Sure, it’s a crime for the bots, but it would also be a crime for the ordinary users that you want to access the website.
Or if you make it clear that they’re allowed, I’m not sure you can stop the bots then.
Or if you make it clear that they’re allowed, I’m not sure you can stop the bots then.
The (theoretical) scenario is: There is a website (example.com) that publishes the correct credentials, and tells users to go to example.com/authenticate and put those there.
At no point is a user (or bot) bypassing anything that was meant to stop them, they're following what the website is telling them publicly.