{ }jsonkitOpen
Tokens, auth and security

Registered claims (exp, iss, aud)

Also called Reserved claims, JWT registered claims

Registered claims are the standard JWT claim names defined in RFC 7519: iss (issuer), sub (subject), aud (audience), exp (expiration time), nbf (not before), iat (issued at) and jti (JWT ID). The jti claim is a unique ID for one token, used to block replays or revoke that token. Check exp, iss and aud on every request, or expired and misdirected tokens will pass.

In more detail

Registered claims are the claim names RFC 7519 reserves in a JSON Web Token payload. None of them is required by the spec, but libraries and identity providers rely on them, so use them for their defined meaning.

iss (issuer) names who created the token. sub (subject) names who it is about, usually a user ID. aud (audience) names who it is for. exp (expiration time), nbf (not before) and iat (issued at) are NumericDate values, which means Unix timestamps in seconds.

jti (JWT ID) is a unique identifier for one token. A server can store used jti values to reject a replayed token, or put a jti on a deny list to revoke one token before it expires.

Decoding a JWT only reads these claims. A server must still verify the signature, then check exp, nbf, iss and aud on every request. Otherwise an expired token, or one issued for another service, is accepted.

Example

A JWT payload with all seven registered claimsjson
{
  "iss": "https://auth.example.com",
  "sub": "usr_8x42",
  "aud": "api.example.com",
  "exp": 1783497600,
  "nbf": 1783494000,
  "iat": 1783494000,
  "jti": "5f2b8c1e-9d4a-4c6e-8b1f-2a7d3e9c0f41"
}

Try it

Learn more in the guide Understanding JWTs: structure, claims and verification.

← Back to Registered claims (exp, iss, aud) in the JSON glossaryUpdated 2026-10-01