"Generated token is too large" on some user profiles, but not others

Can you share the exact Lock config you use on your SPA to perform the authentication request so that I test under the same conditions? The reason I ask is that although the length of the access token you mention is somewhat significant it’s strange to hit the limit just because of that and I confess that I read it like both tokens were being issued and to be honest that would be the most simple explanation.