Authentication2026-09-29

JWT Expired: What the exp Claim Means and How to Fix It

Understand JWT exp timestamps, clock skew, refresh flows, and expired-token errors without confusing decoded claims with signature validation.

jwtexptoken-expiredoauthauthentication

What does “JWT expired” mean?

For a JWT with an exp (expiration time) claim, the token must not be accepted at or after that time. exp is a NumericDate: the number of seconds since 1970-01-01 00:00:00 UTC, not milliseconds. A server returning “JWT expired” is commonly telling you that its current time has reached the token's exp value. The exact error text depends on the library.

{
  "sub": "user-123",
  "iat": 1760000000,
  "exp": 1760003600
}

In this illustrative payload, exp - iat = 3600 seconds, so the intended lifetime is one hour. The payload alone cannot prove when the server issued the token or whether its signature is valid. RFC 7519, section 4.1.4 defines exp and permits a small leeway for clock skew.

Diagnose the error

  1. Inspect a safe test token. The JWT Decoder reads exp, iat, and nbf in your browser. It does not verify a signature, issuer, audience, or revocation. Do not paste a live bearer token into screenshots, tickets, or shared logs.
  2. Read exp as seconds. Convert it with the Unix Timestamp tool. JavaScript's Date constructor expects milliseconds, so use new Date(exp * 1000) rather than new Date(exp).
  3. Check server time. A server clock that is ahead can reject a token early. Synchronize clocks; allow only a small, deliberate skew in the verifier. Do not extend leeway enough to hide a broken clock.
  4. Check which token you sent. An old access token may remain in a cache, cookie, or retry queue after a new one has been issued. Also confirm that you are not sending a refresh token to an API expecting an access token.
  5. Check related claims. nbf means “not before”; iat is issue time. A token can be unexpired yet invalid because its signature, issuer, audience, or nbf check fails.

What should the application do?

When an access token expires, obtain a new one using your provider's supported refresh or sign-in flow, then retry only as your application permits. A refresh token is a separate sensitive credential with its own expiry and rotation rules; some providers do not issue one. A user who has lost the session may need to sign in again.

Do not edit exp in the token payload. That changes the signed bytes and should fail signature validation. Do not disable expiration checking to get past the error. On the server, validate the token using a trusted library and the expected algorithm, key, issuer, audience, and time claims. On the client, plan to refresh before a short-lived access token expires when your provider supports it.

For another frequent JWT rejection, see how to fix an audience mismatch. For the difference between reading and validating a JWT, see Understanding JWT Tokens.