Thanks for those screenshots @ahmadegbaria000 . It does appear that your /posts endpoint is allowing access, but I tested a number of other ones from your screenshot and all of those appear to be properly protected. /pages, /blocks, /shipping_company, etc
Is it possible that a theme or another plugin is stepping in and also modifying your REST API access? If you could send me a list of the plugins active on the site and what theme you’re using I would appreciate it, and in the meantime I’ll look at things on this end to see if I can find a bug in the code.
Thanks! Talk to you soon.