What sort of permissions should there be for the browsable API? Docs: https://www.django-rest-framework.org/tutorial/4-authentication-and-permissions/ https://www.django-rest-framework.org/api-guide/permissions/