JWT expiration time builder

Stop calculating Unix timestamps by hand. Choose “1 hour from now”, an exact date, or a raw timestamp and get the exact exp, nbf and iat values — in local time and UTC.

Loading…

NumericDate in one minute

JWT time claims are NumericDate values: seconds (not milliseconds) since 1970-01-01T00:00:00Z. In JavaScript that is Math.floor(Date.now() / 1000); forgetting the division by 1000 creates tokens that expire in the year 58,000.

const now = Math.floor(Date.now() / 1000);
const payload = {
  iat: now,             // issued now
  nbf: now,             // valid immediately
  exp: now + 60 * 60,   // expires in 1 hour
};

Choosing a lifetime

TokenTypical lifetime
Access token5–60 minutes
ID token (OIDC)5 minutes – 1 hour
Service-to-service token1–5 minutes, minted per call or cached briefly
Email verification / password reset15 minutes – 24 hours, single use (jti)

These are common conventions, not rules — choose based on how much damage a leaked token could do before it expires.

When to use nbf

nbf is useful for tokens issued ahead of time (scheduled access) and for testing “not yet valid” handling. For ordinary tokens, set it to the issue time or omit it.

Build a complete token with these values in the JWT encoder, or check an existing token's expiry with the JWT expiration checker.