Plain HTTP sends everything (tokens, data) in the clear, readable by anyone on the network. HTTPS wraps HTTP in TLS to encrypt the connection, authenticate the server, and detect tampering. Modern auth (bearer tokens, OAuth, clipboard, geolocation) requires a secure context. There is no acceptable reason to run a production API over plain HTTP.