JWT expiry checker
One question, answered instantly: is this token expired, and if not, how long is left? The countdown ticks live from your device clock.
Guide
How to use it
- Paste the token from your header, cookie or debugger.
- Read the badge and the expires tile: the countdown updates every second.
- issued (iat) and not before (nbf) tiles appear when the token carries them, useful for spotting clock skew.
- Need the full payload too? Use the main decoder.
Examples
Worked examples
Users report being logged out every 15 minutes. The token shows exp exactly 15 minutes after iat: the issuer's token lifetime setting, not a bug in your app.
Grab the token before and after a refresh call. If the second one's countdown restarted, the refresh worked; if the exp is identical, you were handed the same token back.
A vendor integration token shows NO EXPIRY CLAIM. Worth raising: a leaked token with no exp stays live until someone notices and revokes it.
Method
How it works
The payload segment is base64url-decoded locally and the registered time claims read out: exp compared against your device clock gives the verdict and the live countdown. No signature check is attempted, so the verdict means "what the token claims about time", the same first check a server makes before the cryptography.
Nothing you paste leaves the page. Built by Wolds Cyber.
FAQ
Frequently asked questions
How do I know when my JWT expires?
The exp claim in the payload is a Unix timestamp. Paste the token here and it is translated into your local time with a live countdown, updating every second.
Why did my token expire so quickly?
Access tokens are commonly minted for 5 to 60 minutes on purpose: a short life limits the damage of a leak. The refresh token, exchanged behind the scenes, is the long-lived one.
Can I extend a token's expiry?
No. exp is inside the signed content, so changing it breaks the signature. The only way to a later expiry is asking the issuer for a new token.
What if there is no exp claim at all?
Then the token never expires by itself, which the checker flags. Long-lived tokens are a real risk if leaked, so issuers should always set exp.
My token says valid but the server disagrees. Why?
Servers reject tokens for more than time: bad signature, wrong audience, missing scopes or a revocation list. Time claims are just the first, cheapest check.
Does the countdown send my token anywhere?
No. The token is decoded once in your browser and the countdown is computed from your device clock. Nothing is transmitted.
More tools