How rate limiting works:
Every request must pass two checks — (1) the key's total limit and (2) the per-IP sub-limit.
Whitelisted IPs skip the per-IP check but still count toward the key total.
Routes with per-route overrides below get their own isolated bucket — they don't eat into the default per-IP quota.