That's a different question (probably needs its own thread), but the short answer is that there is no one-size fits all answer. You need to assess your own needs based on your customer usage levels. You don't want to impede legit traffic, so you set hourly rates just beyond the upper bounds of your typical usage. So it won't become a barrier, but is there to safeguard if credentials get exposed or an errant script starts sending spam.