What does “JWT expired” mean?
For a JWT with an exp (expiration time) claim, the token must not be accepted at or after that time. exp is a NumericDate: the number of seconds since 1970-01-01 00:00:00 UTC, not milliseconds. A server returning “JWT expired” is commonly telling you that its current time has reached the token's exp value. The exact error text depends on the library.
{
"sub": "user-123",
"iat": 1760000000,
"exp": 1760003600
}
In this illustrative payload, exp - iat = 3600 seconds, so the intended lifetime is one hour. The payload alone cannot prove when the server issued the token or whether its signature is valid. RFC 7519, section 4.1.4 defines exp and permits a small leeway for clock skew.
Diagnose the error
- Inspect a safe test token. The JWT Decoder reads
exp,iat, andnbfin your browser. It does not verify a signature, issuer, audience, or revocation. Do not paste a live bearer token into screenshots, tickets, or shared logs. - Read
expas seconds. Convert it with the Unix Timestamp tool. JavaScript'sDateconstructor expects milliseconds, so usenew Date(exp * 1000)rather thannew Date(exp). - Check server time. A server clock that is ahead can reject a token early. Synchronize clocks; allow only a small, deliberate skew in the verifier. Do not extend leeway enough to hide a broken clock.
- Check which token you sent. An old access token may remain in a cache, cookie, or retry queue after a new one has been issued. Also confirm that you are not sending a refresh token to an API expecting an access token.
- Check related claims.
nbfmeans “not before”;iatis issue time. A token can be unexpired yet invalid because its signature, issuer, audience, ornbfcheck fails.
What should the application do?
When an access token expires, obtain a new one using your provider's supported refresh or sign-in flow, then retry only as your application permits. A refresh token is a separate sensitive credential with its own expiry and rotation rules; some providers do not issue one. A user who has lost the session may need to sign in again.
Do not edit exp in the token payload. That changes the signed bytes and should fail signature validation. Do not disable expiration checking to get past the error. On the server, validate the token using a trusted library and the expected algorithm, key, issuer, audience, and time claims. On the client, plan to refresh before a short-lived access token expires when your provider supports it.
For another frequent JWT rejection, see how to fix an audience mismatch. For the difference between reading and validating a JWT, see Understanding JWT Tokens.