I have faced this recently and adding "Use Any API Client" permission set has solved the problem. Latest documentation to check if your org has API whitelisting: https://help.salesforce.com/s/articleView?id=sf.security_api_access_control_all_users.htm&type=5