rules: posts publish through LinkedIn's official share API after you connect with OAuth, everything that needs your logged-in session runs inside your own Chrome tab through the free LiHelper Connector extension, and the server caps every action per day. This page explains each of those choices so you can judge the risk for yourself rather than take our word for it.

The short answer

Writing, scheduling and publishing posts with LiHelper is as safe as posting by hand, because the post goes to LinkedIn the same way LinkedIn's own partners send it: through the official API with a token LinkedIn issued to you. The engagement autopilot and Easy Apply assist on the Pro plan are a different category. They act inside your own browser session, and LinkedIn's User Agreement can treat that as automation, so they carry real risk. LiHelper limits that risk with daily caps, a circuit breaker and a strict "nothing happens unless you click" rule, but it cannot remove it. Our FAQ and Terms say the same thing.

What runs where

Every feature falls into one of three places: LiHelper's servers, LinkedIn's official API, or your own browser. The table shows which, and exactly what leaves your browser in each case.

Where each LiHelper feature runs and what data leaves your browser
FeatureWhere it runsWhat leaves your browser
Writing and designing postsLiHelper servers (AI via OpenRouter)Your own posts, profile and CV, quoted in your own words, to ground your drafts; never anyone else’s; and, when you allow it, your results — never your text — in what LiHelper learns across members (Settings → Privacy turns this off)
Publishing to your profileLinkedIn's official share API (OAuth)Nothing beyond the post itself; the OAuth token is encrypted at rest
Analytics syncYour own Chrome tab, via the LiHelper ConnectorImpressions, engagements, followers, profile views and per-post stats — numbers only
Likes and comments (Pro)Your own Chrome tab, only when you clickPost text you chose to comment on, and whether the action completed
Easy Apply assist (Pro)Your own Chrome tab, stops at the review stepWhich fields were filled; never a guessed answer
Your LinkedIn password or session cookieStays in your browserNothing — LiHelper never asks for or reads it

No password, no cookie: how you connect

You connect LinkedIn with LinkedIn OAuth: LinkedIn's own login page opens, you approve the scopes, and LinkedIn hands LiHelper an access token for your account. That token is encrypted at rest with Fernet before it is stored, and it is the only LinkedIn credential LiHelper holds. It can publish posts and read the basic profile you approved; it cannot log in as you, read your inbox or change your password. Disconnecting LinkedIn from Settings deletes it.

The alternative many tools use is a session cookie. You paste the cookie from your browser, a server stores it and then browses LinkedIn as you, from a data-centre IP, at any hour. That is the pattern LinkedIn's detection is built to catch, and it is also a plain security problem: whoever holds that cookie holds your account. LiHelper has no field to paste a cookie into, and the extension has no code path that reads one. Your own account password is hashed with Argon2, so even we cannot read it.

Publishing through LinkedIn's official API

Every post LiHelper publishes, whether you approved a draft on Creator or let auto-publishing send it on Pro, goes out through LinkedIn's Share API. That is the same route LinkedIn offers to scheduling tools generally: a documented endpoint, authenticated by your OAuth token, that creates a post on your profile with the text and image you chose. No browser is driven, no button is clicked for you, and the timing is a normal API call at your scheduled slot. If you never switch on the Pro engagement or job features, the official API is the only way LiHelper ever writes to LinkedIn on your behalf. See how LiHelper works for the full flow from profile sync to a scheduled post.

What the extension does in your browser

LinkedIn's API does not expose your analytics to third parties, so the numbers on your dashboard come from the LiHelper Connector, a Chrome extension that runs in your own logged-in tab. When you click "Sync everything" it opens your analytics, activity, profile and skills pages, reads impressions, engagements, followers, profile views, per-post stats and your headline and skills, and sends only those values to your account. It requests the storage permission plus access to linkedin.com and the LiHelper API — no tabs permission, no access to other sites, no remote code, and no background activity. The extension page explains every permission in the same words as the Chrome Web Store listing.

On Pro, the same extension can run likes you approved in LiHelper and pre-fill Easy Apply forms. Comments are drafted by the AI for you to read, edit and post yourself; a comment runs unattended only if you explicitly approved that exact action in LiHelper first. Easy Apply stops at the review step and never guesses a screening question; auto-submit, if you turn it on, still only submits when nothing had to be guessed.

Daily caps and the circuit breaker

The limits live on the server, so a modified extension or a second browser cannot exceed them. As of September 2026 the caps are 40 likes and 10 comments per account per day, and an action only counts once the extension confirms it happened on the page — a failed click is not silently retried. Posts too short to comment on meaningfully are skipped before any action is queued, so the AI is never asked to reply to a one-liner.

There is also a ban-risk circuit breaker. If the extension detects a LinkedIn block, checkpoint or challenge signal twice within 24 hours, the server refuses to hand out any further engagement command for that account and tells you to rest it. The pause lifts on its own once the signals age out. You can also pause engagement autopilot yourself at any time from Settings, and it is off by default on every plan.

What LiHelper refuses to do

Some things are missing on purpose. If a competitor offers them and LiHelper does not, this is why.

  • No engagement pods. LiHelper never enrols you in a group that likes and comments on each other's posts. Pods inflate numbers, get flagged and teach the algorithm nothing about your real audience.

  • No mass connection or messaging bots. There is no "send 200 connection requests" button and no auto-DM. LiHelper is a posting and analytics tool, not an outreach tool — if you need outreach automation, this is the wrong product.

  • No scraping of other people. The extension reads your own analytics, your own profile and the text of a post you personally chose to engage with. It does not harvest profiles, emails or connection lists, and the Terms forbid using it to do so.

  • No cookie-based login. Some tools ask you to paste a session cookie so a server can act as you. LiHelper never does; a server acting on your cookie from a foreign IP is exactly the pattern that triggers LinkedIn restrictions.

  • No background activity. The extension has no timer and no tabs permission. Nothing runs when you close the popup, and auto-publishing on Pro goes through the official API, not your browser.

  • No selling or training on your data. Your data is scoped to your account, is not used for advertising profiles and is not used to train our own models. The AI models see your text as context for a draft and nothing more.

Your data, in plain words

LiHelper stores your account details, the posts and drafts you create, the analytics numbers the extension synced, and your encrypted LinkedIn OAuth token. To generate a draft, the relevant text — your headline, skills and the posts of yours that performed best — is sent to the AI provider through OpenRouter (models currently include DeepSeek, OpenAI and Google models) and processed under that provider's terms; no model is trained on it. Payments are handled by Paddle, our Merchant of Record, so we never see your full card number. You can delete drafts and posts in the app, disconnect LinkedIn to remove the token, and email support@lihelper.com to close the account entirely. The Privacy Policy lists every provider and your rights under GDPR and similar laws.

The honest risk

LiHelper is an independent product and is not affiliated with, endorsed by, or sponsored by LinkedIn. We do not claim LinkedIn permits any particular automation, and we do not promise you will never be restricted. What we can say is where each feature runs, what it can and cannot do, and that the defaults are conservative: nothing publishes on your behalf until you switch on auto-publishing, and nothing acts in your session until you click. Compare what each plan enables on the pricing page, and start with posting only if you want zero in-session automation.

Read the full guide: Is LinkedIn automation safe? What gets accounts restricted, and what does not — what LinkedIn's rules actually cover, why cookie-replay bots get caught, and a checklist for judging any tool.

Security FAQ

Is LiHelper a safe LinkedIn automation tool?

Writing and scheduling posts is the low-risk part: posts publish through LinkedIn's official share API after you connect with LinkedIn OAuth, and no password or cookie is ever stored. Engagement and Easy Apply act inside your own browser session through the LiHelper Connector extension, only when you click, within daily caps. Those in-session features can still be inconsistent with LinkedIn's User Agreement, so use them conservatively.

What are the daily caps on likes and comments?

The server, not the extension, owns the limits. As of September 2026 the caps are 40 likes and 10 comments per day per account, counted only when the extension confirms the action actually happened on the page. If LinkedIn shows a block or challenge signal twice within 24 hours, a circuit breaker pauses all engagement for that account until the signals age out.

Does LinkedIn detect auto-likes and auto-comments?

It can, and its detection is built around the patterns cloud bots leave: a login replayed from a data-centre IP, a headless browser, and activity at inhuman volume or hours. LiHelper does none of that. Likes and comments you approved run in your own Chrome tab, on your own IP, only when you click, within 40 likes and 10 comments a day, and a circuit breaker pauses everything after two block signals in 24 hours. That lowers the risk; it does not remove it, because LinkedIn decides what counts as automation.

Does LiHelper use engagement pods or connection bots?

No. LiHelper does not run or join engagement pods, does not send connection requests or messages in bulk, and does not scrape other people's profiles. The extension reads your own analytics and profile pages, drafts comments for you to review, and acts only on the posts you approved. Growth comes from your own posting rhythm, not from artificial reciprocity.

Can LinkedIn still restrict my account?

Yes, and we say so plainly. LinkedIn decides what it considers automation, and any tool that acts in your session carries some risk. LiHelper reduces it by running in your own browser on your own IP, by capping every action per day, and by pausing on the first block signals, but you remain responsible for how you use it. If you only write, schedule and publish through the official API, your exposure is the same as posting by hand.

Ready to try it without handing over a password? Create your account and start the 14-day Creator trial — no card needed. Questions about a specific feature? Ask us on the contact page.