Another factor: anonymous faceted regex search across a huge volume of code allows bad actors to find hardcoded credentials and gain access to additional systems, without a good audit trail.
But yes, there are multiple good explanations for why they would lock down the API.