Playground API
DocsStatsBlogStudio
Documentation Tree
Technical BlogFeature Deep Dives
  • Introduction
  • Quickstart
    5 min
  • How It Works
  • Recipes & Cookbooks
  • Platform Comparisons
  • Real-World Showcase
  • Interactive Studio
    Studio
  • GraphiQL IDE
    IDE
  • Session Quotas & Activity
  • Network Chaos Simulator
  • Atomic Sandbox Reset
  • Overview & Models
    Hub
  • Users Resource
  • Posts Resource
  • Comments Resource
  • Todos Resource
  • Custom Collections
    Custom
  • Multipart File Uploads
    Upload
  • Dynamic SVG Avatars
    SVG
  • Image Thumbnails
    CDN
  • Relational Filtering
  • Full-Text Search
  • Dynamic Sorting
  • Offset Pagination
  • Cursor Pagination
    Scroll
  • CSV & Excel Export & Import
    IO
  • Custom Collections
    CRUD
  • Overview & Architecture
    Hub
  • JWT Auth Flow
  • Refresh Token Rotation
    Mutex
  • RBAC Permission Matrix
    Roles
  • Expiry Simulation
  • Clock Skew Drift
  • Password Recovery Loop
  • Dual-Mode Sandboxing
  • GraphiQL IDE
    IDE
  • Relational Queries
  • Stateful Mutations
  • Realtime Subscriptions
  • Overview & Flowcharts
    Hub
  • Hosted Checkout
    Stripe
  • Payment Intents API
  • 3DS Challenge Modal
    Modal
  • Customers Vault
  • Charges & Refunds
  • Test Cards Catalog
  • Overview & Channels
    Hub
  • Virtual Email Mailbox
    Mailtrap
  • Virtual SMS Terminal
    Phone
  • In-App Notifications
  • Message Dispatcher
  • Realtime Studio
    Studio
  • Native WebSocket (/ws)
  • Socket.io Gateway
  • Presence & Echo Bot
  • Server-Sent Events (SSE)
    SSE
  • Analytics Telemetry
  • Webhook Subscriptions
  • HMAC SHA-256 Signatures
  • Delivery Logs
  • Manual Retry Simulator
  • Network Latency Delay
  • HTTP Status Codes
  • Rate-Limit Simulator
    429
  • Flaky Network & Jitter
    Chaos
  • Session Quotas & Activity
  • JSON Snapshots
    JSON
  • Headless CI/CD Testing
    CI
  • Mobile QR Code Sync
  • System Metrics & Health
  • Atomic Sandbox Reset
  • Official TypeScript SDK
  • Multi-Language Generators
  • DevTools Extension
  • OpenAPI 3.1 Spec
    JSON
  • Postman Collection v2.1
  • Bruno Collection
  • Insomnia Workspace
  • TypeScript .d.ts
    .d.ts
  • AI Prompt Rules
    Rules
  • Context Index (llms.txt)
  • Full Schema (llms-full.txt)
  • Manifest (product.json)
  • All Feature Articles
    Blog
  • React CRUD Without Backend
    Deep Dive
  • Why Static APIs Fail
  • Mocking Stateful Auth
  • WebSockets & SSE Guide
Technical Blog
Articles

In-depth articles explaining stateful mock APIs, WebSockets, payments, and frontend resilience.

Read Articles
PreviousExpiry Simulation
NextPassword Recovery Loop
Auth & Security

Clock Skew Drift & Leeway Tolerances

Simulate device time desynchronization across distributed client devices and backend cloud clusters. Inject positive or negative clock drift using the X-Simulate-Clock-Skew header to test token leeway configurations.

Interactive Clock Drift Simulator

Select a drift offset below to inject time distortion into the token issuance engine:

Simulate Clock Skew: +120s

POST
response.json
1
{
2
// Click "Send" above to execute this request against the live server.
3
}

Why Test Clock Drift?

Real-world failure modes caused by NTP drift on mobile devices and distributed edge nodes:

01

Not-Before (nbf) Rejection

If client time lags behind the server, tokens generated by the server appear to be issued in the future, triggering premature token rejection errors.

02

False-Positive Expirations

If a client device clock is ahead by just 30 seconds, a 1-minute access token will prematurely appear expired to the client before the server rejects it.

03

Leeway Tolerance Cushion

Configuring a 60-second clock tolerance window in token verification libraries cleanly absorbs clock skew without weakening overall token security.

Leeway Configuration Recipes

How to configure clock tolerance across modern JWT verification libraries:

jwtVerifyWithLeeway.ts
1
// Node.js jsonwebtoken with Clock Tolerance Leeway
2
import jwt from 'jsonwebtoken';
3
4
const JWT_SECRET = process.env.JWT_SECRET || 'your_secret_salt_here';
5
6
export function verifyTokenWithLeeway(token: string) {
7
try {
8
const decoded = jwt.verify(token, JWT_SECRET, {
9
algorithms: ['HS256'],
10
// Absorb clock discrepancies up to 60 seconds (prevents nbf and premature exp errors)
11
clockTolerance: 60, // 60 seconds leeway
12
});
13
return decoded;
14
} catch (err: any) {
15
if (err.name === 'NotBeforeError') {
16
console.error('Clock skew detected: Token used before issuance timestamp (nbf)');
17
} else if (err.name === 'TokenExpiredError') {
18
console.error('Token expired:', err.expiredAt);
19
}
20
throw err;
21
}
22
}