403 for custom route & API token

Tried it - ticked the box, no change.

Wouldn’t have thought this would be the solution since a) user authentication is done via providers, not explicit token, and b) Users + Permissions is a plugin, while API tokens are part of core admin package