Each system API has its own settings. Without settings, a system API is NO_ACCESS : your code calls it through g.sys, the admin panel tests it, and an HTTP call is refused with 401. The token API is the exception : public unless its settings say otherwise.
Page
API Info → System API → the plus button of the API.
Open only what applications really need : execute plain query, get secret, create indexes and the cache resets change or reveal a lot. The APIs Security Report lists the sensitive ones which are open.