1. The temporary token should be run-
- The temporary token should be run-bound, only work for the duration of the run. If you can use it 1 hour after the run, that would be quite a huge security bug so please report that if it actually happens.
- Not sure about ToS, it definitely looks a bit shady. But practically it sounds ok, for PPR/PPE, the compute/proxies/storage costs for the token are subtracted from your PPE revenue so the customer wouldn't really care what you do with it. For PPU however, you could just abuse the token for your stuff. The delay between your server and Apify should be tens of ms (if you are in the US) so I would really go with relaying everything back to the Actor.
- What is the reason to use your server, are you hitting any bottlenecks?