Skip to the tool

JWT expiry checker

One question, answered instantly: is this token expired, and if not, how long is left? The countdown ticks live from your device clock.

Guide

How to use it

  1. Paste the token from your header, cookie or debugger.
  2. Read the badge and the expires tile: the countdown updates every second.
  3. issued (iat) and not before (nbf) tiles appear when the token carries them, useful for spotting clock skew.
  4. Need the full payload too? Use the main decoder.

Examples

Worked examples

Debugging a flaky session

Users report being logged out every 15 minutes. The token shows exp exactly 15 minutes after iat: the issuer's token lifetime setting, not a bug in your app.

Is the refresh working?

Grab the token before and after a refresh call. If the second one's countdown restarted, the refresh worked; if the exp is identical, you were handed the same token back.

The forever token

A vendor integration token shows NO EXPIRY CLAIM. Worth raising: a leaked token with no exp stays live until someone notices and revokes it.

Method

How it works

The payload segment is base64url-decoded locally and the registered time claims read out: exp compared against your device clock gives the verdict and the live countdown. No signature check is attempted, so the verdict means "what the token claims about time", the same first check a server makes before the cryptography.

Nothing you paste leaves the page. Built by Wolds Cyber.

FAQ

Frequently asked questions

How do I know when my JWT expires?

The exp claim in the payload is a Unix timestamp. Paste the token here and it is translated into your local time with a live countdown, updating every second.

Why did my token expire so quickly?

Access tokens are commonly minted for 5 to 60 minutes on purpose: a short life limits the damage of a leak. The refresh token, exchanged behind the scenes, is the long-lived one.

Can I extend a token's expiry?

No. exp is inside the signed content, so changing it breaks the signature. The only way to a later expiry is asking the issuer for a new token.

What if there is no exp claim at all?

Then the token never expires by itself, which the checker flags. Long-lived tokens are a real risk if leaked, so issuers should always set exp.

My token says valid but the server disagrees. Why?

Servers reject tokens for more than time: bad signature, wrong audience, missing scopes or a revocation list. Time claims are just the first, cheapest check.

Does the countdown send my token anywhere?

No. The token is decoded once in your browser and the countdown is computed from your device clock. Nothing is transmitted.

More tools

Related tools

JWT decoderThe full header, payload and claims table. What is a JWT?The plain-English explainer, with the decoder embedded. Hash generatorMore local-only inspection tools for developers.
Skip to the tool

JWT expiry checker

One question, answered instantly: is this token expired, and if not, how long is left? The countdown ticks live from your device clock.

Decode only.

The signature is NOT verified, so treat the contents as claims, not facts. The token never leaves your browser.

Paste a token to read its header and payload.

Everything runs in your browser. Tokens are decoded on your device and never transmitted or logged.

Guide

How to use it

  1. Paste the token from your header, cookie or debugger.
  2. Read the badge and the expires tile: the countdown updates every second.
  3. issued (iat) and not before (nbf) tiles appear when the token carries them, useful for spotting clock skew.
  4. Need the full payload too? Use the main decoder.

Examples

Worked examples

Debugging a flaky session

Users report being logged out every 15 minutes. The token shows exp exactly 15 minutes after iat: the issuer's token lifetime setting, not a bug in your app.

Is the refresh working?

Grab the token before and after a refresh call. If the second one's countdown restarted, the refresh worked; if the exp is identical, you were handed the same token back.

The forever token

A vendor integration token shows NO EXPIRY CLAIM. Worth raising: a leaked token with no exp stays live until someone notices and revokes it.

Method

How it works

The payload segment is base64url-decoded locally and the registered time claims read out: exp compared against your device clock gives the verdict and the live countdown. No signature check is attempted, so the verdict means "what the token claims about time", the same first check a server makes before the cryptography.

Nothing you paste leaves the page. Built by Wolds Cyber.

FAQ

Frequently asked questions

How do I know when my JWT expires?

The exp claim in the payload is a Unix timestamp. Paste the token here and it is translated into your local time with a live countdown, updating every second.

Why did my token expire so quickly?

Access tokens are commonly minted for 5 to 60 minutes on purpose: a short life limits the damage of a leak. The refresh token, exchanged behind the scenes, is the long-lived one.

Can I extend a token's expiry?

No. exp is inside the signed content, so changing it breaks the signature. The only way to a later expiry is asking the issuer for a new token.

What if there is no exp claim at all?

Then the token never expires by itself, which the checker flags. Long-lived tokens are a real risk if leaked, so issuers should always set exp.

My token says valid but the server disagrees. Why?

Servers reject tokens for more than time: bad signature, wrong audience, missing scopes or a revocation list. Time claims are just the first, cheapest check.

Does the countdown send my token anywhere?

No. The token is decoded once in your browser and the countdown is computed from your device clock. Nothing is transmitted.

More tools

Related tools