For security reasons you should always have the authentication information stored in a separate, secure file. Call the file using "require". If this is a cgi script then the authentication file should be stored outside of the webserver's document tree. You don't want to give anyone the chance to read it.