I genuinely don't understand why you're keeping the TPD limit under wraps for "risk control" or "security" reasons. I've worked on risk control myself—your API response headers return this data on every single call. It's already an open secret at this point. Honestly, this kind of restriction does nothing for "security purposes"; all it does is leave legitimate customers confused and helpless when they inexplicably hit 429 errors. Let's be real: if I were a bad actor, I'd just make one API call, see the TPD limit in the headers, and know exactly what's going on. It serves no purpose whatsoever. Mainstream platforms all publish their rate limits explicitly, and besides, calling your API costs money. it's not post-paid. I personally cannot comprehend why you've set things up this way.