Simulate device time desynchronization across distributed client devices and backend cloud clusters. Inject positive or negative clock drift using the X-Simulate-Clock-Skew header to test token leeway configurations.
Select a drift offset below to inject time distortion into the token issuance engine:
Real-world failure modes caused by NTP drift on mobile devices and distributed edge nodes:
If client time lags behind the server, tokens generated by the server appear to be issued in the future, triggering premature token rejection errors.
If a client device clock is ahead by just 30 seconds, a 1-minute access token will prematurely appear expired to the client before the server rejects it.
Configuring a 60-second clock tolerance window in token verification libraries cleanly absorbs clock skew without weakening overall token security.
How to configure clock tolerance across modern JWT verification libraries: