# Glossary

Short definitions of the terms used in these docs. Each links to the page that describes the behavior in full.

## Billing

### Search credits

The balance used by the finders, enrichment, phone lookups, company search, and similar domains. See [Quotas](/usage-and-quotas#quotas).

### Verification credits

The balance used by the email verifier. See [Quotas](/usage-and-quotas#quotas).

### Email count credits

The balance used by email count, email format, and location. When it runs out, those endpoints return `429` instead of `402`. See [Quotas](/usage-and-quotas#quotas).

### Sources credits

The balance used by email sources. When it runs out, the endpoint returns `429` instead of `402`. See [Quotas](/usage-and-quotas#quotas).

### Usage window

The period after which your plan's credit allowances reset. Unused plan credits don't carry over to the next window. See [Quotas](/usage-and-quotas#quotas).

### Duplicate request

A request with the same user, endpoint, and parameters as an earlier one in the same usage window. It returns the data without charging credits again. See [Duplicate requests](/usage-and-quotas#duplicate-requests).

### Plan

Your subscription. It sets your credit allowances, your [rate limits](/rate-limits#limits-by-plan), and account caps such as the number of API keys and leads. See [Quotas](/usage-and-quotas#quotas).

## Accounts and access

### Workspace

A team of Tomba users under one owner. Members use the owner's credits and rate limits and share bulk jobs, and the owner can set a credit limit for each member. See [Quotas](/usage-and-quotas#quotas).

### API key

A credential that starts with `ta_`, sent in the `X-Tomba-Key` header. An account can hold several keys, each with its own name and expiry date. See [Authentication](/authentication#request-headers).

### Secret

Your account's secret, which starts with `ts_` and is sent in the `X-Tomba-Secret` header. An account has one secret, shared by all of its keys. See [Authentication](/authentication#request-headers).

### OAuth scope

A permission granted to an OAuth 2.0 access token, such as `search` or `verify`. A token without the scope an endpoint needs gets `403 insufficient_scope`. See [OAuth 2.0](/authentication#oauth-20).

### Request ID

The value of the `X-Request-ID` response header, which identifies one API request. Quote it when you contact support. See [Request IDs](/going-to-production#request-ids).

## Data and results

### Verification status

The detailed outcome of an email verification, returned in `status`. See [Status values](/attributes/verifier#status-values).

### Verification result

The deliverability verdict of an email verification, returned in `result`. See [Result values](/attributes/verifier#result-values).

### Accept-all

A domain whose mail server accepts mail for any address, also called catch-all, so Tomba can't confirm that a specific mailbox exists. See [Status values](/attributes/verifier#status-values).

### Disposable

A domain that belongs to a disposable email provider. Domain search returns no addresses for it, the email finder rejects it, and a verification that returns this status isn't charged. See [Status values](/attributes/verifier#status-values).

### Webmail

A domain that belongs to a webmail provider, such as Gmail or Outlook. Domain search returns no addresses for it and the email finder rejects it; the email verifier reports it in the `webmail` field. See [What Tomba excludes](/data#what-tomba-excludes).

### Score

A confidence value on a result. A person result's `score` is based on the address's verification status and the number of public sources that list it; the email verifier's `score` is higher when delivery is more likely. See [Checks and scores](/data#checks-and-scores).

### Claim

A request from a person to remove their email address, phone number, or LinkedIn profile from Tomba. Requests that name claimed data return `451`. See [Data removal](/data#data-removal).

## Features

### Bulk job

One Tomba operation run over a list of inputs. You create and launch it, poll its progress, and download the results as CSV. See [Bulk operations](/bulks).

### Webhook callback

A `POST` of a request's result to the `webhook_url` you add to a supported request. Callbacks aren't signed. See [Per-request callbacks](/webhook#per-request-callbacks).

### Lead webhook

A URL, set in the dashboard, that Tomba calls each time a lead is created in your account. See [Lead events](/webhook#lead-events).

### Flag

A report of incorrect data, sent with `POST /v1/flag`. When Tomba confirms a report that an email address hard-bounced, it returns a search credit. See [Refunds for incorrect data](/usage-and-quotas#refunds-for-incorrect-data).

### MCP server

A Model Context Protocol server that lets AI assistants call Tomba as tools. Tomba hosts a [remote server](/llm/remote-mcp/introduction) and publishes a [local server](/llm/local-mcp/introduction) that runs on your machine.

### Pay per request (MPP)

Access to Tomba endpoints at `agents.tomba.io` without a Tomba account or API key. The caller pays for each request through InFlow with the Machine Payments Protocol. See [Tomba for AI agents](/mpp/introduction).
