WAF blocks known threats. Custom authorizer validates short-lived tokens proving app origin. Session-based rate limiting tracks per-token usage. This addresses CGNAT environments where IP-based limiting fails. Session tokens replace IP addresses as the primary rate limit identifier. No traditional authentication required.