Tomba
The Tomba API finds, verifies, and enriches professional email addresses, phone numbers, and company data over REST.
Getting started
Send every request with your API key and secret in the X-Tomba-Key and X-Tomba-Secret headers. Create both in the dashboard; see Authentication.
Code
Base URL and versioning
All endpoints are served from https://api.tomba.io/v1. Backward-compatible changes ship without a new version path.
Rate limits and credits
Limits are enforced per plan and per endpoint. Rate-limited endpoints return rate-limit headers on every response, and a request over a limit returns 429 Too Many Requests with a Retry-After header. See Rate limits for the limits and headers, and Credits and usage for what each endpoint costs.
Errors
Missing, malformed, or expired credentials return 400 with an errors.type of authentication_failed or api_key_expired; credentials that don't match an account return 401. Branch on errors.type, not on the status code alone. See Errors.
Timeouts
Set a client timeout of at least 180 seconds. Searches and verifications run in real time against remote mail servers and websites, so response times vary. For large volumes, use bulk jobs.
MCP server
AI assistants can use the same data through the MCP server at https://mcp.tomba.io/mcp. See Remote MCP server.
base64(api_key:secret) as the bearer token; the REST API at api.tomba.io doesn't.X-Tomba-Key header. Get your API credentials at app.tomba.io/api.X-Tomba-Secret header. Get your API credentials at app.tomba.io/api.