Thanks again. I’ve addressed both issues:
Sorting on percent-encoded key is mentioned. I refrained from describing your algorithm, though, as sorting on the intermediate string will take the “=” character into account for the sort, which I believe is incorrect (and may lead to some subtle error in a few cases). I’ve put in a note about secondary sort, but that shouldn’t apply to Twitter API requests. Hopefully you’ll find the updated text to be suitable.
Percent encoding the consumer key and secret are now mentioned as well. I do believe that this won’t be an issue, but it’s best to be rigorous here.
Thanks for catching these!