How to connect a client's LinkedIn account without their password
Agencies shouldn't hold client passwords. Send a hosted login link instead: the owner logs in from their own country, and each account keeps its own proxy.
If you run LinkedIn outreach for clients, you’ve probably been sent a password in a chat message at some point. Maybe a spreadsheet of them. It feels like the quickest way to get started, and it causes three problems.
- Security. You now hold a credential that gives full access to someone’s professional identity, and you’re responsible for it.
- Location. When you log in from your office, LinkedIn sees the account appear somewhere new, often in another country. That’s exactly the kind of change that triggers security checks.
- Trust. Some clients, rightly, won’t share a password at all. Onboarding stalls while everyone argues about it.
There’s a better way to do this, and it doesn’t involve a password changing hands.
The short version
- You create the sender and generate a hosted login link.
- You send the link to the account owner.
- The owner opens it, logs in to LinkedIn themselves, and enters any verification code LinkedIn asks for.
- The account connects, with a proxy in the owner’s own country.
You never see the password. Neither do we.
Step by step
In GrowthxAI Outreach, the flow looks like this. The full article is in the docs.
- Go to Senders → Connect sender and choose LinkedIn.
- Tick the box confirming you have the account owner’s consent. This isn’t a formality; connecting someone’s account without their permission is against our acceptable use policy.
- Enter the details, and set Owner email to the account owner’s own address, not yours.
- On the last step, click Copy link to send to the sender owner.
- Send the link to the owner. They open it, log in to LinkedIn and enter any verification code.
The sender shows Connecting until they finish, then Connected.
One practical detail: the link expires after 15 minutes. Agree a time with the owner first, or send it when you know they’re at their desk. Links sent at 18:00 and opened the next morning just need sending again.
Why the owner must open the link, not you
This is the part people are most tempted to skip, so it’s worth explaining.
Every LinkedIn account in the product sends through its own proxy: an IP address in one country, so LinkedIn sees the account connect from a consistent place, the way a real person’s account does. There’s one proxy per sender; accounts don’t share one.
The proxy country is set by whoever opens the hosted login link. If your client is in Germany and you open their link from India, their account would appear to be working from India from then on. To LinkedIn, that looks like someone else has taken over the account, which is roughly what happened.
When the owner opens the link, the proxy lands in their own country, matching where they normally use LinkedIn. It can be changed later from the sender’s page, but it’s best to get it right from the start: changing it often, or to a country that doesn’t match the account, can hurt the account’s health.
The same logic applies to working hours. Set each sender’s schedule in the owner’s real time zone, so activity happens during their working day, not yours. If the time zone and proxy country don’t match, the sender’s Schedule tab shows a warning.
When the session ends later
LinkedIn ends sessions from time to time. When it does, the sender shows Re-login needed, and its queued actions wait rather than failing. Leads that failed only because of the disconnect are retried once the account reconnects.
To reconnect, click Send re-login link on the sender’s Overview tab. You can copy the new link and pass it to the owner, and it goes through the same hosted page: the owner logs in, you never see the password.
If you’d rather not ask clients to log in again, the owner can install our optional Chrome extension, which keeps the session refreshed on its own.
What the client keeps control of
A client handing you their LinkedIn account should be able to take it back without asking you. They can:
- End the session at any time by logging out of LinkedIn.
- Ask you to disconnect it. A Manager in your workspace can disable the sender with Purge stored secrets ticked, which removes all stored session data for that account.
It’s also worth telling clients what the product won’t do with their account. Every sender runs inside daily and weekly limits and a warm-up period that nobody in your workspace can raise above the platform ceiling. A new account starts slowly and earns more as it stays healthy. If a client asks “how many invites will you send from my account?”, you can give a real answer; the numbers are on our safety page.
A checklist for onboarding a client’s account
- Agree a 15-minute window with the owner.
- Confirm you have their consent, and tick the box.
- Put their email in the Owner email field.
- Send them the link. Don’t open it yourself.
- Set working hours in their time zone.
- Offer the Chrome extension if they’d rather not log in again later.
- Tell them how to end the session if they ever want to.
Where this fits in an agency setup
Connecting accounts is the first step of client work, not the last. Once a client’s sender is connected, you can group it with the client’s other senders, keep that client’s blacklists and reports separate from every other client, and give the client a portal login that shows only their own conversations and results.
If you run outreach for several clients, see how that works on the agencies page. If you want the client portal on your own brand and domain, see white-label.