I think it’s tough to stop them because, as you said, they use keys as logins. However, since they operate through an API, maybe clients could limit them by analyzing metadata from the requests and combining it with a specific tag in the posts, like you suggested.
With new challenges, I’m hopeful that clients will evolve to address these issues!