1. Log in to get a token. Crack its HS256 secret offline against the provided wordlist.txt (recompute the signature for each candidate until it matches). The secret is secret123. Why: HMAC security depends entirely on an unguessable key; a dictionary word is brute-forceable.
2. Forge a new token with {"user":"you","admin":true} signed with the cracked secret. Run solve.py to do this automatically.
3. Set it as the jwt cookie and open /admin for the flag.
Lesson: use long, random, high-entropy signing keys; rotate and store securely.