One idea I had was to count # of distinct API keys that have spent atleast $100 (number's flexible), which would be enough to provide guidance on if the traffic is from a single power-user.
In the Cursor case which is BYOK, that would count as distinct API keys.