Get records with API object-based and user token

Trying to get records after logging the user in with the user token with:

var axios = require('axios'); 

var config = {
method: 'get',
url: '',
headers: {
'X-Knack-Application-Id': 'XXXXXX',
'Authorization': 'XXX.XXX.XXX'
} };

function (response) {
}).catch(function (error) {

This returns the first level of objects, however when I change the URL to:

It returns:

Unauthorized Object Access

How I can receive the object/records with only user token and APP ID and not using API key?

Do it like this:
url: rates_url,
type: 'GET',
headers: {
'Authorization': Knack.getUserToken(),
'X-Knack-Application-ID': Knack.application_id,
'Content-Type': 'application/json',
'Access-Control-Allow-Origin': ''