From c1e0461b90a7f062eabfd03e4143c50cbab55c48 Mon Sep 17 00:00:00 2001
From: Toasterkitten
Date: Wed, 16 Sep 2026 16:53:13 -0400
Subject: [PATCH] tampermonkey
---
grab.user.js | 28 ++++++++++++++++++++++
index.html | 65 ++++++++++++++++++++++++++++++----------------------
2 files changed, 65 insertions(+), 28 deletions(-)
create mode 100644 grab.user.js
diff --git a/grab.user.js b/grab.user.js
new file mode 100644
index 0000000..cfee03e
--- /dev/null
+++ b/grab.user.js
@@ -0,0 +1,28 @@
+// ==UserScript==
+// @name Notaquest Token Grabber
+// @namespace https://notaquest.owendeed.com
+// @version 1.0
+// @description One-click Meta token grabber for Notaquest
+// @match https://secure.oculus.com/*
+// @match https://notaquest.owendeed.com/*
+// @grant GM_setValue
+// @grant GM_getValue
+// @run-at document-idle
+// ==/UserScript==
+
+if (GM_getValue("used")) return;
+if (location.hostname === "notaquest.owendeed.com") {
+ if (!location.search.includes("token=")) {
+ window.location.href = "https://secure.oculus.com/";
+ }
+ return;
+}
+
+if (location.hostname === "secure.oculus.com") {
+ var html = document.documentElement.innerHTML;
+ var match = html.match(/"accessToken":"(OC[A-Za-z0-9+\/=]+)"/);
+ if (match) {
+ GM_setValue("used", true);
+ window.location.href = "https://notaquest.owendeed.com/?token=" + match[1];
+ }
+}
\ No newline at end of file
diff --git a/index.html b/index.html
index 16289be..88d7fb0 100644
--- a/index.html
+++ b/index.html
@@ -54,10 +54,15 @@
still made it a quest for me to make this work for you, and it's gonna
suck, but it'll suck less than the normal way. i have uploaded 2 images
of forks for meta verification, i will update this message if it works
- and i can do oauth. you need to use devtools and grab a cookie. i'm very
- sorry. this seems to work better on mobile than on pc. tested on android
- with google chrome. you may need to quickly accept a pairing
- confirmation on the device and headset. firefox is not supported :(
+ and i can do oauth. update: it did not. you can use the tampermonkey
+ script to automate it or use devtools and grab a cookie. i'm very sorry.
+ this seems to work better on mobile than on pc. tested on android with
+ google chrome. you may need to quickly accept a pairing confirmation on
+ the device and headset. the tampermonkey script cannot be ran on Android
+ Chrome since it doesn't support extensions. you can use firefox for it
+ and swap to Chrome later, use a browser that supports bluetooth and
+ extensions, or do it on a pc first and swap later. firefox is not
+ supported for bluetooth :(
i apologize for you having to give me the token, this isn't something
@@ -90,12 +95,6 @@
program, if i change it, it will change.
-
- why does this site look ancient?
-
- this site is a one time tool, there's no point to make it look good.
-
- what is the point?
@@ -113,29 +112,39 @@
but i can't access devtools on my phone!
- yeah. here's the best fix for that i can come up with for now. (check
- back later if you really can't do this, once i get oauth it will be
- much simpler). at the bottom click the generate token qr code button.
+ do the tampermonkey script on firefox/a browser on mobile with
+ extension support and swap to one with bluetooth after! or do the
+ following if you can do devtools on a pc but don't wanna do
+ tampermonkey: at the bottom click the generate token qr code button.
this will give you a qr code. scan it on your phone and go to the
link. it will be prefilled with your token so you don't need to type
it :)