JSON Web Tokens are actually great, just not for sessions
kerkour.com
kerkour.com
If you issue a "reset" token embedded in an emailed link, when it's consumed the stored token can be invalidated/deleted, enforcing that the token really is single-use.
A JWT used for this still opens up the same problems as with auth: it's open to re-use, and can't be invalidated. Yes it can have a much shorter TTL, but there's still potential for it to be abused.
The only real valid use I see from the article, is to replace presigned URLs, simply because it could be a standardised thing in CDNs, rather than the completely random implementations that are used now.
Actions would be written to a database and a web page sent to the user, then the user would click something and a request would reach a web server, occasionally arriving before that server's database shard had seen the database write.
JWT passed the information via the user's browser, eliminating the race.
I think the JWT usage was in 2, but moving it to 1 would have presented the same problem, because in that case the mapping from user to backend would have to be coordinated for geographically dispersed load balancers, with the same timing constraints.
It would also be possible to use various techniques that add a delay to the user, such as avoiding anycast and having the client occasionally slow down while searching for a usable cluster.