bcrypt, scrypt or argon2 for a new project?
Argon2id with the current OWASP parameters, and bcrypt only when a library constraint forces it. What matters more than the choice is that the cost parameter is revisited: a setting tuned five years ago is now cheap to attack.
What is a sane rate limit design for a public API?
Token bucket per key and per IP, with the limit expressed in the response headers so clients can behave. The subtle part is what you do on limit: a 429 with Retry-After is cooperative, silently dropping is what turns one misbehaving client into a retry storm.
Do I need CSRF protection if I use bearer tokens?
Not if the token lives in memory and is sent in a header, because the browser will not attach it automatically. The moment it moves into a cookie for convenience, CSRF is back, and SameSite=Lax becomes load-bearing.