I have implemented authentication on an API Gateway level using NGINX+ and now I have concern if APIs behind it should still to authenticate using API Keys or JWT? What are