Yes, one header
Yes, more than one header
No
Your app is either an API or a traditional web app.
If you have a reliable token that will not be invalidated during the scan then this is probably your best option to use.