No way to do this in vCenter 6.5.
For 6.7 the user must be in "SSO->Groups->Administrators" to create a valid API session and run some GET commands.
This answers my OP.
The user is not able to Create/Modify/Delete local users even though they have the vCenter Appliance Role 'superAdmin'.
Cannot perform these actions through the API or UI.
The UI is unavailable if they don't have permissions in the vCenter Object. I have to manually add them to a different role defined at that location.
Those are separate issues and I'll start a new thread.
Appliance Role, Object Role, and SSO Groups, does this confuse anyone else?