Based on the data returned by /me, I'd expect it to work without any API key permissions, however after testing I've found it requires customers_read for some reason.