Adding a surface is a declaration plus one configuration value — deliberately not routing code. That cheapness is the point, and it is also the risk.
Two surfaces is clearly right. The structure would happily accept six, and it is not obvious that six would be.
What would settle it: a case where a proposed surface cannot be expressed as a version or a subroute of an existing one. Webhooks looked like a third surface at first and turned out not to be — a provider integration is a different subroute of the API, versioned exactly like everything else there, because the thing that distinguishes a surface is who consumes it, not what shape its payload is.
Until something fails that test, two is the answer, and the burden stays on any proposal for a third.