Rating:

TLDR: Use github to find open API endpoint that signs tokens. Change JWT identity to admin, sign token, and recieve flag.

Original writeup (https://jaquiez.github.io/Blog/UMASSCTF2022/#AutoFlag).