Reading — step 1 of 5
Read
~1 min readClaims & Validation
Standard Claim Validation
After signature verifies, validate the CLAIMS:
| Claim | Validation |
|---|---|
exp | current_time < exp. Else: token expired |
nbf | current_time >= nbf. Else: not yet valid |
iat | usually informational; reject if too old |
iss | match expected issuer |
aud | this server's identifier MUST be in audience |
jti | check against blacklist (revoked tokens) |
python
The leeway parameter (typically 30s-5min) handles clock skew between issuer and verifier. Without it, a JWT issued at 12:00:00 with exp=12:05:00 would be rejected at 12:05:00.001 by a slightly-fast verifier.
Discussion
Ask a question, share an insight, or help someone who’s stuck.
Sign in to post a comment or reply.
Loading…