Their default of “just go ham on that API” feels like the same footgun of “by default this Humongous Database is wide open.”
The easiest path will always be the default for the majority of devs, with a simple "timer" type solution being the easiest to implement in pretty much all cases except where otherwise it's literally forced on them.