VSThiran

How to check if a JWT is expired

Quick answer

Paste the token into the JWT Expiry Calculator - it reads the "exp" claim (a Unix timestamp) and shows a plain status (Valid, Expired, or Not yet valid), the exact date and time in your time zone and UTC, and a live countdown, so there is no timestamp math to do by hand.

Free, no sign-up, and your file is read on your own device rather than uploaded.

Tokens are commonly issued with short lifetimes - anywhere from a few minutes to a few hours - specifically so a stolen or leaked token stops being useful quickly. Seeing an authentication error does not automatically mean something is broken; it often just means the token needs refreshing or the user needs to sign in again.

The expiry lives in the payload as the "exp" claim, a Unix timestamp. Reading it directly as a raw number is not very useful - converting it to an actual date and comparing it to now is what actually answers the question.

Step by step

  1. Paste the token

    The JWT Expiry Calculator decodes it and reads iat, nbf and exp directly - no signature or secret needed just to check timing.

    JWT Expiry Calculator
  2. Read the status

    Valid, Expired, or Not yet valid, plus the exact date/time and a live countdown - no manual timestamp math.

    JWT Expiry Calculator

Tips

  • Not every JWT has an "exp" claim at all - some are issued without an expiry, particularly for long-lived API keys, though this is increasingly considered poor practice for anything security-sensitive.
  • A token can be structurally valid and unexpired but still fail signature verification if it was tampered with, or if the server rotated its signing key - expiry is only one of several reasons a token can be rejected.

Common problems

A request fails with a 401 shortly after login.

Check the token's exp claim against the current time - a very short expiry combined with a slow request or clock drift between client and server can cause this.

The token looks unexpired but is still rejected.

Expiry is not the only check a server performs - signature validity, issuer and audience claims can all cause a rejection even on a token that has not technically expired yet.

Frequently asked questions

What format is the exp claim in?
A Unix timestamp - the number of seconds since January 1st, 1970 UTC, the same format used throughout JWT's standard time-related claims (iat, nbf, exp).
What happens after a token expires?
A server checking expiry correctly will reject it, typically with a 401 response - the usual next step is refreshing the token or signing in again.

Related related tools

Related articles

Ready to do it?

Free, no sign-up, and nothing is uploaded to a server.