I wondered about the version number in the URL; but when I add that, I
get the same error. I also removed the token secret from the request

Where would I set the permissions on the API key? I'm not familiar
with that process. In any case, my own scripts were just passing the
keys I had copied and pasted from my Twitter account, so that approach
should still work, right?

In my requests (which are generated by the oauth-php library) I
noticed that the signature line is a single value followed by an
encoded ampersand. Is that correct, for the specified authentication


