Skip to content

Windows curl-impersonate workaround still results in session redirect / expired cookies #5

Description

@topshot99

Hi, I’m trying to use linkedincli on Windows as a local MCP/CLI connector for read-only LinkedIn access first. I followed the README guidance around manual cookies and the curl-impersonate workaround, but I’m still unable to validate the session.

Goal

Use linkedincli locally on Windows to authenticate via LinkedIn browser cookies and run read-only commands like:

linkedin status --verify
linkedin companies view peacock-labs --pretty

No posting/write commands were attempted.

Environment

• OS: Windows
• Node/npm: using  npx.cmd 
• Package:  @bcharleson/linkedincli 
• Auth method: manual  li_at  +  JSESSIONID 
• Cookies tested from:
• Microsoft Edge
• Google Chrome
• curl-impersonate: Windows release from  lexiforest/curl-impersonate 

What I tried

1. Installed and ran npm package

npx.cmd -y @bcharleson/linkedincli login
npx.cmd -y @bcharleson/linkedincli status --verify

During login I saw:

{"message":"Cookies saved but validation failed — they may still work","warning":"fetch failed","config":"~/.linkedin-cli/config.json","validated":false}

Then:

{"logged_in":true,"profile":"Unknown","session_valid":"unknown","message":"Could not verify session: fetch failed"}

2. Checked local config shape

The saved cookies look structurally correct:

•  li_at  exists and starts with  AQED 
•  JSESSIONID  exists and starts with  ajax: 

I did not expose/store the actual cookie values.

3. Tried documented curl-impersonate workaround

I downloaded Windows  curl-impersonate  and verified  curl_chrome123.bat  runs:

curl_chrome123.bat --version

That works.

Then I set:

$env:LINKEDIN_HTTP="curl-impersonate"
$env:LINKEDIN_CURL_IMPERSONATE_BIN="path\to\curl_chrome123.bat"
npx.cmd -y @bcharleson/linkedincli status --verify

But the npm package still returned:

{"logged_in":true,"profile":"Unknown","session_valid":"unknown","message":"Could not verify session: fetch failed"}

4. Noticed npm package may not include transport workaround

I inspected the installed npm package and couldn’t find references to:

•  LINKEDIN_HTTP 
•  curl-impersonate 
•  LINKEDIN_CURL_IMPERSONATE_BIN 

The built  dist/index.js  appeared to call Node  fetch  directly.

However, the GitHub  main  branch does include  src/core/transport.ts  with the curl-impersonate logic.

Is the npm package behind the GitHub README/main branch?

5. Built GitHub main locally

I cloned and built the repo from GitHub main:

git clone https://github.com/bcharleson/linkedincli.git
npm install
npm run build

Then ran:

$env:LINKEDIN_HTTP="curl-impersonate"
$env:LINKEDIN_CURL_IMPERSONATE_BIN="path\to\curl_chrome123.bat"
node dist/index.js status --verify

This returned:

{"logged_in":true,"source":"config","profile":"Unknown","session_valid":"unknown","message":"Could not verify session: spawn EINVAL"}

6. Tried Windows shim around curl-impersonate.exe

Since spawning the  .bat  failed, I created a small local Windows  .exe  shim that calls:

curl-impersonate.exe --impersonate chrome123 <forwarded args>

The shim works with:

shim.exe --version

Then I set:

$env:LINKEDIN_HTTP="curl-impersonate"
$env:LINKEDIN_CURL_IMPERSONATE_BIN="path\to\shim.exe"
$env:LINKEDIN_CURL_IMPERSONATE_REAL_BIN="path\to\curl-impersonate.exe"
node dist/index.js status --verify

This changed the error to:

{"logged_in":true,"source":"config","profile":"Unknown","session_valid":false,"message":"Session cookies expired. Run: linkedin login"}

And:

node dist/index.js companies view peacock-labs --pretty

returns:

Error: Session redirected by LinkedIn. Run: linkedin login

I then refreshed cookies from Chrome and repeated login, but got the same result.

Questions

1. Is the npm package currently missing the  LINKEDIN_HTTP=curl-impersonate  transport support that exists on GitHub main?
2. Is Windows expected to work with  LINKEDIN_CURL_IMPERSONATE_BIN  pointing to a  .bat  file, or does it require an  .exe ?
3. Is there a recommended Windows setup for  curl-impersonate  with this CLI?
4. Is manual  li_at  +  JSESSIONID  expected to work on Windows, or is full Chrome cookie import required?
5. Since  --from-chrome  is documented as unsupported on Windows due to Chrome App-Bound Encryption, is Windows currently considered unsupported for reliable LinkedIn session validation?

Thanks — happy to provide more command output, but I’m avoiding sharing actual cookie values.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions