have you tried via Postman or similar tool so you can control exactly what headers are sent and see what the HTTP (error) response is. Browsers sometimes hide the details because they may already have cached tokens and default headers so it's hard to know what worked or not when using the browser.
That said, in my REST 'GET' tests with Postman, I had no headers (except the defaults that Postman adds (postman-token,cache-control) and it worked fine.