Created a new proxy with verify api key policy and added to the product and app.
I tried testing with different active keys present in the org. The expectation is to throw an error when keys other than the original key are sent. But the proxy accepts all the active keys present in that env/org. Is it a right understanding?