'paths' => ['api/*', 'sanctum/csrf-cookie', 'login', 'logout'], // Added common auth paths 'allowed_methods' => ['*'], // DO NOT USE '*' here when supports_credentials is true 'allowed_origins' => [ 'https://myvirtualpi.com', 'https://portal.myvirtualpi.com', 'https://backend.myvirtualpi.com' ], 'allowed_origins_patterns' => [], 'allowed_headers' => ['*'], 'exposed_headers' => [], 'max_age' => 0, // THIS MUST BE TRUE for cookies/tokens to work 'supports_credentials' => true,