Point --remote_cache at the bare host and Bazel appends the rest itself, reading and writing both the action cache and the content-addressable store.
It is the same workspace token as every other protocol, and a read-only token is rejected on writes to both stores.