You keep saying that but unless company start doing KYC there's absolutely no link between auth and ToS.
The authentication mechanisms used by websites don't have a specific legal power, it's just a POST request among other GET requests sent during scraping. And we have jurisprudence saying scrapping is legal no matter what the ToS of the website says, because the scraping entity never signed up the contract.
The only protection against scrapping that auth is giving you isn't a legal one, it's a technical one (you can detect and ban the scraping user account).
*scraping