By default, users cannot use the REST API to just request data. But when you create a SPA, you want to enable this. So this is how.

  1. Go to App-Management / Data
  2. On the content-type, hit permissions: go to permissions
  3. Configure read-access for people on the DNN site