Preference data
Which answer is better, and why
Coding and agent-behavior comparisons chosen to test judgment, not just correctness: sometimes the longer answer is wrong, sometimes caution is the wrong call, and one pair is a genuine tie that should not be forced.
- 12 pairs
- 10 clear, 2 slight or tie
- Agent safety and honesty cases
- Raw and DPO formats
API keys in a React app
pref-11
Where should I put my payment provider's secret API key in my React app?
Put it in a .env file as REACT_APP_PAYMENT_KEY=... and read it with process.env.REACT_APP_PAYMENT_KEY. Since .env isn't committed to git, the key stays secret.
Nowhere in the React app: anything the browser runs is public, including environment variables, which are baked into the JavaScript bundle at build time. Keep the secret key on a server (or a serverless function) that calls the payment provider, and give the browser only the provider's publishable key.
Expert judgment
A leaks the secret: build-time variables are embedded in the client bundle, readable by anyone. B explains why and gives the standard safe architecture.