A service token is not end-user authorization
A service-to-service token proves which machine called your API. It does not prove which human may see or change a specific resource.
If an internal worker calls GET /invoices/4821 with a service JWT,
authbyexample.hashnode.dev1 min read