A password, API key, or token assigned a literal string embeds a secret in source code.
Load secrets from secure storage or environment configuration, never from source literals.