Invalid credentials when hitting the /userinfo endpoint

I could replicate this problem while having a rule modifying the scope claim of the access token of the open id token. When I disabled the rule everything started working again. This was not happening yesterday and I don’t see any other feasible explanation besides a change in Auth0 code since nothing changed on my rule code or lock config. Maybe you were doing something similar in a rule?