jwt not active 🔐 Authentication

NotBeforeError: jwt not active (nbf claim in the future)

The token’s nbf (not before) time is in the future for the verifying server — usually clock skew between servers.

Seen on: REST API

Meaning

If the issuer’s clock is ahead of the API server’s, freshly issued tokens look “not active yet”. Sync clocks (NTP) and allow a small clockTolerance.

Common causes

  • Clock skew between issuer and verifier
  • Container/VM clock drift
  • Token deliberately issued with future nbf

⚡ Quick fix

  1. Sync server clocks with NTP
  2. Set clockTolerance (e.g. 30 s) in verification
  3. Check nbf vs server time

Detailed fix by platform

JavaScript

  1. jwt.verify(token, key, { algorithms: ["RS256"], clockTolerance: 30 });

Linux

  1. bash
    timedatectl status
    sudo timedatectl set-ntp true

How to diagnose

  1. Times — nbf vs server time (date -u)
  2. Clocks — NTP synced?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.