Token/OAuth Access If Duplicacy Abandoned

Apologies if this is a dumb question as I don’t understand how OAuth/token credentials work, but I’m concerned about maintaining access to my backup years from now even if for some reason Duplicacy is abandoned. If I hold onto the downloaded Google Drive json token file, is that all I will need in the future to allow a different system to use the duplicacy cli executable to restore my backups or is there some interaction between duplicacy.com and Google Drive that could fail and prevent this (like a token refresh?) if duplicacy.com were no longer around? It seems like people consider the service account credential file to be more reliable or secure and I’m not sure why

If you can access your data on Google drive you can download or mount it with any other tool and configure duplicacy to use it as a local storage to restore.