JWT Expiration Checker
Check whether a JWT is expired, not yet valid, or still inside its exp window. Time claims only — the signature is not verified.
What exp, nbf, and iat tell you
Paste a JWT and this page reads the time claims. exp is the moment after which the token is expired. nbf is the moment before which it must not be accepted. iat is when it was issued. Times are shown in UTC and in your local timezone. The example token uses a fixed exp in 2018, so it checks as expired.
JWT NumericDate values are seconds since the Unix epoch. JavaScript's Date.now() is milliseconds. If exp is a string, or a number large enough to be milliseconds, the checker reports it instead of converting it. A token with no exp has no expiration to check.
To read the header and payload, use the JWT Decoder. Paste that JSON into the JSON Formatter when you want it indented. Neither tool verifies the signature.
Common questions
What do exp, nbf, and iat mean?
exp is the expiration time. After that instant, the token should be rejected. nbf means not before, so the token should be rejected until that instant. iat is the issued-at time. All three are NumericDate values in seconds.
Are JWT times in seconds or milliseconds?
Seconds. A 13-digit exp is usually a JavaScript millisecond timestamp. This checker does not divide by 1000. A string such as "1700000000" is also rejected, because NumericDate is a JSON number.
What about clock skew?
Servers often allow a small leeway, commonly a minute or two, because the issuer's clock and the verifier's clock differ. This page compares the claims with your browser clock and applies no leeway. A token shown as just expired can still be accepted by a server that allows skew.
Why does a server reject an expired token?
exp is the time after which the token must not be accepted. A valid signature does not extend that lifetime. Once exp has passed, the server should reject the token and the client should get a new one.
Does an unexpired token mean it is genuine?
No. Anyone can write an exp in the future. This page only reads the time claims. Trust the token only after your server verifies the signature.