Hello Shaked Eyal
Greetings!
In an inbound NSG rule, the source virtual network service tag includes peered VNET IP ranges, while the destination virtual network service tag includes current VNET IP ranges.
For an outbound NSG rule, the source virtual network service tag includes current VNET IP ranges, and the destination virtual network service tag includes peered VNET IP ranges.
And also check the below link to find the IP ranges for service tag:
Azure IP Ranges and Service Tags
Regarding your API management to fetch the IP ranges, please check the link below for more information:
Hope the above answer helps! Please let us know do you have any further queries.
Please do consider to “up-vote” wherever the information provided helps you, this can be beneficial to other community members.