At AAM, we take WordPress security seriously. We believe that exposing REST API endpoints to users who don’t have access to them is both unnecessary and potentially risky. That’s why we’ve made a deliberate decision not to register AAM-specific RESTful API endpoints for unauthorized users or visitors.
As a result, you won’t see the aam/v2 namespace listed for users who lack the necessary permissions to use AAM functionality.

If needed, you can override this default behavior by defining the AAM_FORCE_REST_API_REGISTER constant in your wp-config.php file. This will force the registration of AAM’s RESTful API regardless of user access:
define('AAM_FORCE_REST_API_REGISTER', true);