    API's with same URL in different orgs messed up

      We created API's in different orgs with simple HTTP auth only allowing access from that particular org.


      We found when the API's with the same URL, calling them will get the requests randomly hit both/all the orgs. And both org's credential could pass the HTTP auth.


      We think this might be a bug? Any ideas on this please?