> ## Documentation Index
> Fetch the complete documentation index at: https://docs.gtm-api.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Execute custom LinkedIn request (escape hatch)

> ESCAPE HATCH: issue one arbitrary LinkedIn HTTP call (url + GET/POST + headers/body) under a chosen OWN account, for endpoints the typed methods do not cover. May be a read or an action (apply to a job, attend an event), so you own the semantics. High-risk: admin-gated + feature-flagged; the url must match the server host allowlist (else 403 forbidden_endpoint). OWN-ACCOUNT ONLY: linkedin_account_sid is REQUIRED, no pool fallback. Non-creditable: 0 credits, but it spends the account's custom_request bucket, which returns 429 when saturated. A non-2xx response is still a successful dispatch (ok=false, status_code carries it; never throws). The response comes back inline, NOT stored; the audit is the linkedin-account-activity-log row (action_type=custom_request). PREFER TYPED METHODS FIRST: searches/lists → linkedin-scraping; one profile/company/post's own data → linkedin-enrichment; sends/invites/reactions/comments → messaging & networking. Never use it to route around a rate limit or a missing permission.

Contract:
- MCP tool `execute_linkedin_custom_request`, registry package `mcp.linkedin/linkedin_custom_requests`, mount `linkedin.platform`.
- Operation `action`, response envelope `action`.
- Flags: dangerous: the MCP layer gates it behind a preview/commit token, and the effect cannot be undone through this API.



## OpenAPI

````yaml /api-reference/linkedin/openapi.yaml post /api/linkedin-custom/execute
openapi: 3.0.3
info:
  title: 'GTM API public contract: gtm.service.linkedin'
  description: >-
    Connected LinkedIn accounts and everything driven through them: account
    health and smart limits, conversations and messages, the connection graph,
    outbound posting, scraping, profile and company enrichment, and the
    antidetect browsers that execute it all.


    GENERATED. This document is projected from the Zod MCP tool registry in
    `product/mcp/gtm.mcp` (one tool per public endpoint, 1:1). Do not edit it by
    hand; edit the tool definition and regenerate with `pnpm openapi:public`.


    Surface: the public `/api` contract of `gtm.service.linkedin`, 150
    operations. Internal (`/internal`) and health endpoints are deliberately
    absent; the code-faithful spec that documents those lives in
    `product/openapi/gtm.openapi.tech`.


    Conventions:

    - Auth is a bearer JWT, optionally narrowed by the `Team-SID` header.

    - Every success body is an MCP envelope: `success: true` plus one typed
    `operation` shape (`search`, `get`, `create`, `update`, `delete`, `metrics`,
    `group_by`, `action`), and a `meta` block with `trace_id` for support.

    - Every failure is the same `McpError` envelope with a code from a fixed
    16-code taxonomy, so a client maps errors once.

    - Lists page with `page_size` (0 to 500, default 50) plus an opaque forward
    `cursor`; `page_size: 0` returns counts only.

    - On `GET` and `DELETE`, object-valued query parameters (`filter`, `sort`)
    travel as JSON text and array-valued ones repeat as `name[]=value`.

    - The MCP-only `_meta` field (usage analytics) never reaches the backend and
    is not part of this contract.
  version: '1.0'
  contact:
    name: GTM API
    url: https://gtm-api.com
    email: support@gtm-api.com
  license:
    name: Proprietary
    url: https://gtm-api.com/license
servers:
  - url: https://app.gtm-api.com/linkedin/v4
    description: Production, through the app.gtm-api.com gateway
  - url: http://localhost:8020
    description: Local Docker (gtm_linkedin_nginx_dev)
security:
  - BearerJwt: []
    TeamSid: []
tags:
  - name: antidetect_browser_logs
    description: >-
      Registry package `mcp.linkedin/antidetect_browser_logs`, served on MCP
      mount `linkedin.browsers`.
  - name: antidetect_browser_proxies
    description: >-
      Registry package `mcp.linkedin/antidetect_browser_proxies`, served on MCP
      mount `linkedin.browsers`.
  - name: antidetect_browsers
    description: >-
      Registry package `mcp.linkedin/antidetect_browsers`, served on MCP mount
      `linkedin.browsers`.
  - name: cloud_browser_sessions
    description: >-
      Registry package `mcp.linkedin/cloud_browser_sessions`, served on MCP
      mount `linkedin.browsers`.
  - name: cloud_browsers
    description: >-
      Registry package `mcp.linkedin/cloud_browsers`, served on MCP mount
      `linkedin.browsers`.
  - name: data_requests
    description: >-
      Registry package `mcp.linkedin/data_requests`, served on MCP mount
      `linkedin.data`.
  - name: linkedin_account_activity_log
    description: >-
      Registry package `mcp.linkedin/linkedin_account_activity_log`, served on
      MCP mount `linkedin.account-monitor`.
  - name: linkedin_account_block_log
    description: >-
      Registry package `mcp.linkedin/linkedin_account_block_log`, served on MCP
      mount `linkedin.account-monitor`.
  - name: linkedin_account_quota_hits
    description: >-
      Registry package `mcp.linkedin/linkedin_account_quota_hits`, served on MCP
      mount `linkedin.account-monitor`.
  - name: linkedin_account_smart_limits
    description: >-
      Registry package `mcp.linkedin/linkedin_account_smart_limits`, served on
      MCP mount `linkedin.accounts`.
  - name: linkedin_account_snapshots
    description: >-
      Registry package `mcp.linkedin/linkedin_account_snapshots`, served on MCP
      mount `linkedin.account-monitor`.
  - name: linkedin_account_sync_runs
    description: >-
      Registry package `mcp.linkedin/linkedin_account_sync_runs`, served on MCP
      mount `linkedin.account-monitor`.
  - name: linkedin_accounts
    description: >-
      Registry package `mcp.linkedin/linkedin_accounts`, served on MCP mount
      `linkedin.accounts`.
  - name: linkedin_auto_scrape_results
    description: >-
      Registry package `mcp.linkedin/linkedin_auto_scrape_results`, served on
      MCP mount `linkedin.auto-scrapes`.
  - name: linkedin_auto_scrape_runs
    description: >-
      Registry package `mcp.linkedin/linkedin_auto_scrape_runs`, served on MCP
      mount `linkedin.auto-scrapes`.
  - name: linkedin_auto_scrapes
    description: >-
      Registry package `mcp.linkedin/linkedin_auto_scrapes`, served on MCP mount
      `linkedin.auto-scrapes`.
  - name: linkedin_benchmarks
    description: >-
      Registry package `mcp.linkedin/linkedin_benchmarks`, served on MCP mount
      `linkedin.account-monitor`.
  - name: linkedin_connection_invitations
    description: >-
      Registry package `mcp.linkedin/linkedin_connection_invitations`, served on
      MCP mount `linkedin.network`.
  - name: linkedin_connection_requests
    description: >-
      Registry package `mcp.linkedin/linkedin_connection_requests`, served on
      MCP mount `linkedin.network`.
  - name: linkedin_connections
    description: >-
      Registry package `mcp.linkedin/linkedin_connections`, served on MCP mount
      `linkedin.network`.
  - name: linkedin_conversations
    description: >-
      Registry package `mcp.linkedin/linkedin_conversations`, served on MCP
      mount `linkedin.messaging`.
  - name: linkedin_custom_requests
    description: >-
      Registry package `mcp.linkedin/linkedin_custom_requests`, served on MCP
      mount `linkedin.platform`.
  - name: linkedin_enrichment
    description: >-
      Registry package `mcp.linkedin/linkedin_enrichment`, served on MCP mount
      `linkedin.enrichment`.
  - name: linkedin_followers
    description: >-
      Registry package `mcp.linkedin/linkedin_followers`, served on MCP mount
      `linkedin.network`.
  - name: linkedin_messages
    description: >-
      Registry package `mcp.linkedin/linkedin_messages`, served on MCP mount
      `linkedin.messaging`.
  - name: linkedin_posting
    description: >-
      Registry package `mcp.linkedin/linkedin_posting`, served on MCP mount
      `linkedin.content`.
  - name: linkedin_scraping
    description: >-
      Registry package `mcp.linkedin/linkedin_scraping`, served on MCP mount
      `linkedin.scraping`.
paths:
  /api/linkedin-custom/execute:
    post:
      tags:
        - linkedin_custom_requests
      summary: Execute custom LinkedIn request (escape hatch)
      description: >-
        ESCAPE HATCH: issue one arbitrary LinkedIn HTTP call (url + GET/POST +
        headers/body) under a chosen OWN account, for endpoints the typed
        methods do not cover. May be a read or an action (apply to a job, attend
        an event), so you own the semantics. High-risk: admin-gated +
        feature-flagged; the url must match the server host allowlist (else 403
        forbidden_endpoint). OWN-ACCOUNT ONLY: linkedin_account_sid is REQUIRED,
        no pool fallback. Non-creditable: 0 credits, but it spends the account's
        custom_request bucket, which returns 429 when saturated. A non-2xx
        response is still a successful dispatch (ok=false, status_code carries
        it; never throws). The response comes back inline, NOT stored; the audit
        is the linkedin-account-activity-log row (action_type=custom_request).
        PREFER TYPED METHODS FIRST: searches/lists → linkedin-scraping; one
        profile/company/post's own data → linkedin-enrichment;
        sends/invites/reactions/comments → messaging & networking. Never use it
        to route around a rate limit or a missing permission.


        Contract:

        - MCP tool `execute_linkedin_custom_request`, registry package
        `mcp.linkedin/linkedin_custom_requests`, mount `linkedin.platform`.

        - Operation `action`, response envelope `action`.

        - Flags: dangerous: the MCP layer gates it behind a preview/commit
        token, and the effect cannot be undone through this API.
      operationId: execute_linkedin_custom_request
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ExecuteLinkedinCustomRequestRequest'
      responses:
        '200':
          description: '`action` success envelope.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ExecuteLinkedinCustomRequestResponse'
        4XX:
          $ref: '#/components/responses/McpClientError'
        5XX:
          $ref: '#/components/responses/McpServerError'
components:
  schemas:
    ExecuteLinkedinCustomRequestRequest:
      type: object
      description: Request body of `execute_linkedin_custom_request`.
      properties:
        linkedin_account_sid:
          type: string
          minLength: 18
          maxLength: 18
          pattern: ^ln_ac_
          description: >-
            REQUIRED executor: the OWN account (ln_ac_…) the call runs on. There
            is NO pool fallback (an arbitrary call must never run under a shared
            infra account).
        url:
          type: string
          minLength: 1
          maxLength: 2048
          description: >-
            Absolute LinkedIn URL (e.g.
            "https://www.linkedin.com/voyager/api/…") or a bare path (resolved
            against https://www.linkedin.com). MUST match the server host + path
            allowlist (provisional: *.linkedin.com + path prefixes
            /voyager/api/, /sales-api/). Otherwise 403 forbidden_endpoint.
        method:
          type: string
          enum:
            - GET
            - POST
          description: >-
            HTTP verb, default GET. Write-shaped verbs (PUT/DELETE/PATCH) are
            out of scope at launch (SAFETY).
        headers:
          type: object
          additionalProperties:
            type: string
          description: Extra request headers merged onto the default voyager headers.
        body:
          anyOf:
            - type: object
              additionalProperties: {}
            - type: string
            - {}
          description: >-
            POST JSON body (object → JSON-encoded) or raw string (passed
            through); ≤ 50 KB serialized; null/omitted for GET.
        form:
          type: boolean
          description: >-
            Modifier: when true, send `body` as
            application/x-www-form-urlencoded (NOT a separate body). POST only.
        include_default_headers:
          type: boolean
          description: >-
            Inject the plugin's default voyager headers (default true); false to
            send only `headers`.
      required:
        - linkedin_account_sid
        - url
    ExecuteLinkedinCustomRequestResponse:
      type: object
      properties:
        success:
          type: boolean
          enum:
            - true
        operation:
          type: string
          enum:
            - action
        action:
          type: string
          description: kebab-case verb; matches the route segment.
        item: {}
        result:
          type: object
          properties:
            status_code:
              type: integer
              description: >-
                The HTTP status the plugin observed: ANY value; the verb never
                throws on non-2xx.
            ok:
              type: boolean
              description: true iff status_code ∈ [200,299].
            headers:
              type: object
              additionalProperties:
                type: string
              description: Response headers the plugin observed.
            body:
              description: >-
                Parsed response body (JSON when parseable, else raw string).
                Returned inline, NOT persisted at rest.
            activity_log:
              type: object
              properties: {}
              description: >-
                Full dispatch row (linkedin-account-activity-log,
                action_type=custom_request) per §4.12a.
          required:
            - status_code
            - ok
            - headers
            - activity_log
        meta:
          type: object
          properties:
            trace_id:
              type: string
              description: UUID v7; same 128-bit value as the X-Trace-Id header.
            span_id:
              type: string
              pattern: ^[0-9a-f]{16}$
              description: 16 hex chars, root span of this request.
            timestamp:
              type: string
              description: ISO 8601 UTC (Y-m-dTH:i:sZ), response time.
            duration_ms:
              type: integer
              minimum: 0
              description: Server-side wall clock.
            debug_url:
              type: string
              description: Deep link to the post-call analysis UI.
          required:
            - trace_id
            - span_id
            - timestamp
            - duration_ms
            - debug_url
        credits:
          type: object
          properties:
            charged:
              type: integer
              minimum: 0
              description: Credits debited for THIS call (0 on own-account / cache hit).
            reason:
              type: string
              nullable: true
              enum:
                - infra_pool
                - limit_fallback
            executed_on:
              type: string
              enum:
                - own_account
                - infra_pool
            balance_after:
              type: integer
              nullable: true
              minimum: 0
              description: >-
                Team balance after the debit; null when the ledger was
                untouched.
          required:
            - charged
            - reason
            - executed_on
            - balance_after
      required:
        - success
        - operation
        - action
        - item
        - result
        - meta
    McpError:
      type: object
      properties:
        success:
          type: boolean
          enum:
            - false
        error:
          type: object
          properties:
            code:
              type: string
              enum:
                - validation_failed
                - nothing_to_update
                - not_found
                - relation_not_found
                - invalid_transition
                - limit_exceeded
                - payment_required
                - duplicate_rejected
                - conflict
                - delete_blocked
                - unauthorized
                - forbidden
                - rate_limited
                - internal_error
                - service_unavailable
                - not_implemented
            message:
              type: string
            recoverable:
              type: boolean
            suggestion:
              type: string
            field_errors:
              type: object
              additionalProperties:
                type: array
                items:
                  anyOf:
                    - type: string
                    - type: object
                      properties:
                        rule:
                          type: string
                        message:
                          type: string
                      required:
                        - rule
                        - message
            blockers:
              type: array
              items:
                type: object
                properties:
                  type:
                    type: string
                    description: >-
                      Machine-readable blocker type (active_flow, pending_tasks,
                      …).
                  severity:
                    type: string
                    enum:
                      - hard
                      - soft
                    description: >-
                      hard = external action required; soft = acknowledge is
                      enough.
                  description:
                    type: string
                  entity_sid:
                    type: string
                    nullable: true
                  count:
                    type: integer
                  resolution:
                    type: string
                    description: 'Hard: tool name to call. Soft: code for acknowledge[].'
                  resolution_hint:
                    type: string
                required:
                  - type
                  - severity
                  - description
                  - entity_sid
                  - resolution
                  - resolution_hint
            context:
              type: object
              additionalProperties: {}
          required:
            - code
            - message
            - recoverable
        meta:
          type: object
          properties:
            trace_id:
              type: string
              description: UUID v7; same 128-bit value as the X-Trace-Id header.
            span_id:
              type: string
              pattern: ^[0-9a-f]{16}$
              description: 16 hex chars, root span of this request.
            timestamp:
              type: string
              description: ISO 8601 UTC (Y-m-dTH:i:sZ), response time.
            duration_ms:
              type: integer
              minimum: 0
              description: Server-side wall clock.
            debug_url:
              type: string
              description: Deep link to the post-call analysis UI.
          required:
            - trace_id
            - span_id
            - timestamp
            - duration_ms
            - debug_url
      required:
        - success
        - error
  responses:
    McpClientError:
      description: >-
        MCP error envelope. `error.code` is one of validation_failed,
        nothing_to_update, not_found, relation_not_found, invalid_transition,
        limit_exceeded, payment_required, duplicate_rejected, conflict,
        delete_blocked, unauthorized, forbidden, rate_limited, not_implemented.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/McpError'
    McpServerError:
      description: >-
        MCP error envelope with `error.code` internal_error or
        service_unavailable.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/McpError'
  securitySchemes:
    BearerJwt:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        Access token issued by gtm.service.id. Its `access_identity` claim
        carries `team_sid`, `actor_sid` and `actor_type`, and that team scope is
        authoritative.
    TeamSid:
      type: apiKey
      in: header
      name: Team-SID
      description: >-
        Team scope for tokens that do not carry one. Ignored when the token
        already names a team.

````