The 401 error when accessing a sitemap is “fine” as this is Main UI determining whether authentication token is required.
I can reproduce your issue when disabling implicit user role in API security settings. This is a different issue, but now that I can reproduce it is easy to fix (the fix took me 10 minutes):