It comes down to whether the OAuth token generated by their client is used only in their client.
If you register a new OAuth client and generate access tokens for it to call the API, then you are following the rules.