I think you hugely over-estimate the importance of “developer APIs” to the number of bots on twitter.
You’re never going to really fully defeat browser automation or HTTP request playback with automatically generated payloads. No one technically needs an API if a web interface exists to automate something. It’s easier with an official API sure, but not super hard without.
Indeed, a truly malicious bot farm would avoid the API altogether and just fake web client requests to look as much like the real thing as possible. Anyone can capture the HTTP messages with just a computer and an open source MITM proxy to decrypt and inspect the SSL message contents for recreating in a bot script or application.