Basic JWT token vulnerability, if you supply none in the alg field, it doesn’t verify the signature.
none
alg
Flag: S1gn4tuR3_v3r1f1c4t10N_1S_1MP0Rt4n7
S1gn4tuR3_v3r1f1c4t10N_1S_1MP0Rt4n7