Earlier quoted context omitted.
You can't plan for every contigency, but you can reserve potentially scary message for situations where you know they are correct. An unpected error state should NOT result in a "invalid credentialiald error".
This is the nature of credentials errors. The more information you give, the more you're telling an untrusted and therefore assumed-hostile agent. I hate it because it's bad UX, but that's the thinking behind it.
The argument here is the kind of nonsense cargo cult security that pervades the industry.