Switched off header-checking by page-rule, but still get rejected



I’ve switched everything off that I can think of, but I still get my API call rejected due to header-checks:
The owner of this website (blabla.blala.io) has banned your access based on your browser’s signature (49eb3623fe5fc83d-ua21).


Optimized it somewhat by adding the /* to the pagerule:


Under the Firewall tab, check your Firewall Rules, IP Access Rules and User Agent Blocking.


Also completely off:


And under the WAF tab, I have also switched off the browser integrity check:

