currently, we would have to hard code the headers and there is no dynamic way of passing the tokens to the external api's.
and the token has to be passed in the url which can be exposed to vulnerabilities.
I suggest please include this as soon as possible.