Good beginner tips?

I run a website called https:/, an online SMS verification service. We have a lot of users that use our APIs to receive SMS verifications. Making it a bit harder to block most traffic or even use pro bot detection as there’s no way to whitelist specific directories, I’ve already blocked risk scores that go above 60 by default but not sure what to do more other than rate limits as even though I block them using the managed challenge, a lot of requests manage to bypass it.

Some usefull Firewall tips for Firewall Rules here:

