Would you expect Google's security team to provide a detailed list of all of the security procedures in place to prevent access to their network?
Rejecting "security through obscurity" just means you shouldn't rely on obscurity alone. Obscurity + good security > good security alone, since it increases the threshold of time and ability that any attacker would need to bring to an attack.
After left-pad I think we'd all like to see a strong, well documented methodology to keep things like this from happening again. The broad strokes can't be any more clever than what the rest of us would expect, so why not at least provide a basic idea of what you're doing and then we could trust the system a bit more.
Neither of those are security systems. That's like asking for their password and claiming you've proven security through obscurity.
The idea behind dismissing obscurity is that if everything but private tokens were exposed, your system should still remain secure.