How-to · Updated October 2, 2026
How do you calculate a JWT expiration time?
Direct answer
exp = iat + TTL in seconds. Issued at 1735689600 (2025-01-01T00:00:00Z), a 15-minute token expires at 1735690500 (2025-01-01T00:15:00Z).
Same iat, different lifetimes
iat 1735689600 is 2025-01-01T00:00:00Z. The exp column is that instant plus the TTL.
| TTL | Seconds | exp | UTC |
|---|---|---|---|
| 15 minutes | 900 | 1735690500 | 2025-01-01T00:15:00Z |
| 1 hour | 3,600 | 1735693200 | 2025-01-01T01:00:00Z |
| 8 hours | 28,800 | 1735718400 | 2025-01-01T08:00:00Z |
| 1 day | 86,400 | 1735776000 | 2025-01-02T00:00:00Z |
| 7 days | 604,800 | 1736294400 | 2025-01-08T00:00:00Z |
Seven days is 7d (604,800 seconds), past the calculator’s 24-hour line. A lifetime under 300 seconds is the short band.
Limits
- This is expiration arithmetic. It does not decode a token or check a signature. Use a JWT library for verification.
- A leaked long-lived token stays usable until exp. Access tokens in the 5–30 minute range are the usual pattern, with a separate refresh token.
- One day is exactly 86,400 seconds. The calculator treats a TTL as long-lived only when it is greater than 86,400 seconds.
Use the calculator
The extra window after exp: how JWT clock skew affects expiry. Enter iat and a TTL in the JWT expiry time calculator.