## Description * Key failover via SDK middleware and passthrough reverse proxy * Provider-specific cooldown header extraction * BYOK bypass: only apply failover in centralized mode * Exhaustion handling: return 429 or 502 depending on failure type