Discussion posts and replies are publicly visible
Couple of things to check
1. Have you configured API key properly in your request body.
2. And is SSO enabled in target environment? If yes make sure the user is not part of SAML group as it shouldn't authenticate using SSO.