User:BDavis (WMF)/Notes/Recover OAuth secret

It is possible to recover a lost OAuth secret key if you have production database and deployment configuration access. This isn't a quick process, so it's not widely advertised.

First, get the  from the metawiki database for the consumer:

Then get the $wgOAuthSecretKey value that is being used on the production cluster:

Finally compute the SHA1 HMAC of the consumer secret and the cluster secret:

Gergő suggests a more direct alternative: