Disable HTTPS-based Services (except REST API)

It’s not public-facing. I typically disable all web-based access to a router. I need the REST API for some automation work that I’m doing, but don’t like that I have to open additional (and unnecessary) attack vectors to accomplish this.