For once, a piece of European regulation that I can only applaud.
LinkedIn has no public API for members. The Sales Navigator API is closed to new partners, and the other APIs cover ads, company pages and "Sign in with LinkedIn". For years, the only official way to get your own data out was the "Download your data" zip: request it, wait up to 3 days for the email, unzip, repeat next month.
The EU's Digital Markets Act (DMA) changed that. It forces the largest platforms, the "gatekeepers", to let users take their data out continuously and in real time, not only as a one-off download. LinkedIn complies with the Member Data Portability API: an official, free, read-only API that returns your own LinkedIn data as JSON, whenever you ask.
It works only for members located in the EU/EEA or Switzerland, based on the location on your LinkedIn profile. Everyone else gets an error. For once, being in Europe is the advantage.

Why it exists: the Digital Markets Act
- The European Commission designated Microsoft as a gatekeeper on 6th September 2023, with LinkedIn as one of its core platform services.
- Gatekeepers had 6 months to comply, so the obligations apply since March 2024.
- Article 6(9) of the DMA requires gatekeepers to give end users effective portability of their data, free of charge, including continuous and real-time access. A download button once a month doesn't meet that bar, hence an API.
- LinkedIn runs 2 variants: one for members (you fetch your own data with your own app) and one for third parties (an app fetches a member's data with that member's consent).
I wrote about the DMA when it was announced (!random/eu-dma). 4 years later, this API is the first tangible result I use every day.

What the API gives you
2 endpoints carry the data:
| Endpoint | What it returns |
|---|---|
| Member Snapshot API | Your full history, per data domain, as of the moment you call it |
| Member Changelog API | Every action since you consented (messages, comments, reactions...), kept 28 days |
The snapshot covers about 60 domains. The ones that matter most:
| Domain | Content |
|---|---|
INBOX |
Every message sent and received, full history |
CONNECTIONS |
Name, position, company and date of each 1st-degree connection |
INVITATIONS |
Invitations sent and received, with the note (last 6 months) |
ALL_COMMENTS, ALL_LIKES |
Your comments and reactions |
MEMBER_SHARE_INFO |
Your posts and reposts |
PREMIUM_NOTES |
Your private notes on connections |
SEARCHES |
Your recent searches |
PROFILE, POSITIONS, SKILLS |
Your own profile, section by section |
Plus learning history, endorsements, recommendations, groups, follows, saved jobs, ad targeting and more.
What it does not give you:
- Other people's profiles.
CONNECTIONSgives a name, a title and a company, nothing more. - Any write access. You can't send a message or an invitation.
For business people
What it changes: your LinkedIn activity becomes data you own, live, not a monthly zip.
- Your inbox in your own tools. Every DM, back to the first one (mine go back to 2007), searchable next to your CRM and email.
- No more lost replies. The changelog shows a reply within hours. Combined with a list of who accepted your invitation, you see who wrote and never got an answer.
- Follow-up you can measure. Who accepted, who you messaged, who replied, per campaign or event.
- No account risk. Scraping tools and browser extensions break LinkedIn's User Agreement and get accounts restricted. This is LinkedIn's own API, used with your own consent.
Cost: free. Effort: 10 minutes of setup, then 1 click a year to renew the token.
The main limitation: it is your data only. Prospecting data on people you don't know still comes from enrichment providers.
For technical people
Setup
- Create an app on LinkedIn Developers. Use the company page "Member Data Portability (Member) Default Company". Creating your own page blocks the access request.
- On the app's Products tab, request Member Data Portability API (Member). Access is granted immediately after you accept the terms.
- Get a token with the scope
r_dma_portability_self_serve: either with the OAuth Token Tools in the developer portal, or with a standard 3-legged OAuth flow and a redirect URL such ashttp://localhost:8799/callback. - Call
POST /rest/memberAuthorizationswith{}to start the changelog archiving (the consent usually does it already).
Calls
Every request needs the header Linkedin-Version: 202312. It's the only version these endpoints accept; any other returns 426 NONEXISTENT_VERSION.
# full history of one domain, page by page (start=0, 1, 2...)
curl -s "https://api.linkedin.com/rest/memberSnapshotData?q=criteria&domain=INBOX&start=0" \
-H "Authorization: Bearer $TOKEN" -H "Linkedin-Version: 202312"
# new activity since a timestamp (epoch ms), max 50 per call, 28 days back at most
curl -s "https://api.linkedin.com/rest/memberChangeLogs?q=memberAndApplication&startTime=1790929912000&count=50" \
-H "Authorization: Bearer $TOKEN" -H "Linkedin-Version: 202312"
# is archiving on, and since when
curl -s "https://api.linkedin.com/rest/memberAuthorizations?q=memberAndApplication" \
-H "Authorization: Bearer $TOKEN" -H "Linkedin-Version: 202312"
Learnings from my setup (October 2026)
- The snapshot is built after you consent, not before. Every domain answered
404 No data foundat first.PROFILEandCONNECTIONSwere ready after 21 minutes,INBOXafter about 1 hour. Comments, likes and posts took longer than a day. - The fields match the CSV export.
CONNECTIONSreturns "First Name", "Connected On", "URL";INBOXreturns "CONVERSATION ID", "FROM", "CONTENT". A parser written for the "Download your data" zip works on the API unchanged, and rows dedupe across both sources. - Paging ends with an error. Loop on
startuntil the API answers "No data found"; thetotalfield is not reliable. - The changelog is thin. A message event carries the thread ID and person URNs, not names. Resolve the name from the conversation you already hold.
startTimeis inclusive. The last event comes back on every call; dedupe on the eventid.- Some listed domains don't work.
EVENTSis in the documentation but returns400 not supported.ARTICLEScomes back as broken HTML lines. - The token lasted 1 year (
expires_inin the token response), although the app page shows 2 months. There is no refresh token: plan a yearly re-consent. - The conversation ID opens the thread.
https://www.linkedin.com/messaging/thread/{CONVERSATION ID}/goes straight to the conversation in your inbox.
How I use it
A small Python script pulls the changelog every 4 hours and a full snapshot once a week, into the SQLite database that already holds my LinkedIn export. A dashboard on top lists everyone who accepted my invitation and never got a message, with a draft ready per person, and ticks each row when the API sees my message or their reply. See also Linkedin for other LinkedIn resources.
Further Reading
- Member Data Portability (Member): setup and token
- Member Snapshot API: endpoint and paging
- Member Snapshot Domains: the full domain list
- Member Changelog API: events, 28-day window
- DMA designated gatekeepers: European Commission