I guess I am confused. I use ValetforTesla, granted it runs on my Mac, but I do not give anything other than token generated through an API call via a script, npx generate-tesla-token [1] ; after a NPM install through terminal. So yeah, its not official, but its open enough to know what it does
there are sites out there which claim security to generate tokens for you but I am not going to even begin to suggest them.
[1] https://github.com/ELLIOTTCABLE/generate-tesla-token