snapshot
Returns a point-in-time snapshot of the rate limiter state.
Thread-safety note: tokens and lastRefillMs are read from @Volatile fields without holding mutex. Each field is individually visible across threads but the combination may be momentarily inconsistent. This is an intentional approximation suitable for health-check endpoints and dashboards.