Jeff Barr: customers should not have to pay for unauthorized requests
https://twitter.com/jeffbarr/status/1785386554372042890
I potentially encountered a similar issue with API Gateway: CORS preflight requests are sent by browsers without headers, so you can't put them under an API usage plan with an API key. So far, I couldn't find out whether I'd be charged for these requests or not.