27 September 2026
The perils of a free API offer: a week of bots, repeat claims and quiet persistence
We reopened our $10 free tier for nine days. 174 claims, 125 refused automatically, 75 declined on review, and about one grant in five taken back. What abuse of a free API offer actually looks like, and what it costs.
We reopened our $10 free tier on 19 September and paused it again on 27 September. In those nine days it did what we wanted: real developers pointed real coding agents at it and sent more than 19,000 requests, with 93% of input tokens served from cache. It also turned into something we did not plan for, which was a small daily contest with people who wanted more than one helping.
This post is about that second part. Not the specific defences, which we are keeping to ourselves, but the shape of the problem, because anyone thinking about a free offer for an API should know what they are signing up for.
The numbers from one week
174 people started a claim. 125 attempts were refused automatically before anyone looked at them. 94 claims were held for a person to review, and 75 of those were declined. 88 grants went out, and roughly one in five was later taken back after we found it was a second or third helping for someone who already had one.
On most days of the offer, at least one account was revoked. That is the "almost daily battle" in plain numbers. None of it was dramatic. All of it took attention.
Free attracts two audiences, and they look alike at the door
The first audience is the one you built the offer for: a developer who wants to see whether a model and a gateway hold up under their own agent before paying for it. They sign up once, get a key, and either use it hard or never come back.
The second audience wants the credit itself. Some are curious tinkerers who push their luck. Some are organised. They arrive through the same form, with the same kind of email address, from the same kind of home connection. The difference only shows up in behaviour, and usually only after the fact.
What abuse actually looked like
Almost none of it was clever. It was persistent. The patterns repeated so often that we stopped being surprised by them:
- One person, many addresses. The most common case by far. A second address a few minutes after the first, then a third with a digit changed.
- Changing networks. When a second claim was refused, the next attempt came from a phone's mobile data, a VPN, or a rented server, often within a minute.
- Hitting the ceiling, then starting over. Our heaviest free users ran into the daily spending cap and, rather than wait a day, tried to open a fresh account to keep going.
- Several keys, one conversation. In one case a single agent session was spread across four free accounts, each taking a turn, so that no one account ever looked busy.
- Throwaway inboxes. Disposable mail services, private alias services and brand new domains with no website, each good for exactly one signup.
- Word of mouth. Links to the offer were shared in communities that trade tips on collecting free credit. Traffic from those arrived in waves, and the waves were noticeably more persistent.
Most of these people were not running botnets. They were individuals with a browser, a phone and patience. That is harder to deal with, not easier, because every single attempt looks like an ordinary person.
The costs nobody puts in the budget
The credit itself was the cheap part. The spend ceilings meant no single account could run away with more than a few dollars a day, and the tier ran on inference capacity we already had.
The expensive part was attention. Every held claim is a small judgement call. Every revocation is a decision about fairness to someone who might, occasionally, be a genuine user who just tried twice. Every login link a determined person requests is another email sent. Multiply that by a week and it is a real slice of a small team's time.
There is also a quieter cost. The stricter the checks, the more likely an honest person on an unusual connection gets held. We approved plenty of people from VPNs, shared offices and big mobile carriers who turned out to be exactly who they said they were. Getting that balance right, day after day, is the actual work.
What we would tell anyone planning a free tier
- Cap by spend, not by requests. An agent can fit a very expensive call into a single request. A daily dollar ceiling is what keeps a giveaway predictable.
- Assume every limit will be tested within a day. Whatever the rule is, someone will find its edge, usually by changing one thing at a time.
- Budget for review time, not just credit. The giveaway costs what you give away plus the hours spent deciding who gets it.
- Measure use, not signups. Claimed slots are a vanity number. Our first round showed most keys were never used at all.
- Decide your fairness rules before you need them. "One per person" sounds simple until a household, an office or a shared connection shows up.
Was it worth it?
Yes, with eyes open. Around fifty free accounts used the tier as a real workload this week, a few of them found us through a recommendation rather than a forum thread, and the traffic confirmed again that cache pricing is what decides agent costs. That is worth a week of vigilance.
The free tier is paused for now, and we may bring it back. In the meantime credit packs start at $10, never expire, and unlock every model in the catalogue on one key.