Rate limits
Tomba limits how many requests you can send to each endpoint per second, per minute, and per day. The limits depend on your plan and apply to your whole account. Monthly allowances are separate; see Credits and usage.
Limits by plan
Each cell is requests per second / per minute / per day.
| Endpoint | Free | Basic | Growth | Pro |
|---|---|---|---|---|
| Domain search, email finder, similar domains, technology | 1 / 2 / 5 | 3 / 50 / 500 | 5 / 80 / 1,000 | 8 / 150 / 4,000 |
| Email verifier | 1 / 2 / 10 | 2 / 40 / 500 | 3 / 60 / 1,000 | 5 / 100 / 4,000 |
| Author finder | 1 / 2 / 5 | 3 / 50 / 500 | 5 / 80 / 1,000 | 5 / 100 / 4,000 |
Email enrichment (/enrich) | 1 / 2 / 5 | 3 / 50 / 500 | 5 / 80 / 1,000 | 5 / 150 / 4,000 |
| Person, company, and combined enrichment | 1 / 2 / 5 | 3 / 50 / 500 | 5 / 80 / 1,000 | 5 / 100 / 4,000 |
| LinkedIn finder, phone finder, phone validator | 1 / 2 / 5 | 2 / 20 / 200 | 3 / 40 / 500 | 5 / 80 / 2,000 |
| Location | 1 / 5 / 20 | 2 / 20 / 200 | 3 / 40 / 500 | 5 / 80 / 2,000 |
| Email count | 1 / 5 / 20 | 3 / 50 / 1,000 | 5 / 80 / 2,000 | 8 / 150 / 5,000 |
| Email format | 1 / 5 / 20 | 2 / 50 / 1,000 | 3 / 80 / 2,000 | 5 / 150 / 5,000 |
| Email sources | 1 / 5 / 20 | 2 / 20 / 100 | 3 / 10 / 100 | 5 / 10 / 100 |
| Domain suggestions | 1 / 5 / 20 | 3 / 50 / 500 | 5 / 80 / 1,000 | 8 / 150 / 4,000 |
Account (/me) | 2 / 30 / 500 | 5 / 100 / 3,000 | 5 / 150 / 5,000 | 10 / 200 / 10,000 |
Other plans:
- Pro Plus and Scale plans: no limits on these endpoints.
- Enterprise: no per-second or per-minute limit, and 100,000 requests per endpoint per day.
- Credit packs: while a pack has credits left, each limit is the higher of your plan's and the pack's. A pack of 50,000 credits or more removes the limits.
The table shows each plan's standard limits. GET /v1/rate-limits returns the limits that apply to your account; see Check your limits.
Endpoints with fixed limits
These endpoints have the same limits on every plan:
| Endpoint | Limit |
|---|---|
POST /reveal/search | 5 requests per second |
| Bulk jobs | See Bulk operations |
GET /keys, GET /keys/{id} | 100 requests per minute |
POST, PATCH, PUT, DELETE /keys | 100 requests per hour |
GET /flag, POST /flag | 10 requests per minute per IP address |
Leads, lead lists, lead attributes, /logs, /usage, /rate-limits, and /domain-status aren't rate-limited.
How limits are counted
- One set of counters per account. Every API key, OAuth app, and workspace member of an account shares the same counters. Limits aren't per key.
- Per endpoint. Each row in the table has its own counters.
- Every accepted request counts, including requests that return no result or fail after the limit check. Requests rejected with
429don't count. - Daily limits reset at 00:00 UTC.
- Per-second and per-minute limits reset once 1 second or 60 seconds pass without an accepted request. A steady stream of requests keeps the counter from resetting, so continuous traffic can reach the limit even when its average rate is lower. After a
429forrpsorrpm, pause for the whole window, 1 or 60 seconds, before you retry.
Rate limit headers
Every response from an endpoint in the Limits by plan table carries these headers, on successful and 429 responses alike:
| Header | Value |
|---|---|
x-second-rate-limit | Per-second limit. 0 means no limit. |
x-minute-rate-limit | Per-minute limit. 0 means no limit. |
x-daily-rate-limit | Daily limit. 0 means no limit. |
x-minute-request-left | Requests left in the per-minute counter |
x-daily-request-left | Requests left today |
x-minute-reset-seconds | Seconds until the next full minute. The per-minute counter can take longer to reset; see How limits are counted. |
x-daily-reset-seconds | Seconds until 00:00 UTC |
RateLimit-Policy | The per-second and daily policies, for example "rps";q=8;w=1, "daily";q=4000;w=86400 |
RateLimit | Remaining requests and seconds to reset for the same policies, for example "rps";r=7;t=1, "daily";r=3842;t=64802 |
On a 429, the headers show the values from before the rejected request.
Endpoints with fixed limits return X-RateLimit-Limit, X-RateLimit-Remaining, and X-RateLimit-Reset on successful responses and only Retry-After on a 429.
Handle 429 responses
A request over a limit fails with status 429, error type rate_limit, and a Retry-After header in seconds:
Code
The message names the limit that was hit: rps, rpm, or daily. For daily, Retry-After is the time until 00:00 UTC. A 429 without Retry-After from email count, email format, location, or email sources means that balance is used up, not that you're sending too fast; see Credits and usage.
Wait at least Retry-After seconds, and for rps and rpm at least the whole window, then retry with exponential backoff:
Check your limits
GET /v1/rate-limits returns the limits that apply to your account and your current usage, for each endpoint group. It isn't rate-limited itself.
Code
Code
Most keys match the endpoint path. The others:
| Key | Endpoint |
|---|---|
enrich | /enrich |
linkedin | /linkedin |
phone | /phone-finder |
enrich-email | /people/find |
enrich-company | /companies/find |
enrich-combined | /combined/find |
me | /me |
searches | Searches from the Tomba dashboard |
reveal | Listed but not enforced; /reveal/search has a fixed limit |
In a workspace, members see the owner's limits and the workspace's combined usage. The dashboard shows the same information under Rate limits.