That doesn't sound like an amazingly safe idea
Upstream can easily f-up and (accidentally) delete production data if you do this on a live db. Which is why PostgreSQL and nearly all other DBS have a miriad of tools to solve this by not doing it directly on a production database
What if someone screws up the zip and instead of 10000 today, it’s only 10?
In either the solution is probably to check rough counts and error if not reasonable.
which wouldn't exist if the api is simply just a single CSV file?
at least with a zip, the CRC exists (an incomplete zip file is detectable, an incomplete, but syntactically correct CSV file is not)