By default, users cannot use the REST API to just request data. But when you create a JavaScript application like a SPA, you want to enable this.
Prerequisite: you are on a permissions dialog of data/query/app etc.
- Hit add-permission
- Create the permission by adding a nice name, selecting View as a Requirement (so it will only work if users are on the DNN website) and setting the Grant to read.