I've seen many SPAs with totally unauthenticated API endpoints. They'll control what a user's allowed to do with the UI and hide unauthorized functionality, but direct requests to the backend still allow any request.
The thing to keep in mind is: don't trust the client. The final word on authentication and authorization should always be done server-side.