I think I understand now what you are trying to do. The durable functions API uses a different authentication system, though it is fairly consistent- that's why there is no function key for that API.
With traditional functions, in order to use AAD auth instead of keys you need to enable the AAD provider on the App Service level and then set the individual function to "anonymous" access. As long as app service auth is turned on this won't open it to the public- it just stops it from requiring a key. If you were to turn on App Service auth and leave the default function settings on then you would need both AAD permission and the function key.