If it was a password entered into a form would you still consider it protected by obscurity? Both are the same level of security.
It's not impossible that someone sees the URL, and if it's stored in an email the backups or local clients could store it plaintext, but I don't see how the URL is any more likely than the password to be sniffed during the connection itself