You can store the expiry time in the token itself. Then it is up to your server to validate that the token is still live. If you need to mass invalidate every token, you change the signing key.
So is there any way to do single-sign-out if using these tokens for authentication?