Secrets and encoding

How to read the expiry claim in a JWT

A user is logged out and the token might be expired. Read the claim on JWT Decoder.

A JWT decode shows header and payload JSON. The signature is not checked, and exp is seconds.
exp, nbf, and iat are seconds, and a decode does not check the signature.

What to run

Open JWT Decoder, Unix Timestamp Converter, and Epoch Now. All three stay in the browser.

How to read the result

exp is seconds since the epoch, UTC. Convert it.

If Epoch Now is greater than exp, the token is expired by its own claim.

That still does not mean the signature was valid.

What to open next

Stop before claiming the token was accepted by the server. PageUtil cannot verify it.