An exact expiration boundary with a matching signature
Bad input: An otherwise correctly signed HS256 token has exp = 1700000000. The verification clock is also 1700000000 Unix seconds.
Failure: The HMAC still matches, but the token has expired: the required condition is current time < exp, not current time <= exp. In contrast, nbf = current time meets the not-before condition.
Fix: Keep the signature result separate from time-policy checks. Request a newly issued token after expiration; editing exp inside the old token invalidates its signature.