The token includes the time when it was created (iat attribute) so critical actions could check that the token is less than 3 minutes old.