Hello,
The issue indicates that the API Gateway is not correctly extracting or evaluating the header used to identify a partner's subscription tier. As a result, requests are falling through to a default path or are being processed without the expected usage plan association, allowing them to bypass configured rate limits.
The first area to validate is the header mapping and extraction logic at the API Gateway layer. Confirm that the header name, case sensitivity, transformation rules, and any custom authorizer or policy logic are consistently passing the tier identifier through the request pipeline. Gateway logs should be reviewed to verify the exact header values received versus the values used during usage plan evaluation.
Once header extraction is corrected, the rate-limiting configuration should be redesigned so that usage plans are bound to a trusted identity source rather than relying solely on client-supplied headers. Where supported by the platform, API keys, subscription identifiers, JWT claims, or authenticated client attributes are more reliable for tier enforcement. This prevents clients from accidentally or intentionally bypassing limits through malformed or missing headers.
After the changes are implemented, perform validation testing against each subscription tier to confirm that throttling thresholds, burst limits, and quota policies are enforced consistently and that requests with missing or invalid headers are rejected or assigned to the appropriate fallback policy.
I hope you've found something useful here. If it helps you get more insight into the issue, it's appreciated to accept the answer. Should you have more questions, feel free to leave a message. Have a nice day!
Domic Vo.