According to the documentation,
API Gateway selects the route with the most-specific match, using the following priorities:
1. Full match for a route and method.
2. Match for a route and method with a greedy path variable ({proxy+}).
3. The $default route.
And our API Gateway looks like this:

I would expect this to go to the /auth lambda function:
curl -X POST --data @auth.json https://XYZ.execute-api.us-west-2.amazonaws.com/MY-stage/auth
But instead, the request is being intercepted by the /{entity} lambda function.
Any idea what could be wrong?