By default, users cannot use the REST API to just request data. But when you create a JavaScript application like a SPA, you want to enable this. 

Prerequisite: you are on a permissions dialog of data/query/app etc.

  1. Hit add-permission add permissions
  2. Create the permission by adding a nice name, selecting View as a Requirement (so it will only work if users are on the DNN website) and setting the Grant to read
    set view may read permissions