By default, users cannot use the REST API to just request data. But when you create a SPA, you want to enable this. So this is how.

  1. Go to App-Management / Query
  2. Add permissions by going through these steps:
    go to permissionsadd permissionsset view may read permissions