If I remember right, you simply create a new user and password and set permissions on the documents as you need either for that user or for a new group. The permissions on the document(s) will allow/disallow the REST user from querying documents or nodes they shouldn't be.
You might read up on REST Authentication and the different methods to authenticate.