We may or may not be able to reuse/extend the existing `host` strategy. It might be that we can just add auth headers to it, but we need to verify.