Tomba for AI agents

Tomba finds and verifies professional email addresses for B2B sales and outreach, used by sales teams building prospect lists. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

CRMAPI keyMCP + RESTtomba.io
AUDIT LOG · TOMBAPOLICY: acme-support
09:41:07 · claude · u_8f2read
tomba.search_domain_contacts
Search Domain Contacts✓ allowed · 212ms
09:41:08 · claude · u_8f2read
tomba.find_email
Find Professional Email✓ allowed · 164ms
09:41:09 · claude · u_8f2write
tomba.keys_list
List API Keys✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
tomba.keys_delete
Delete API Key by ID✕ blocked · policy: deny
EVERY TOMBA CALL, ON THE RECORD
01 · USE CASES

What agents do in Tomba.

01

Find a professional email address

Look up the likely work email for a person at a company, a read-only search.

02

Verify an email address

Check whether an email address is valid and deliverable before it's added to a list.

03

Confirm before deleting a lead list

Check with the user before deleting a saved lead list, since the enrichment work is lost with it.

02 · ACTIONS

25 Tomba actions, graded by risk.

Every Tomba action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

12

Look things up. Allowed by default.

  • tomba.find_email
    Find Professional Email
  • tomba.find_phone
    Find Phone Numbers
  • tomba.find_author
    Find Article Author
  • tomba.get_email_count
    Get Domain Email Count
  • tomba.get_email_format
    Get Domain Email Formats
  • tomba.get_email_sources
    Get Email Sources
  • tomba.get_employee_locations
    Get Employee Locations
  • tomba.search_domain_contacts
    Search Domain Contacts
  • tomba.find_email_from_linkedin
    Find Email From LinkedIn
  • tomba.verify_email
    Verify Email
  • tomba.verify_emails
    Verify Emails
  • tomba.validate_phone
    Validate Phone Number

write

11

Create and change things. Allow, or ask the user first.

  • tomba.keys_list
    List API Keys
  • tomba.leads_list
    List Leads
  • tomba.lists_list
    List Lead Lists
  • tomba.usage_stats
    Get Usage Statistics
  • tomba.leads_create
    Create Lead
  • tomba.lists_update
    Update Leads List
  • tomba.domain_status
    Domain Status
  • tomba.enrich_person
    Enrich Person
  • tomba.enrich_company
    Enrich Company
  • tomba.attributes_list
    List Lead Attributes
  • tomba.enrich_person_and_company
    Enrich Person and Company

destructive

2

Delete, cancel or archive. Ask first, or deny outright.

  • tomba.keys_delete
    Delete API Key by ID
  • tomba.lists_delete
    Delete Leads List by ID
03 · HOW IT WORKS

Tomba in three steps.

  1. 01Your users connect TombaThey add their Tomba api key on Arc0 Connect, under your brand. It goes straight into the vault.
  2. 02You set the rulesReads run, writes like “list API Keys” can wait for the user, and “delete API Key by ID” can be denied outright.
  3. 03Any agent can actYour agent calls Tomba through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('tomba', {
  read: 'allow',
  write: 'ask',        // keys_list
  destructive: 'deny',  // keys_delete
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How Tomba connects.

Users add their Tomba api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

The same Tomba connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
API key
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use Tomba from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

Tomba and Arc0, answered.

Q01

Can I use Tomba with Claude, ChatGPT or Cursor?

Yes. Connect Tomba to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Tomba actions you allow.

Q02

How do users connect Tomba?

Users add their Tomba api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

Q03

Which Tomba actions can my agent take?

25 in total: 12 read, 11 write and 2 destructive, such as “list API Keys”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in Tomba?

Yes. Actions like “delete API Key by ID” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call Tomba too?

Yes. The same Tomba connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug Tomba into your agent.

Your users connect Tomba once, under your brand. Your agent gets 25 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan