Local MCP server
@tomba-io/tomba-mcp-server is an MCP server that runs on your machine and calls the Tomba API with your key and secret. It provides the same 28 tools as the remote server. The remote MCP server needs no installation and also supports OAuth; Local server differences lists how the two servers behave differently.
Requirements
- Node.js 18.20 or later. Earlier versions stop at startup with
SyntaxError: Unexpected token 'with'. - A Tomba API key and secret. See Get your key and secret.
Run the server
Your MCP client usually starts the server for you, as shown in Configure a client. To check that the package installs and runs, print its version:
Code
The server reads your credentials from two environment variables, and exits with Error: TOMBA_API_KEY and TOMBA_SECRET_KEY environment variables are required if either is missing:
| Variable | Value |
|---|---|
TOMBA_API_KEY | Your API key, ta_… |
TOMBA_SECRET_KEY | Your secret, ts_… |
It accepts these options:
| Option | Default | Description |
|---|---|---|
--transport, -t | stdio | stdio to talk to the client that started it, or http to serve Streamable HTTP. See HTTP transport. |
--port, -p | 3000 | Port for the HTTP transport |
--version, -v | Print the version and exit | |
--help, -h | Print the options and exit |
Configure a client
In each example, replace ta_xxxx and ts_xxxx with your key and secret. Keep configuration files that contain your secret out of version control.
Claude Desktop
In Claude Desktop, open Settings → Developer and select Edit Config. The file is at ~/Library/Application Support/Claude/claude_desktop_config.json on macOS and %APPDATA%\Claude\claude_desktop_config.json on Windows. Add the server, then quit and restart Claude Desktop:
Code
The same mcpServers entry works in the configuration files of Cursor, Windsurf, Gemini CLI, and Cline; Connect a client says where each client keeps its file.
Claude Code
Code
VS Code
Add the server to .vscode/mcp.json, or to the file that MCP: Open User Configuration opens. VS Code asks for the key and secret on first use and stores them securely:
Code
Zed
Run zed: open settings file and add the server under context_servers:
Code
Verify the connection
- The client lists 28 Tomba tools.
- Ask the assistant to run the
list_flagstool. A list of flags, even an empty one, means your credentials work.
When the server starts over stdio, it writes Tomba MCP server running on stdio to its error output. Claude Desktop saves that output in mcp-server-tomba.log, in ~/Library/Logs/Claude on macOS and %APPDATA%\Claude\logs on Windows.
HTTP transport
With --transport http, the server listens on the given port and serves Streamable HTTP at /mcp, with a health check at /health:
Code
Clients connect to http://localhost:3000/mcp. The server handles one MCP session per process: a second client, or a client that reconnects, gets HTTP 500 until you restart the server.
In HTTP mode, the server doesn't authenticate clients, listens on every network interface, and accepts requests from any web page origin. Anyone who can reach the port can use your Tomba credits. Run it only where the port is closed to other machines, or use stdio.
Troubleshooting
| Symptom | What to do |
|---|---|
SyntaxError: Unexpected token 'with' at startup | Upgrade Node.js to 18.20 or later. The client runs the node found on its own PATH, which can differ from your terminal's. |
Error: TOMBA_API_KEY and TOMBA_SECRET_KEY environment variables are required | Set both variables in the env block of the client configuration. |
| The tools are listed, but every call returns an authentication error | The server checks credentials only when a tool calls the API. Check the key and secret, and whether the key has expired: see Key expiry. |
| A call fails with a rate limit error | The local server doesn't retry failed requests. Wait, then call again; see Handle 429 responses. |