Stop letting every agent that knows your MCP server URL hammer your paid backend for free. This tutorial drops L402 Lightning gating plus a Depth-of-Identity score check in front of one tool, with a clone-and-run example repo. Ten minutes start to finish.