It's also a good way to identify who is making requests and allow you to make exceptions for some clients vs others.
I like public api's that provide access for non identified clients but they are throttled highly, versus clients who register to access a token.
And you can’t abuse the download in the same way?
If it's public data, people will "abuse" it just as well by requesting/scraping the website directly. In most cases it'll cost you more in resources when someone "abuses" the website as opposed to the API (as they'd typically make more requests and/or use more bandwidth on irrelevant things).