Passing HTTP headers for @lambda

Yes, this behavior is correct. I don’t think there is a way to avoid this behavior at the moment, the graphql() function carries forth your existing auth headers. You can entirely bypass auth by making dql queries from lambda