Use an API token with the read scope. An administrator creates one with whatbreaks-api token create.
read
whatbreaks-api token create