Registration limits
5 per hour per IP and per email.
POST /api/auth/register: 5 attempts per hour per IP, 5 attempts per hour per email. Excess returns HTTP 429 with a Retry-After header.
Disposable-email checks run BEFORE the rate-limit counter increments, so blocked attempts do not exhaust legitimate users' budget.