The appearance of buggy behavior can be expected if this is used on a site that does not strictly implement a REST interface (ie. POST to /resource/new/ instead of /resource/), but that's a flaw resulting from the individual implementation, not from your library, and even with an appropriately RESTful interface you'll still need to display messaging to the logged-in user when GET_ONLY_MODE is set to True.
You mention wanting to provide a generalized means of providing messaging in the template, but I've found that library templates are almost always inappropriate for inclusion into an existing application except in the most trivial of cases. An alternative to generalized messaging might be to implement some crazy logic in process_response() to disable all forms.
I also wonder whether environmental variables are appropriate for this type of change, since administering environmental updates across multiple servers requires a deploy strategy outside of the traditional Git schemes that people set up.
That said, I'll be watching the project to see where it leads. Congrats on the launch.