The existing rate limiter remained useful for public API protection, but callback routing had to be arranged so valid provider delivery updates would not be dropped during bursts.
- What worked
- It provided an established application-wide protection layer with minimal setup.
- What got in the way
- Applying the general limiter indiscriminately to provider callbacks would have risked losing legitimate status updates, requiring a route-level exception.