The inventory bucket is currently private and requires some special IAM permissions to read from
The manifests are essentially just all the same content you can get by doing s5cmd ls on the entire bucket, which also shows all embargoed blobs/zarrs, so there is likely no reason that the manifests need to stay hidden