Skip to content
Tool4SaaS
HomeAboutContactBlog
Tool4SaaS

185 fast, local utilities for developers and creators. No sign-ups — most tools run in your browser (see /privacy).

hello@tool4saas.com

Categories

  • Text & Documents

  • Business & Writing

  • Developer Tools

  • Converters

  • Generators

  • Images & Design

  • PDF Tools

  • Calculators

  • Finance & Money

  • Health & Fitness

  • SEO & Marketing

  • Time & Date

Popular Tools

  • Invoice Generator

  • QR Code Generator

  • Word Counter

  • Password Generator

  • JSON Formatter

  • Mortgage Calculator

  • EMI Calculator

  • SIP Calculator

  • View all tools →

Company

  • All Tools

  • About Us

  • Author

  • Methodology

  • Blog

  • Contact Us

Guides

  • Invoice Generator Guide

  • QR Code Generator Guide

  • Resume Builder Guide

  • Mortgage Calculator Guide

  • Password Generator Guide

  • Word Counter Guide

  • llms.txt (for AI)

© 2026 Tool4SaaS. All rights reserved.

  • Privacy Policy

  • ·
  • Terms of Service

  • ·
  • ·
  1. Home
  2. /
  3. Blog
  4. /
  5. Developer Guide
  6. /
  7. Check JWT Expiry Without Trusting the Token

Check JWT Expiry Without Trusting the Token

JWT expiry checks: exp/iat/aud/iss table, alg:none kill rule + decode-vs-verify discipline with redaction habits. Free local decoder.

By Tool4SaaS Editorial Team · Published 2026-10-07 · Updated 2026-10-07 · 3 min read

Try it now — JWT Decoder, free in your browser

Decode JSON Web Tokens safely · No signup · No watermark · Free forever.

Open JWT Decoder →
On this page
  • Claims table
  • Kill alg:none
  • Decode vs verify

Staging worked, production rejected every token. Diffing the two JWTs showed identical structure — except exp: staging tokens lived 24 hours, production 15 minutes, and the reviewer's clock ran 4 minutes slow. Three lessons in one outage: decode shows claims, expiry decides, and clocks lie. This guide teaches checking exp/iat, audience, and the alg:none kill-switch — decoding plus verification, in that order, without ever trusting a token you only read.

Part of the developer toolkit guide. Inspect in the JWT decoder (redact before screenshots); convert epochs in the timestamp converter.

Read claims: exp, iat, aud, iss

ClaimMeansCheck
expExpiry epoch secondsexp: 1717252800 past = dead, no exceptions
iatIssued-atFuture iat means clock skew or forgery
audIntended audienceMust equal your service ID exactly
issIssuerMust equal your IdP, character-for-character
subSubject user IDOpaque string like 123, not an email to trust blindly

Convert exp in the timestamp converter — epoch integers hide “expired 2 hours ago” behind inscrutable digits. Allow ~30 seconds clock skew (sync NTP on all parties); beyond that, fix clocks, not tolerances.

Kill alg:none on sight

An unsigned token with {"alg":"none"} verifies against nothing — any attacker mints admin claims in seconds. History is littered with libraries that accepted it during algorithm-confusion attacks (attacker swaps RS256→HS256, signs with the public key as HMAC secret). Rules: reject none unconditionally, pin expected algorithms server-side, fetch signing keys only from the IdP's published JWKS over HTTPS. Client-side decoding can display alg; only the backend decides. If your decoder ever shows none on a production token, treat it as an incident, not a curiosity.

Decode ≠ verify (the two-step discipline)

  1. Decode (client-safe): paste into the decoder, read claims, check expiry/audience/issuer visually. Catches 80% of integration bugs (wrong env, stale token, clock skew).
  2. Verify (backend only): signature against IdP keys, algorithm allowlist, expiry enforcement, audience match — every request, no caching of verdicts.
  3. Redact before sharing: tokens in screenshots, tickets and logs leak sessions. Redact signature segments, rotate exposed tokens immediately.

Staging-vs-production mismatches (24h vs 15min lifetimes, different aud) cause most “works here, fails there” mysteries — diff the decoded claims side by side before touching code. Full flag/claim drills in regex groups for log correlation and Base64 modes for segment decoding.

General guidance only, not a security audit. Token architectures for regulated data need professional review.

Related free tools

Timestamp Converter →Base64 Encode / Decode →

Frequently asked questions

Decode and compare exp epoch seconds like 1717252800 against now, allowing about 30 seconds clock skew with NTP synced. Past exp means dead with no exceptions regardless of signature appearance. Convert inscrutable integers in the timestamp converter to reveal expired-two-hours-ago status, then diff staging versus production lifetimes.

Never in production since unsigned tokens with alg none verify against nothing and enable trivial forgery in seconds. Reject unconditionally, pin expected algorithms server-side, and fetch signing keys only from the IdP published JWKS over HTTPS. If a decoder shows none on production tokens, treat it as an incident.

No, since decoding only displays claims while backend signature verification against IdP keys authorizes. Client-safe decoding catches 80% of integration bugs like wrong environment, stale tokens and clock skew. Every request still needs algorithm allowlists plus expiry, audience and issuer enforcement without caching verdicts for secure authentication workflows.

Usually different lifetimes like 24 hours versus 15 minutes, mismatched audiences, or clock skew up to four minutes. Diff decoded claims side by side before touching code, checking exp, aud and iss character-for-character. Sync NTP on all parties rather than widening tolerances beyond 30 seconds.

Only redacted since tokens in screenshots, tickets and logs leak sessions immediately. Redact signature segments, rotate any exposed token immediately, and verify audience and issuer visually before sharing. Remember decoding never authorizes — only backend verification against IdP keys with algorithm checks permits access for safe debugging practices.

Done reading — open the JWT Decoder

Decode JSON Web Tokens safely — free in your browser, no signup.

Open JWT Decoder →

Keep reading in this guide

Pillar guide

Debug API Responses Locally: JSON, Base64, JWT, Regex Guide

In this silo

Why JSON.parse Fails: Trailing Commas and Quotes

In this silo

Base64 URL-Safe vs Standard: Padding and Modes

In this silo

Regex Flags and Capture Groups That Work