The process of building custom applications and tools that interact with Microsoft SharePoint, including SharePoint Online in Microsoft 365.
Based on the current Microsoft Graph documentation, your expectation appears to be correct.
Can you verify that the token used for the discardCheckout call is an application token (contains a roles claim) rather than a delegated token (contains an scp claim)?
Which application permissions have been granted to the app? According to the documentation, application access with permissions such as Files.ReadWrite.All or Sites.ReadWrite.All should be supported for this operation.
Have you tested the same scenario against both the /v1.0 and /beta endpoints, and if so, do they return the same error?