Two different questions get asked on every paid API request. Who is this? And what is this person allowed to see? A key answers the first. A subscription answers the second. They are separate on purpose, and mixing them up explains a surprising share of confused integrations.
Why they are separate
A key is an identifier you can rotate without touching billing, revoke without cancelling anything, and issue more than one of. A subscription lives in a payment system and changes on its own schedule. Tying them together would mean rotating a key cancelled your access, which nobody wants.
So the key resolves to an account, and the account is checked against what it holds. If the account holds nothing, the key is still perfectly valid; it simply opens the free surface.
Reading the two refusals
A 401 means we do not know who you are: the key is missing, malformed or unknown. Check the header first. A 402 means we know exactly who you are and this is not included: the fix is a purchase, not a new key.
A third answer is worth having, and many APIs skip it. If the entitlement system itself is unreachable, the honest response is neither of those. It is a temporary failure on our side, and a client should retry rather than tell a paying customer they did not pay.
One key, several products
If a vendor sells more than one product, the same key can open different sets of endpoints depending on what the account holds. That is normal. What should not happen is a cheaper tier silently opening an expensive one, which is why lanes are usually allow-listed rather than blocked individually.