jwt challenge if the jwt using weak secret, you can brute it or in this case it allows hmac, if you have a private key, you can use it