ZITADEL doesn't support anonymous clients. Honestly, it's not the best practice anyway.
As for Forward Auth, the concept can be a bit fuzzy, and from what I gather, ZITADEL doesn't really support that.
Trusted Header Auth might work in some scenarios, but that definition is also a bit fuzzy, so hard to say for sure.