exp — Expiration Time
Location: payload · Format: timestamp
Unix epoch seconds after which the token must be rejected. A very common decoder bug is treating this value as milliseconds (e.g. from Date.now()) instead of seconds, which pushes the apparent expiry thousands of years into the future; verifiers should also allow only a small, bounded clock-skew leeway (commonly ~60s), never an unlimited one.
Defined in RFC 7519 §4.1.4.
Decode a JWT and inspect its exp claim in the TokenPrism debugger — free, entirely in your browser.