Restriction when enabling/disabling rewards via API request

Correct.

No as thats not what the scope granted access to

The scope (manage channel rewards) on the API only lets you manage rewards that the ClientID created.

The dashboard ClientID != the ClientID you used

And the “owner” of the ClientID is irrelevant (as thats not how oAuth works)
There are not “permissions” between a ClientID and the owner of the ClientID