This API should be publicly accessible without requiring a valid token to access, it artificially limits the domain of the API to impersonation tokens. The documentation page itself masks this requirement as you only enter the token to validate, not realising to access the site itself requires a valid token which is transparently passed along with the API request itself.