Technology & Developers
JWT Expiry Calculator
Decode a JWT’s time claims to see when it was issued, when it becomes valid, when it expires and how long it has left.
Free to useNo sign-up requiredNo watermarkRuns in your browser
A “401 token expired” error usually comes down to three numbers inside the token: iat (issued at), nbf (not before) and exp (expires). They are Unix timestamps in seconds, which are hard to read at a glance. This calculator decodes the token and shows each one as a date and time in your time zone and in UTC.
It also shows how old the token is, how long it has left (updating every second), its total lifetime and a clear status, with an optional clock-skew allowance like the leeway most JWT libraries apply. It does not verify the signature: a token can look valid here and still be forged. For HMAC signature checks, use the JWT Decoder.
How this tool works
Paste the token
Paste the JWT, or a whole “Bearer …” header value - the prefix is removed.
Set a clock-skew allowance
Optional. Enter the leeway your verifier uses, in seconds, e.g. 60.
Read the status
Valid by time, Expired, Not yet valid (nbf) or No exp claim, with the time left or elapsed.
Check the claim dates
Compare iat, nbf and exp in local time and UTC, plus the token’s total lifetime.
How it works
The token is split at its dots. The header and payload are base64url-decoded as UTF-8 and parsed as JSON; any problem - the wrong number of segments, invalid base64url, or a segment that is not JSON - is reported in words.
iat, nbf and exp are NumericDate values: seconds since 1 January 1970 UTC. Each is converted to a date in your browser’s time zone and in UTC. A value that looks like milliseconds, or a string instead of a number, is flagged, because many libraries mis-handle or reject those.
Status follows RFC 7519: a token is expired once the current time reaches exp plus the skew allowance, and not yet valid while the current time is before nbf minus the allowance. The signature is never checked, so the status is about time only.
Common use cases
- Working out why an API returns 401 “token expired” or “token not yet valid”.
- Checking the lifetime your identity provider actually issues for access and ID tokens.
- Converting exp and iat timestamps into readable dates in your time zone and in UTC.
- Testing refresh logic by seeing exactly when a token will expire.
- Spotting clock drift between servers with a clock-skew allowance.
JWT registered time claims
| exp (Expiration Time) | Must not be accepted on or after this time |
|---|---|
| nbf (Not Before) | Must not be accepted before this time |
| iat (Issued At) | When the token was issued; used for age checks |
| iss (Issuer) | Who issued the token |
| sub (Subject) | Who the token is about, e.g. a user ID |
| aud (Audience) | Who the token is intended for |
| jti (JWT ID) | Unique ID, used to prevent replay |
Decoded is not verified
Anyone can create a JWT with any claims - the payload is only base64url-encoded, not encrypted. What makes a token trustworthy is its signature, checked by your server with the right key and a fixed list of allowed algorithms. Tokens with alg "none" are unsigned and should always be rejected.
Formula
Time until expiry
exp − now
Negative once expired; shown as time since expiry.
Token age
now − iat
Total lifetime
exp − iat
Expired when
now ≥ exp + skew
Not yet valid when
now < nbf − skew
Worked examples
A one-hour access token
iat 1,800,000,000 and exp 1,800,003,600 give a lifetime of 3,600 seconds (1 hour). Checked 50 minutes after issue, it is valid by time with 10 minutes left.
Expired by a few seconds
A token that expired 20 seconds ago is Expired with no allowance, but valid by time with a 60-second clock-skew allowance - which is why two servers can disagree about the same token.
Frequently asked questions
Does this tool verify the JWT signature?
No. It decodes the token and analyses its time claims only. A decoded token is not proof that it is authentic. The JWT Decoder on this site can verify HMAC (HS256/384/512) signatures with a shared secret.
What units are exp, iat and nbf in?
Seconds since 1 January 1970 UTC (Unix time), called NumericDate in the JWT specification. If a value is in milliseconds, the date will be tens of thousands of years in the future - this tool flags that.
What is clock skew?
Servers’ clocks are never perfectly in sync, so verifiers usually allow some leeway - commonly 30 to 300 seconds - when checking exp and nbf. Enter your verifier’s leeway to see the status it would give.
What if the token has no exp claim?
Then it never expires by time. The specification allows that, but many APIs reject such tokens, and a leaked one stays usable until the signing key is rotated or it is otherwise revoked.
Is my token sent anywhere?
No. Your token is processed locally in your browser and is not uploaded. Even so, treat production tokens like passwords.
