X-Robots rules in netlify.toml are not adhered

Does this still hold true?

Redirects and Headers specified in netlify.toml are site-wide and cannot be configured specifically for some contexts.

Then, why is it working for the basic auth, but not for x-robots?