Missing Authorization in CORS headers of Cloud API

I haven't tried it, but according to the docs, the PUT request for Flashing a binary via the cloud API accepts an ?access_token= as part of the URI.

Or am I missing something?