The trouble with API keys that never expire
A key issued years ago, never rotated, and still valid today is not a convenience. It is a liability nobody has actually looked at in years.
"Unlimited" is a word with a precise meaning that gets used loosely often enough that the precise meaning has started to feel almost naive to expect. It should mean exactly what it says: no ceiling on the number of requests you can send under that plan, at any rate your actual usage reaches. It should not mean a very large number that the provider has not disclosed, a rate that gets throttled once usage crosses an internal threshold, or a plan that technically has no stated limit but comes with a fair use clause that functions as an undisclosed one.
Our Unlimited key, at €50 a month, means the first definition and only the first definition. There is no internal threshold above which requests start getting throttled, no fair use policy standing in for a number we would rather not publish, and no distinction between what the plan advertises and what it actually permits once you use it heavily. If we ever built in a genuine technical safeguard, the honest response would be to rename the plan and publish the real number, not keep the word and quietly attach a condition to it.
We think a useful test for whether an unlimited claim is genuine is whether it is falsifiable in a specific, checkable way: can a customer send an unusually large volume of requests in a short period and see whether the plan actually holds, or does the provider have language somewhere that lets them redefine "unusual" after the fact, in a way the customer could not have predicted from the plan's terms. A claim that can always be explained away after the fact is not really a claim. It is a placeholder for whatever the provider decides later.
This distinction matters because unlimited plans exist specifically for customers who need to stop thinking about their request volume as a cost center to manage. That is the entire value proposition: pay a flat amount and stop counting. A plan that quietly still has a ceiling defeats that purpose in the worst possible way, because the customer who bought it specifically to stop worrying about limits is the one most likely to be surprised when a hidden one gets enforced, since they were the one relying most heavily on the word meaning what it said.
We are not arguing every provider needs to offer an unlimited tier, or that a capped, clearly priced plan is worse than an unlimited one. A clearly stated cap is honest on its own terms. What is not honest is calling a capped plan unlimited because the cap is set high enough that most customers will never personally test it. The word should describe a property of the plan, tested and true at any volume, not a marketing impression that happens to hold for the median customer and quietly fails for anyone who actually needed the promise to be literal.