right now we put the thin auth api key in the url - but ideally we support custom domains, or sub-domains.
One idea I had to support this is we can add "authDomain" to tenants, then for certain requests rather than requiring apiKey we can instead read the request domain and do a tenant lookup that way.
There may be other / better solutions as well.