If you have thousands, you end up spending a lot of time on key distribution if you need individually distributed secret keys.
If you have thousands, you end up spending a lot of time on key distribution if you need individually distributed secret keys.
What you get is that the peer can't forge tokens. But you're trying to authenticate to them; they already have full authority. So what are you fixing? (I'm not saying it's "nothing", but I am saying it's very little, and it's definitely plausible the increased risk isn't worth it.)
What do you mean by "tiers" here? The specificity of that word suggest you don't just mean "peers", but at the same time clearly symmetric systems win at nested delegation. (krb5, macaroons come to mind)
You get something you can show to a third party: 'see, the bank said their client was good for $10,000!' I can see where that might be useful.