How-to · Updated October 2, 2026
How does clock skew affect JWT expiry?
Direct answer
The token is expired when now ≥ exp + skew. A 15-minute token with exp 1735690500 and 60 seconds of skew stays active until 1735690560 (2025-01-01T00:16:00Z).
The 60-second boundary
iat 1735689600 (2025-01-01T00:00:00Z) plus 15 minutes is exp 1735690500 (2025-01-01T00:15:00Z). Skew is 60 seconds.
| Server time | UNIX now | Status |
|---|---|---|
| At exp | 1735690500 | Active |
| 59 seconds after exp | 1735690559 | Active |
| 60 seconds after exp | 1735690560 | Expired |
Same token, different skew
| Skew | Reject at | UTC |
|---|---|---|
| 0 seconds | 1735690500 | 2025-01-01T00:15:00Z |
| 30 seconds | 1735690530 | 2025-01-01T00:15:30Z |
| 60 seconds | 1735690560 | 2025-01-01T00:16:00Z |
| 300 seconds | 1735690800 | 2025-01-01T00:20:00Z |
Limits
- This matches the calculator’s comparison: expired when now is at least exp plus skew. Signature checks are separate.
- Sixty seconds is the default tolerance. It covers small clock drift between services.
- Skew does not replace a short access-token lifetime. It only moves the rejection instant later.
Use the calculator
Building exp from iat: how to calculate a JWT expiration time. Set the skew in the JWT expiry time calculator.