This looks like it could be an instance of this problem:
I have ran into issues on my own gateways where a deployment mode is set before I create the API Key. Usually the way I solve this is creating the key in the core collection (or whatever collection you've defined the additional security levels read permissions in) and then editing and assigning it roles after creation.