It seems a request is made to http://congon4tor.com:7777 to fetch the flag after the OTP check is successful. We could skip the check and directly fetch the URL ourselves.
We can successfully obtain the flag using the Bearer token included in the source code.
GET /flag HTTP/1.1Host:congon4tor.com:7777Authorization:Bearer KMGQ0YTYgIMTk5Mjc2NzZY4OMjJlNzAC0WU2DgiYzE41ZDwNConnection:close