Context
After registering as a trainer, looking at profile page
Behaviour Seen
At the bottom of the page, there is a section:
Authentication token
(keep it secret)
string of tokens
The string of letter/numbers/symbols was in plain text.
I wasn't expecting to see this, and could easily accidentally share if I hadn't noticed.
Possible behaviour
Having the string of tokens dealt with as "click to reveal" or "click to show/hide" or hidden and "click to copy" would perhaps be a better option - to avoid accidental screenshot sharing.
(I think you could argue this both in favour / against.)