How does the Personal Data reporting API work? Authentication? Who calls it?

Hi - having issues implementing auth on this API with Connect, as detailed here Personal data reporting API returning 401 (Connect + JWT)
Any insights on what may be the cause ?