API management is what sits between your API and its consumers, handling the concerns every API has regardless of what it does: identifying consumers through keys or tokens, enforcing rate limits and quotas, applying plans and pricing, collecting analytics, and providing the developer portal and documentation people actually interact with.
Without it you have an endpoint. With it you have a business — a way to onboard consumers, control access, understand usage, and connect consumption to value.
Whether you need a platform is a genuinely open question now. For most of the API era, management was a single product category you bought whole. It has since unbundled: the gateway is often separate from the portal, which is separate from analytics, which is separate from the catalog, which is separate from governance. Plenty of teams assemble these from cloud primitives and open source and are fine.
The framing I would hold onto is that management is about awareness and control over your digital resources. Whatever you buy or build, ask whether you end up knowing who is calling what, how much, at what cost, under which terms — and whether you can change any of that without a deploy. If the answer is yes, the shape of the tooling matters much less than the vendors would like you to believe.