Because they have a lot of complexity that, for a code they runs a part of auth logic, is really dangerous.
For example, verification of third party Macaroons requires building a directed graph, that needs cycle detection. No implementation that I've checked does this instead allowing only one level of nesting.
Third party caveats have more problems, if a third party would issue them they need to be standardized but there is no such standard. Worse, even the underlying byte format is not standardized instead there is this de facto standard of using "variable op value" format. But what variables are supported? It needs to be specified or the third party macaroon would be invalid.
If we talk about byte formats Macaroons are serialized using another custom format. Compare this with base64 and JSON used by JWT.
Then there are certain "programming shortcuts" in implementations [0].
I've spent some time implementing Javascript library to build and verify Macaroons from the paper (that is also inconsistent with the de facto implementations) but ultimately I've decided to just use limited subset of JWT. It's just simpler.
[0]: https://github.com/nitram509/macaroons.js/blob/master/lib/Cr...