While I realize that it's typically going to be an administrator who is in the area of SMS account setup, I think the Auth Token field should be masked just like we mask the password field for e-mail setup. Otherwise, anyone poking around could see that information.