Arguably that was done, if I remember the architecture well… the company had a rule against SPoFs, so there were ① several load balancers at different sites, with ② several clusters of servers behind them, and ③ several backends supplying data to the servers.
I think the JWT usage was in 2, but moving it to 1 would have presented the same problem, because in that case the mapping from user to backend would have to be coordinated for geographically dispersed load balancers, with the same timing constraints.
It would also be possible to use various techniques that add a delay to the user, such as avoiding anycast and having the client occasionally slow down while searching for a usable cluster.