so if you load the homepage and you aren't logged in, you do get 403 on some apis, thats normal, not an issue there. But if you try logging in and then try building an app, and stuff don't work - thats an issue we need to debug and fix.
The way allowed_email thing is so that the platform you deploy, only you would be able to access unless you clone the repo locally, make changes in env vars and redeploy. This is for security so others won't start abusing your deployement.
Whatever email you put in there, you would have to sign up and login via that email