NumericDate in one minute
JWT time claims are NumericDate values: seconds (not milliseconds) since 1970-01-01T00:00:00Z. In JavaScript that is Math.floor(Date.now() / 1000); forgetting the division by 1000 creates tokens that expire in the year 58,000.
const now = Math.floor(Date.now() / 1000);
const payload = {
iat: now, // issued now
nbf: now, // valid immediately
exp: now + 60 * 60, // expires in 1 hour
};Choosing a lifetime
| Token | Typical lifetime |
|---|---|
| Access token | 5–60 minutes |
| ID token (OIDC) | 5 minutes – 1 hour |
| Service-to-service token | 1–5 minutes, minted per call or cached briefly |
| Email verification / password reset | 15 minutes – 24 hours, single use (jti) |
These are common conventions, not rules — choose based on how much damage a leaked token could do before it expires.
When to use nbf
nbf is useful for tokens issued ahead of time (scheduled access) and for testing “not yet valid” handling. For ordinary tokens, set it to the issue time or omit it.
Build a complete token with these values in the JWT encoder, or check an existing token's expiry with the JWT expiration checker.