Nobody has ever improved their situation by hitting an API count target. The number is an output, not a goal, and organizations that chase it end up with a catalog full of endpoints nobody calls.
The questions that actually matter are the inventory questions. How many APIs exist right now, including the ones a team stood up on a cloud account three years ago and forgot? Who owns each one? What data does it expose? Who is calling it, and how much? Which ones are duplicates of each other? Which ones are in production with no test, no contract, and no named owner?
Almost no large organization can answer these without doing the work, and doing the work is the single highest-value governance activity available to most of them. You cannot govern what you are not aware of. Every downstream activity — policy, risk, compliance, deprecation, consolidation, cost control — depends on first knowing what exists.
So the right target is not a number of APIs. It is complete coverage: every API in the estate discovered, owned, described by a machine-readable contract, and accounted for. Get that, and the question of how many you should have answers itself, mostly by revealing how many you should retire.