JWT time-claim review

Review JWT exp, iat, nbf, seconds, and milliseconds

JWT expiry decisions depend on the claim names, their seconds-versus-milliseconds unit, and the receiver's clock skew. Review synthetic cases and save notes.

Review time claims

JWT time claim review

Only synthetic cases are used. JWTs, secrets, and signatures are not sent, saved, or verified.

Boundaries to check

  • exp is expiry, iat is issued-at, and nbf is not-before.
  • JWT NumericDate is normally seconds; a 13-digit value may be milliseconds.
  • Confirm the receiver's clock-skew contract and never treat this as signature verification.