Auth via headers instead of query param

