At work we just implemented some M2M auth using JWT[1]. The other party requires a full certificate chain as our identification and RS256 as algorithm, so our "compact" tokens end up around 8k in size.
At least the auth token we get back lasts a couple of minutes.
[1]: https://difi.github.io/felleslosninger/maskinporten_protocol...