NotBeforeError: jwt not active (nbf claim in the future)
The token’s nbf (not before) time is in the future for the verifying server — usually clock skew between servers.
Seen on:
REST API
Meaning
If the issuer’s clock is ahead of the API server’s, freshly issued tokens look “not active yet”. Sync clocks (NTP) and allow a small clockTolerance.
Common causes
- Clock skew between issuer and verifier
- Container/VM clock drift
- Token deliberately issued with future nbf
⚡ Quick fix
- Sync server clocks with NTP
- Set clockTolerance (e.g. 30 s) in verification
- Check nbf vs server time
Detailed fix by platform
JavaScript
jwt.verify(token, key, { algorithms: ["RS256"], clockTolerance: 30 });
Linux
- bash
timedatectl status sudo timedatectl set-ntp true
How to diagnose
- Times — nbf vs server time (date -u)
- Clocks — NTP synced?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in Authentication
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026