Canonset
← Samples

Preference data

Which answer is better, and why

Coding and agent-behavior comparisons chosen to test judgment, not just correctness: sometimes the longer answer is wrong, sometimes caution is the wrong call, and one pair is a genuine tie that should not be forced.

  • 12 pairs
  • 10 clear, 2 slight or tie
  • Agent safety and honesty cases
  • Raw and DPO formats

API keys in a React app

pref-11

Prompt

Where should I put my payment provider's secret API key in my React app?

Response A

Put it in a .env file as REACT_APP_PAYMENT_KEY=... and read it with process.env.REACT_APP_PAYMENT_KEY. Since .env isn't committed to git, the key stays secret.

Response B

Nowhere in the React app: anything the browser runs is public, including environment variables, which are baked into the JavaScript bundle at build time. Keep the secret key on a server (or a serverless function) that calls the payment provider, and give the browser only the provider's publishable key.

Expert judgment

Prefers response BClear preference

A leaks the secret: build-time variables are embedded in the client bundle, readable by anyone. B explains why and gives the standard safe architecture.