The API server must be given the corresponding public key to verify the tokens using `--service-account-key-file`
Those tokens are automatically mounted into pods if you enable the ServiceAccount admission plugin.