json([ 'success' => false, 'error' => 'INTERNAL_API_TOKEN not configured', ], 500); } $provided = (string) $request->header('X-Internal-Token', ''); if (!hash_equals($expected, $provided)) { return response()->json([ 'success' => false, 'error' => 'Unauthorized', ], 401); } return $next($request); } }