The spec adds an "authorization_header" field in section 10.3.1.1 (SET Token Delivery Using HTTP Profile -> Stream Configuration Metadata -> Push Delivery Using HTTP). The description of this field is also ambiguous in that the words "if the configuration is present" doesn't clarify which configuration this is.
This language (in fact the whole section 10.3.1) should be reconciled with the Stream Configuration section.