If you issue a "reset" token embedded in an emailed link, when it's consumed the stored token can be invalidated/deleted, enforcing that the token really is single-use.
A JWT used for this still opens up the same problems as with auth: it's open to re-use, and can't be invalidated. Yes it can have a much shorter TTL, but there's still potential for it to be abused.
The only real valid use I see from the article, is to replace presigned URLs, simply because it could be a standardised thing in CDNs, rather than the completely random implementations that are used now.