JWT expired token debug guide for API clients
exp marks token expiry; nbf and iat bound validity. Clients must refresh before expiry; servers must reject stale tokens. Debug with decoded claims, not guesswork.
Common causes
- No refresh flow on 401.
- Clock skew between issuer and verifier.
- Long-lived tokens cached past rotation.
How to fix
- Inspect exp/iat/nbf with JWT Decoder and Auth Token Expiry Checker.
- Refresh proactively at 80% lifetime.
- Sync NTP on servers.
Use our tool
Check token expiryRelated