It sounds like the actual demo site didn't actually interact with the registration system at all. He mentions "fake" classes. That's what he wanted the API token for; that would have allowed him to actually make the site function, and he (falsely) assumed that the documentation meant the university was open to the idea.
So while it sounds like his site would almost certainly wound up violating policy had it gone live _it never did so_. That's a pretty good reason for them to deny the API request (which seems like may have not been intended for the public anyway?) But it does not in any way seem to merit the threat of expulsion, or, even worse, the fact that (according to the student in an update), even though he immediately complied they still put a hold on his account anyways.
There is some nuance here for sure, but I do not see in any way that the universities response is proportional to what actually happened.