It can help with rate limiting and preventing abuse.
If it's public data, people will "abuse" it just as well by requesting/scraping the website directly. In most cases it'll cost you more in resources when someone "abuses" the website as opposed to the API (as they'd typically make more requests and/or use more bandwidth on irrelevant things).
It's also a good way to identify who is making requests and allow you to make exceptions for some clients vs others.
I like public api's that provide access for non identified clients but they are throttled highly, versus clients who register to access a token.
And you can’t abuse the download in the same way?
That’s what I was thinking. So the download is open, but the API is restricted? Then the comparison is obviously not about the API but about the restrictions.