You can limit it a lot to minimize the abuse. In free entrypoint, set token and context limits to be very small. Limit to 2 prompts per IP or something every X hour. That is already a substantial limit where bypassing might not provide much benefits.
I entered a question to try it, but as soon as I hit enter it wants my phone number for a login. No thanks.