In either case the server authenticates with TLS and PKI.
But for APIs, the client (usually) authorizes with tokens. And for webhooks, the client (usually) authorizes with signed requests.
---
You could just as easily imagine API authorization with signed requests (e.g. AWS). Or webhook authorization with tokens (e.g. JIRA can do this).
Or where either one uses mTLS (e.g. CMS HETS).
That's not how it's usually done.
But the client-server requirements for confidentiality and authenticity are the same. The only difference is who is the "client" and who is the "server."