Skip to content
FlexibleToolsAI
Security Toolkit · 100% Client-Side Private

JWT Expiration Checker

Find out instantly whether a JSON Web Token is still valid. Paste it to see a live countdown to expiry, the issued-at and not-before times as readable dates, the token's total lifetime, and a converter for Unix timestamps.

Paste a JWT and the checker decodes its exp (expiration), iat (issued at) and nbf (not before) claims, converts them from Unix seconds to your local time and UTC, and shows whether the token is valid, expired or not yet valid — updating every second. It doesn't verify the signature; use the JWT Signature Verifier for that.

Unix timestamp ⇄ date

JWT times (exp, iat, nbf) are seconds since 1 January 1970 UTC. Now: …

Zero Server Uploads

Files process in local RAM

Instant WASM Speed

No waiting queues or lags

Unlimited Batching

Convert files without limits

Suggest a Feature or Improvement for JWT Expiration Checker

Need custom options, higher limits, or extra format support? Let our engineering team know!

How to use JWT Expiration Checker

  1. 1Paste the JWT.
  2. 2Read the status and time remaining.
  3. 3Check each time claim in local time and UTC.
  4. 4Use the converter to create exp values for testing.

JWT time claims

exp, iat and nbf are NumericDate values: seconds since 1 January 1970 UTC (RFC 7519). A common bug is setting them in milliseconds, which makes a token look valid for thousands of years — the checker detects that.

Servers usually allow a small clock-skew leeway (30–60 seconds) when checking exp and nbf.

How long should tokens live?

Access tokens typically last 5–60 minutes, with longer-lived refresh tokens stored securely to get new ones. Tokens without exp stay valid forever if stolen. Create tokens with a set lifetime in the JWT Generator.

Frequently Asked Questions

Why does my token say expired when it just worked?

Check your computer's clock and time zone — expiry is compared with your device's current time. Servers may also allow a little leeway.

Does it validate the signature?

No. It only reads the time claims. Use the JWT Signature Verifier to check the signature.

Is my data sent to your server?

No. This tool runs entirely in your browser using the Web Crypto API and JavaScript. Nothing you type or generate is uploaded, logged or stored.

Guides & Tutorials

Related Tools