
Entries containing sensitive data like API keys, passwords, tokens, etc. should be masked (e.g. shown as ••••••••), with a button to toggle between masked and plain text. Pasting into fields should work correctly even when the text is masked.
This prevents accidental exposure of secrets when browsing through entries during screen sharing or while working with colleagues at the same desk.