middleware(['api', 'api.auth', 'throttle:api-write'])->group(function () { Route::post('/payments/{booking:booking_ref}/initiate', [PaymentController::class, 'initiate'])->name('payment.payments.initiate'); Route::post('/bookings/{booking:booking_ref}/refund', [RefundController::class, 'refund'])->name('payment.bookings.refund'); }); // No auth:sanctum — the gateway authenticates itself via its own signed // payload (verified inside each gateway's handleWebhook()), not a bearer // token (domain.md §6). Route::prefix('api/v1')->middleware(['api', 'throttle:api-webhooks'])->group(function () { Route::post('/webhooks/{method}/{encryptBookingId?}', [PaymentWebhookController::class, 'handle'])->name('payment.webhooks.handle'); });