Yeah I would love to find a way to support non-JS browsers. For now I considered it out of scope. I could very easily make a browser extension or companion app for it though!
My suggestion is that if the script fails (for whatever reason, including non-JS browsers), then in addition to doing what they said (spits out some token), should also link to documentation about how to compute the response. If the user has a program to do it, they can use that one. If not, they might be able to write their own (by following the documentation).