The README currently states that the admin JWT is set via an environment variable. However, in practice, the admin JWT is generated by a hidden API endpoint at /jwt/create. This discrepancy can cause confusion for users and developers trying to configure or use the system.