I am confused to what are the requirements to accessing this API.
Let's say I have a team called `Team-A` and I have a `Group` called `Group-A`.
`Group-A` has the following settings

I added `John` as a member to `Group-A` and added `Group-A` to have access to `Repo-A`. When `John` tries to access this API, he'll get 403 Forbidden.
If I change the team permissions of `Group-A` to allow `Create repositories`, `John` can access this API without a problem.
Is this intended?
* `John` is using Implicit OAuth with `account:read / write` enabled.
Thanks.