# All limits

Every limit that applies to the Tomba API, in one place. Each row links to the page that defines the limit and its current value.

## Limits

| Limit                                         | Value or where to find it                                                                                     | Defined on                                                              |
| --------------------------------------------- | ------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------- |
| Request body size                             | 4 MB. Larger bodies fail with `413`.                                                                          | This page                                                               |
| Request duration                              | 180 seconds. Longer requests end with `504` from the gateway.                                                 | This page                                                               |
| Requests per second, minute, and day          | Per plan and per endpoint. `GET /v1/rate-limits` returns the values for your account.                         | [Limits by plan](/rate-limits#limits-by-plan)                           |
| Endpoints with a fixed rate limit             | Company search, API keys, and flags have the same limit on every plan.                                        | [Endpoints with fixed limits](/rate-limits#endpoints-with-fixed-limits) |
| Credit allowances                             | Search, verification, email count, and sources credits per usage window, by plan. `GET /v1/me` returns yours. | [Quotas](/usage-and-quotas#quotas)                                      |
| Credits per request                           | Per endpoint                                                                                                  | [Credit costs](/usage-and-quotas#credit-costs)                          |
| Free repeat requests                          | Same request within the usage window                                                                          | [Duplicate requests](/usage-and-quotas#duplicate-requests)              |
| Free plan results                             | Domain search result count and pages; company search pages                                                    | [Free plan limits](/usage-and-quotas#free-plan-limits)                  |
| Workspace member credits                      | Optional per-member search and verification limits set by the owner                                           | [Quotas](/usage-and-quotas#quotas)                                      |
| Workspace members                             | `pricing.available_teams` in [`GET /v1/me`](/api/account#get-account)                                         | [API reference](/api/account#get-account)                               |
| Rows per bulk job                             | Per bulk type                                                                                                 | [Bulk types](/bulks#bulk-types)                                         |
| Bulk jobs created, running at once, downloads | Per bulk type and per job                                                                                     | [Bulk limits](/bulks#limits)                                            |
| Page size of paginated endpoints              | Per endpoint                                                                                                  | [Pagination](/going-to-production#pagination)                           |
| Active API keys                               | `pricing.available_keys` in [`GET /v1/me`](/api/account#get-account)                                          | [Authentication](/authentication#rotate-keys)                           |
| API key lifetime                              | Set per key, up to a maximum                                                                                  | [Key expiry](/authentication#key-expiry)                                |
| OAuth token lifetime                          | Access and refresh tokens                                                                                     | [OAuth 2.0](/authentication#oauth-20)                                   |
| Leads and lead lists                          | `pricing.available_leads` and `pricing.available_list` in [`GET /v1/me`](/api/account#get-account)            | [API reference](/api/account#get-account)                               |
| Lead attributes                               | Per account                                                                                                   | [Create a lead attribute](/api/lead-attributes#create-a-lead-attribute) |
| Webhook callback timeout and retries          | Per delivery attempt                                                                                          | [Delivery](/webhook#delivery)                                           |
| Remote MCP server                             | Plan rate limits and credits, plus the server's own retries                                                   | [Limits and billing](/llm/remote-mcp/introduction#limits-and-billing)   |
| Pay per request (agents.tomba.io)             | Shared across all agents                                                                                      | [Rate limits](/mpp/introduction#rate-limits)                            |

A request over a rate limit or a daily bulk limit fails with `429`. A request over a credit balance fails with `402`, or with `429` for the email count and sources balances. A request over an account cap on keys, leads, lead lists, or lead attributes fails with `422`. See [Errors](/error-handling#status-codes).
