Just putting my thoughts
1. As these pages are behind authentication,AEM always look for a valid login-token for allowing the page to render.
2. You may write something (a placeholder component can trigger a servlet ) to generate a valid token whenever you identify a special request header or user...