Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

Tomba MCP Server

REMOTE · MCP.TOMBA.IO · 2 COMPONENTS · SCANNED OCT 2

MCP server for Tomba email finder, verification, and contact enrichment API

0 this week 39 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security97
Transport & Reachability0
Schema Quality & AI Usability0
  • Schema blocked by authentication: the endpoint requires auth we don't have to read it. See how to fix → Unverified
Stability & Change Management0
  • Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage0
  • Tool coverage blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Tool Safety0
  • Tool safety blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Capabilities0
  • Capabilities blocked by authentication: the endpoint requires auth we don't have to read them. See how to fix → Unverified

Unverified: 6 categories

Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm. Claim this server and supply a read-only token to verify it and lift the score.

Install

How do I install the Tomba MCP Server server?

Tomba MCP Server is a hosted endpoint at https://mcp.tomba.io/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · mcp.tomba.io

# add to Claude Code
claude mcp add --transport http tomba-io-tomba-mcp-server 'https://mcp.tomba.io/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "tomba-io-tomba-mcp-server": {
      "url": "https://mcp.tomba.io/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "tomba-io-tomba-mcp-server": {
      "type": "http",
      "url": "https://mcp.tomba.io/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.tomba-io-tomba-mcp-server]
url = "https://mcp.tomba.io/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "tomba-io-tomba-mcp-server": {
      "type": "remote",
      "url": "https://mcp.tomba.io/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add tomba-io-tomba-mcp-server --url 'https://mcp.tomba.io/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  tomba-io-tomba-mcp-server:
    url: "https://mcp.tomba.io/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "tomba-io-tomba-mcp-server": {
      "Transport": "http",
      "Url": "https://mcp.tomba.io/mcp"
    }
  }
}
# add to Vellum
assistant mcp add tomba-io-tomba-mcp-server -t streamable-http -u 'https://mcp.tomba.io/mcp'
// mcp.json
{
  "mcpServers": {
    "tomba-io-tomba-mcp-server": {
      "type": "http",
      "url": "https://mcp.tomba.io/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 28 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 25 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 15 Sept 26 −41
    • Endpoint reachability: reachable → behind authorisation ▼ security
    • Stability: pass → unverified ▼ security
    • Tool safety: pass → unverified ▼ security
    • Transport: pass → unverified ▼ security
    • Authorization: unverified → pass ▲ security
    • HSTS header: fail → pass ▲ security
    • First check of Authorization: pass security
    • Capabilities: pass → unverified ▼ functional
    • Tool coverage: 100 → unverified ▼ functional
    • Schema quality: 100 → unverified ▼ functional
  • 6 Sept 26 +1
    • Stability: 0.97 → pass security
  • 4 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 90 to 93. That category is still filling its 30-day observation window: 27 days of observed history at the previous scan, 28 at this one. The score rises as the window fills, whether or not the server changes.

  • 3 Sept 26 78
    • Tool coverage: 100% → 75% ▼ functional
    • Schema quality: 72 → 56 ▲ functional
    • Tool “mpp_email_verifier” now declares an output schema ▲ functional
    • Tool “mpp_linkedin_finder” now declares an output schema ▲ functional
    • Tool “mpp_phone_finder” now declares an output schema ▲ functional
    • Tool “mpp_phone_validator” now declares an output schema ▲ functional
    • Tool “mpp_similar_finder” now declares an output schema ▲ functional
    • Tool “phone_finder” now declares an output schema ▲ functional
    • Tool “phone_validator” now declares an output schema ▲ functional
    • Tool “similar_finder” now declares an output schema ▲ functional
    • Tool “technology_finder” now declares an output schema ▲ functional
    • Tool “author_finder” now declares an output schema ▲ functional
    • Tool “companies_search” now declares an output schema ▲ functional
    • Tool “domain_search” now declares an output schema ▲ functional
    • Tool “email_count” now declares an output schema ▲ functional
    • Tool “email_enrichment” now declares an output schema ▲ functional
    • Tool “email_finder” now declares an output schema ▲ functional
    • Tool “email_verifier” now declares an output schema ▲ functional
    • Tool “linkedin_finder” now declares an output schema ▲ functional
    • Tool “mpp_author_finder” now declares an output schema ▲ functional
    • Tool “mpp_domain_search” now declares an output schema ▲ functional
    • Tool “mpp_email_count” now declares an output schema ▲ functional
    • Tool “mpp_email_enrichment” now declares an output schema ▲ functional
    • Tool “mpp_email_finder” now declares an output schema ▲ functional
    • The server now declares the “logging” capability functional
    • First check of Tool coverage: 100 functional
    • Schema quality: excellent → good functional
    • New tool “account_info” functional
    • New tool “autocomplete” functional
    • New tool “combined_enrichment” functional
    • New tool “company_enrichment” functional
    • New tool “create_flag” functional
    • New tool “create_lead” functional
    • New tool “domain_status” functional
    • New tool “email_format” functional
    • New tool “email_sources” functional
    • New tool “get_logs” functional
    • New tool “list_keys” functional
    • New tool “list_leads” functional
    • New tool “location” functional
    • New tool “person_enrichment” functional
    • New tool “usage_info” functional
    • New tool “list_flags” functional
  • 26 Aug 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 11 Aug 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 2 Oct 2026 · Probed https://mcp.tomba.io/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=tomba.io CN=YE1,O=Let's Encrypt,C=US 28 Sept 2026 27 Dec 2026 ECDSA 256 ECDSA-SHA384 5509cdc4097f79f0ed11e95820cc5e9f105
SANs: *.tomba.io, tomba.io
CN=YE1,O=Let's Encrypt,C=US (CA) CN=Root YE,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 ECDSA 384 ECDSA-SHA384 5ddd70dd31f801c85c186a7a04b80afe
CN=Root YE,O=ISRG,C=US (CA) CN=ISRG Root X2,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 ECDSA-SHA384 872165fc34b6e5fba8add5b3705fb53a
CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 SHA256-RSA 6c8f1dc727c7117f7baf853ac980f9cd

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of mcp.tomba.io. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
io. present 57355 8 Verified
tomba.io. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication Enforced and verified

The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.

Result Enforced and verified
Enforced On connection
HTTP status 401

WWW-Authenticate challenge Bearer resource_metadata="https://mcp.tomba.io/.well-known/oauth-protected-resource"

Bearer resource_metadata="https://mcp.tomba.io/.well-known/oauth-protected-resource"
Header Value
strict-transport-security max-age=31536000; includeSubDomains
www-authenticate Bearer resource_metadata="https://mcp.tomba.io/.well-known/oauth-protected-resource"

Protected resource metadata

Document https://mcp.tomba.io/.well-known/oauth-protected-resource
Retrieved Yes
Resource https://mcp.tomba.io/mcp
Authorisation server https://api.tomba.io

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://mcp.tomba.io/mcp Auth required 401
http (plaintext) http://mcp.tomba.io/mcp HTTPS enforced 301 https://mcp.tomba.io/mcp
MCP tools · 38 exposed · ~2,260 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
account_info ~23

Get current Tomba account information including plan, credits, and usage limits

Input schema present but exposes no named parameters.

NameTypeReqDescription
data–yes–

No examples provided.

author_finder ~62

Find the email address of an article's author from a given URL. Useful for outreach to content creators and journalists.

NameTypeReqDescription
urlstringyesThe URL of the article or blog post
webhook_urlstring–Optional webhook URL to receive results asynchronously
NameTypeReqDescription
data–yes–

No examples provided.

autocomplete ~25

Autocomplete company names and retrieve logo and domain information

NameTypeReqDescription
querystringyes–
NameTypeReqDescription
data–yes–

No examples provided.

combined_enrichment ~24

Combined person and company enrichment by email

NameTypeReqDescription
emailstringyes–
NameTypeReqDescription
data–yes–

No examples provided.

companies_search ~129

Search for companies in the Tomba database. Filter by name, industry, country, and more to find target companies for outreach.

NameTypeReqDescription
filtersobject–Filter options with include/exclude arrays for: location_country, location_city, location_state, industry, size, type, keywords, founded, technologies, similar, revenue, sic, naics
pagenumber–Page number for pagination (1-1000)
querystring–Search query for company name or keywords (8-100 characters)
webhook_urlstring–Optional webhook URL to receive results asynchronously
NameTypeReqDescription
data–yes–

No examples provided.

company_enrichment ~42

Find company data by domain including industry, size, location, and social profiles

NameTypeReqDescription
domainstringyesThe domain name (e.g., 'stripe.com')
NameTypeReqDescription
data–yes–

No examples provided.

create_flag ~44

Report incorrect data for credit recovery

NameTypeReqDescription
commentstring––
flag_typestringyes–
reasonstringyes–
valuestringyes–
NameTypeReqDescription
data–yes–

No examples provided.

create_lead ~62

Add a new lead to a list

NameTypeReqDescription
companystring––
emailstringyes–
first_namestring––
last_namestring––
list_idintegeryes–
positionstring––
NameTypeReqDescription
data–yes–

No examples provided.

domain_search ~179

Search for all email addresses associated with a specific domain or company. Returns a list of email addresses found for the given company domain along with metadata about each contact.

NameTypeReqDescription
companystring–The company name to search for
countrystring–Filter by country code (e.g., 'US', 'GB')
departmentstring–Filter by department (e.g., 'executive', 'it', 'marketing')
domainstring–The domain to search for emails (e.g., 'example.com')
enrich_mobileboolean–Whether to enrich with mobile phone data
limitstring–Maximum number of results to return (10, 20, or 50)
pagenumber–Page number for pagination
webhook_urlstring–Optional webhook URL to receive results asynchronously
NameTypeReqDescription
data–yes–

No examples provided.

domain_status ~39

Check if a domain is a webmail provider or disposable email service

NameTypeReqDescription
domainstringyesThe domain name (e.g., 'stripe.com')
NameTypeReqDescription
data–yes–

No examples provided.

email_count ~53

Get the count of email addresses available for a specific domain. Useful for estimating the potential reach before performing a full domain search.

NameTypeReqDescription
domainstringyesThe domain to count emails for (e.g., 'example.com')
NameTypeReqDescription
data–yes–

No examples provided.

email_enrichment ~46

Enrich an email address with additional information about the person, including their name, position, company details, and social profiles.

NameTypeReqDescription
emailstringyesThe email address to enrich
NameTypeReqDescription
data–yes–

No examples provided.

email_finder ~152

Find the email address of a specific person given their name and company domain or company name. Uses various techniques to generate and verify the most likely email format.

NameTypeReqDescription
companystring–The company name to search in
domainstring–The domain of the company (e.g., 'example.com')
enrich_mobileboolean–Whether to enrich with mobile phone data
first_namestring–The first name of the person
full_namestring–The full name of the person (alternative to first_name/last_name)
last_namestring–The last name of the person
webhook_urlstring–Optional webhook URL to receive results asynchronously
NameTypeReqDescription
data–yes–

No examples provided.

email_format ~36

Get the email format patterns used by a specific domain

NameTypeReqDescription
domainstringyesThe domain name (e.g., 'stripe.com')
NameTypeReqDescription
data–yes–

No examples provided.

email_sources ~26

Find where an email address was found on the web

NameTypeReqDescription
emailstringyes–
NameTypeReqDescription
data–yes–

No examples provided.

email_verifier ~78

Verify if an email address is valid and deliverable. Checks for proper format, domain validity, and mailbox existence without sending an email.

NameTypeReqDescription
emailstringyesThe email address to verify
enrich_mobileboolean–Whether to enrich with mobile phone data
webhook_urlstring–Optional webhook URL to receive results asynchronously
NameTypeReqDescription
data–yes–

No examples provided.

get_logs ~28

Get recent API request logs

NameTypeReqDescription
limitnumber––
pagenumber––
NameTypeReqDescription
data–yes–

No examples provided.

linkedin_finder ~72

Find the email address associated with a LinkedIn profile URL. Extracts contact information from LinkedIn profiles.

NameTypeReqDescription
enrich_mobileboolean–Whether to enrich with mobile phone data
urlstringyesThe LinkedIn profile URL
webhook_urlstring–Optional webhook URL to receive results asynchronously
NameTypeReqDescription
data–yes–

No examples provided.

list_flags ~33

List submitted data flags with status and credit refund information

NameTypeReqDescription
limitinteger––
pageinteger––
NameTypeReqDescription
data–yes–

No examples provided.

list_keys ~16

List all API keys for the account

Input schema present but exposes no named parameters.

NameTypeReqDescription
data–yes–

No examples provided.

list_leads ~37

List leads with optional domain filter

NameTypeReqDescription
domainstring––
limitnumber––
pagenumber––
NameTypeReqDescription
data–yes–

No examples provided.

location ~34

Get employees location count by country for a domain

NameTypeReqDescription
domainstringyesThe domain name (e.g., 'stripe.com')
NameTypeReqDescription
data–yes–

No examples provided.

mpp_author_finder ~56

Find the email address of the author of a blog post or article using MPP (Machine Payments Protocol). Pay-per-request, no API key required.

NameTypeReqDescription
urlstringyesThe URL of the article or blog post
NameTypeReqDescription
data–yes–

No examples provided.

mpp_domain_search ~144

Search for all email addresses associated with a specific domain using MPP (Machine Payments Protocol). Pay-per-request, no API key required — only an InFlow buyer key.

NameTypeReqDescription
companystring–The company name to search for
countrystring–Filter by country code (e.g., 'US', 'GB')
departmentstring–Filter by department (e.g., 'executive', 'it', 'marketing')
domainstring–The domain to search for emails (e.g., 'example.com')
limitstring–Maximum number of results to return
pagenumber–Page number for pagination
NameTypeReqDescription
data–yes–

No examples provided.

mpp_email_count ~51

Get the count of email addresses available for a specific domain using MPP (Machine Payments Protocol). Pay-per-request, no API key required.

NameTypeReqDescription
domainstringyesThe domain to count emails for
NameTypeReqDescription
data–yes–

No examples provided.

mpp_email_enrichment ~51

Enrich an email address with detailed contact and company information using MPP (Machine Payments Protocol). Pay-per-request, no API key required.

NameTypeReqDescription
emailstringyesThe email address to enrich
NameTypeReqDescription
data–yes–

No examples provided.

mpp_email_finder ~97

Find a person's email address given their name and company domain using MPP (Machine Payments Protocol). Pay-per-request, no API key required.

NameTypeReqDescription
companystring–The company name
domainstring–The domain of the company
first_namestring–The first name
full_namestring–The full name of the person
last_namestring–The last name
NameTypeReqDescription
data–yes–

No examples provided.

mpp_email_verifier ~50

Verify if an email address is valid and deliverable using MPP (Machine Payments Protocol). Pay-per-request, no API key required.

NameTypeReqDescription
emailstringyesThe email address to verify
NameTypeReqDescription
data–yes–

No examples provided.

mpp_linkedin_finder ~52

Find a person's email address from their LinkedIn profile URL using MPP (Machine Payments Protocol). Pay-per-request, no API key required.

NameTypeReqDescription
urlstringyesThe LinkedIn profile URL
NameTypeReqDescription
data–yes–

No examples provided.

mpp_phone_finder ~93

Find phone numbers associated with an email address, domain, or LinkedIn profile using MPP (Machine Payments Protocol). Pay-per-request, no API key required.

NameTypeReqDescription
domainstring–The domain to look up
emailstring–The email address to look up
fullboolean–Whether to return full phone details
linkedinstring–The LinkedIn profile URL
NameTypeReqDescription
data–yes–

No examples provided.

mpp_phone_validator ~54

Validate a phone number and get carrier and location details using MPP (Machine Payments Protocol). Pay-per-request, no API key required.

NameTypeReqDescription
phonestringyesThe phone number to validate in E.164 format
NameTypeReqDescription
data–yes–

No examples provided.

mpp_similar_finder ~50

Find domains similar to a given domain using MPP (Machine Payments Protocol). Pay-per-request, no API key required.

NameTypeReqDescription
domainstringyesThe domain to find similar domains for
NameTypeReqDescription
data–yes–

No examples provided.

person_enrichment ~32

Find person data by email including name, position, company, and social profiles

NameTypeReqDescription
emailstringyes–
NameTypeReqDescription
data–yes–

No examples provided.

phone_finder ~104

Find phone numbers associated with an email address, domain, or LinkedIn profile. Returns direct and company phone numbers when available.

NameTypeReqDescription
domainstring–Domain to search for phone numbers
emailstring–Email address to search for phone numbers
fullboolean–Whether to return full phone details
linkedinstring–LinkedIn URL to search for phone numbers
webhook_urlstring–Optional webhook URL to receive results asynchronously
NameTypeReqDescription
data–yes–

No examples provided.

phone_validator ~60

Validate and get information about a phone number. Returns the carrier, line type, country, and whether the number is valid.

NameTypeReqDescription
phonestringyesThe phone number to validate (E.164 format recommended, e.g., +14155552671)
NameTypeReqDescription
data–yes–

No examples provided.

similar_finder ~56

Find companies similar to a given domain. Returns a list of competitor or similar businesses based on industry, size, and other factors.

NameTypeReqDescription
domainstringyesThe domain to find similar companies for (e.g., 'example.com')
NameTypeReqDescription
data–yes–

No examples provided.

technology_finder ~53

Discover the technologies used by a website. Returns information about the tech stack including CMS, frameworks, analytics, and more.

NameTypeReqDescription
domainstringyesThe domain to analyze for technologies (e.g., 'example.com')
NameTypeReqDescription
data–yes–

No examples provided.

usage_info ~17

Get current API usage statistics across all endpoints

Input schema present but exposes no named parameters.

NameTypeReqDescription
data–yes–

No examples provided.

Common questions

What is the Tomba MCP Server server?

Tomba MCP Server is listed in the public MCP registry as io.github.tomba-io/tomba-mcp-server. MCP server for Tomba email finder, verification, and contact enrichment API. This page covers its hosted endpoint (https://mcp.tomba.io/mcp).

Is the Tomba MCP Server server safe to use?

Tomba MCP Server scores 39 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the Tomba MCP Server server expose?

Tomba MCP Server exposes 38 tools: account_info, author_finder, autocomplete, combined_enrichment, companies_search, and 33 more. Their descriptions and schemas cost roughly 2,260 tokens of context every time the server is loaded.

Does the Tomba MCP Server server require authentication?

Yes. Tomba MCP Server asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.

Is the Tomba MCP Server server still maintained?

Tomba MCP Server is still listed as active in the MCP registry. We last reached this channel on 2 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.