TombaTomba
Start free
  • Documentation
  • API reference
  • SDKs & CLI
  • AI & MCP
  • Integrations
  • Enterprise
  • Migration guides

Find, verify and enrich B2B contacts from public sources, in the app, your spreadsheet or through the API.

GDPR & CCPA

// docs

  • API changelog
  • Support options
  • Security

// platform

  • Dashboard
  • Pricing
  • API status

// resources

  • Help center
  • Product updates
  • TombaBot crawler

// company

  • Website
  • Contact us
  • Edit or remove your data

© 2021–2026 Tomba.io

  • Terms of service
  • Privacy policy
  • Cookie policy
  • Security policy
  • GDPR
  • CCPA
Get started
Platform
    Credits and usageRate limitsErrorsWebhooksVersioningAll limits
API guides
Response reference
Policies
Resources
Platform

Rate limits

Tomba limits how many requests you can send to each endpoint per second, per minute, and per day. The limits depend on your plan and apply to your whole account. Monthly allowances are separate; see Credits and usage.

Limits by plan

Each cell is requests per second / per minute / per day.

EndpointFreeBasicGrowthPro
Domain search, email finder, similar domains, technology1 / 2 / 53 / 50 / 5005 / 80 / 1,0008 / 150 / 4,000
Email verifier1 / 2 / 102 / 40 / 5003 / 60 / 1,0005 / 100 / 4,000
Author finder1 / 2 / 53 / 50 / 5005 / 80 / 1,0005 / 100 / 4,000
Email enrichment (/enrich)1 / 2 / 53 / 50 / 5005 / 80 / 1,0005 / 150 / 4,000
Person, company, and combined enrichment1 / 2 / 53 / 50 / 5005 / 80 / 1,0005 / 100 / 4,000
LinkedIn finder, phone finder, phone validator1 / 2 / 52 / 20 / 2003 / 40 / 5005 / 80 / 2,000
Location1 / 5 / 202 / 20 / 2003 / 40 / 5005 / 80 / 2,000
Email count1 / 5 / 203 / 50 / 1,0005 / 80 / 2,0008 / 150 / 5,000
Email format1 / 5 / 202 / 50 / 1,0003 / 80 / 2,0005 / 150 / 5,000
Email sources1 / 5 / 202 / 20 / 1003 / 10 / 1005 / 10 / 100
Domain suggestions1 / 5 / 203 / 50 / 5005 / 80 / 1,0008 / 150 / 4,000
Account (/me)2 / 30 / 5005 / 100 / 3,0005 / 150 / 5,00010 / 200 / 10,000

Other plans:

  • Pro Plus and Scale plans: no limits on these endpoints.
  • Enterprise: no per-second or per-minute limit, and 100,000 requests per endpoint per day.
  • Credit packs: while a pack has credits left, each limit is the higher of your plan's and the pack's. A pack of 50,000 credits or more removes the limits.

The table shows each plan's standard limits. GET /v1/rate-limits returns the limits that apply to your account; see Check your limits.

Endpoints with fixed limits

These endpoints have the same limits on every plan:

EndpointLimit
POST /reveal/search5 requests per second
Bulk jobsSee Bulk operations
GET /keys, GET /keys/{id}100 requests per minute
POST, PATCH, PUT, DELETE /keys100 requests per hour
GET /flag, POST /flag10 requests per minute per IP address

Leads, lead lists, lead attributes, /logs, /usage, /rate-limits, and /domain-status aren't rate-limited.

How limits are counted

  • One set of counters per account. Every API key, OAuth app, and workspace member of an account shares the same counters. Limits aren't per key.
  • Per endpoint. Each row in the table has its own counters.
  • Every accepted request counts, including requests that return no result or fail after the limit check. Requests rejected with 429 don't count.
  • Daily limits reset at 00:00 UTC.
  • Per-second and per-minute limits reset once 1 second or 60 seconds pass without an accepted request. A steady stream of requests keeps the counter from resetting, so continuous traffic can reach the limit even when its average rate is lower. After a 429 for rps or rpm, pause for the whole window, 1 or 60 seconds, before you retry.

Rate limit headers

Every response from an endpoint in the Limits by plan table carries these headers, on successful and 429 responses alike:

HeaderValue
x-second-rate-limitPer-second limit. 0 means no limit.
x-minute-rate-limitPer-minute limit. 0 means no limit.
x-daily-rate-limitDaily limit. 0 means no limit.
x-minute-request-leftRequests left in the per-minute counter
x-daily-request-leftRequests left today
x-minute-reset-secondsSeconds until the next full minute. The per-minute counter can take longer to reset; see How limits are counted.
x-daily-reset-secondsSeconds until 00:00 UTC
RateLimit-PolicyThe per-second and daily policies, for example "rps";q=8;w=1, "daily";q=4000;w=86400
RateLimitRemaining requests and seconds to reset for the same policies, for example "rps";r=7;t=1, "daily";r=3842;t=64802

On a 429, the headers show the values from before the rejected request.

Endpoints with fixed limits return X-RateLimit-Limit, X-RateLimit-Remaining, and X-RateLimit-Reset on successful responses and only Retry-After on a 429.

Handle 429 responses

A request over a limit fails with status 429, error type rate_limit, and a Retry-After header in seconds:

Code
{ "errors": { "type": "rate_limit", "message": "Rate limit exceeded (rpm). Limit is 150 requests. Retry after 42 seconds.", "code": 429 } }

The message names the limit that was hit: rps, rpm, or daily. For daily, Retry-After is the time until 00:00 UTC. A 429 without Retry-After from email count, email format, location, or email sources means that balance is used up, not that you're sending too fast; see Credits and usage.

Wait at least Retry-After seconds, and for rps and rpm at least the whole window, then retry with exponential backoff:

Check your limits

GET /v1/rate-limits returns the limits that apply to your account and your current usage, for each endpoint group. It isn't rate-limited itself.

TerminalCode
curl "https://api.tomba.io/v1/rate-limits" \ -H "X-Tomba-Key: $TOMBA_API_KEY" \ -H "X-Tomba-Secret: $TOMBA_SECRET_KEY"
Code
{ "data": { "domain-search": { "limits": { "rps": 8, "rpm": 150, "daily": 4000 }, "usage": { "rpm_used": 12, "daily_used": 847 } }, "email-verifier": { "limits": { "rps": 5, "rpm": 100, "daily": 4000 }, "usage": { "rpm_used": 0, "daily_used": 230 } } } }

Most keys match the endpoint path. The others:

KeyEndpoint
enrich/enrich
linkedin/linkedin
phone/phone-finder
enrich-email/people/find
enrich-company/companies/find
enrich-combined/combined/find
me/me
searchesSearches from the Tomba dashboard
revealListed but not enforced; /reveal/search has a fixed limit

In a workspace, members see the owner's limits and the workspace's combined usage. The dashboard shows the same information under Rate limits.

Last modified on September 30, 2026
Credits and usageErrors
On this page
  • Limits by plan
    • Endpoints with fixed limits
  • How limits are counted
  • Rate limit headers
  • Handle 429 responses
  • Check your limits
JSON
async function tombaGet(url, maxRetries = 5) { for (let attempt = 0; attempt <= maxRetries; attempt++) { const res = await fetch(url, { headers: { "X-Tomba-Key": process.env.TOMBA_API_KEY, "X-Tomba-Secret": process.env.TOMBA_SECRET_KEY, }, }); if (res.status !== 429) return res.json(); const body = await res.json(); const retryAfter = Number(res.headers.get("Retry-After") ?? 1); const windowSeconds = /\(rpm\)/.test(body.errors?.message ?? "") ? 60 : 1; const backoff = Math.min(2 ** attempt, 60); const waitSeconds = Math.max(retryAfter, windowSeconds, backoff); await new Promise((resolve) => setTimeout(resolve, waitSeconds * 1000)); } throw new Error("Rate limited: retries exhausted"); } const data = await tombaGet( "https://api.tomba.io/v1/domain-search?domain=stripe.com", ); console.log(data);
JSON
Javascript