> if they can be seen, by the latter of the law, to be falsifying their identity (by using someone else's) to gain access to a resource, then there may be a case for them to be charged with fraud.
Where "impersonation" is part of the protocol no deception is involved, so this shouldn't affect such APIs. In fact in those cases it is not really impersonation, it is acting on behalf of, presumably by prior agreement (or similar by words that are a bit less anthropomorphic).
You've just made quite a few APIs illegal.