"unauthorized users". They are authorized if they are trying to control their own garage door. The company I work for has a policy where we don't block third party clients, as long as they use a uniquely identifiable user agent and API key that we provide to them. That way we can easily monitor if they're calling endpoints excessively and make sure that our alarms don't go off when they did something wrong, but still…
Chamberlain doesn't get to authorize people to open your door, but they do get to decide who uses their API. While I think it's a very poor decision, they certainly can decide that any use of their API they don't like is unauthorized. That said, I would love to see legislation that ends this kind of vendor lock-in.