They broke most federated auth scenarios with ITP, so there needs to be a way for auth to flow between websites in a way that allows users to consent and control it. The logged in API basically takes your auth state (to a first estimate) out of the 3rd party cookies and into the browser. The browser then understands when to reinject them. Ad networks lose tracking via 3p cookies, but you stay logged in to your accounts.