<?php

return [

    /*
    |--------------------------------------------------------------------------
    | Third Party Services
    |--------------------------------------------------------------------------
    |
    | This file is for storing the credentials for third party services such
    | as Resend, Postmark, AWS, and more. This file provides the de facto
    | location for this type of information, allowing packages to have
    | a conventional file to locate the various service credentials.
    |
    */

    'postmark' => [
        'key' => env('POSTMARK_API_KEY'),
    ],

    'resend' => [
        'key' => env('RESEND_API_KEY'),
    ],

    'ses' => [
        'key' => env('AWS_ACCESS_KEY_ID'),
        'secret' => env('AWS_SECRET_ACCESS_KEY'),
        'region' => env('AWS_DEFAULT_REGION', 'us-east-1'),
    ],

    'slack' => [
        'notifications' => [
            'bot_user_oauth_token' => env('SLACK_BOT_USER_OAUTH_TOKEN'),
            'channel' => env('SLACK_BOT_USER_DEFAULT_CHANNEL'),
        ],

        'SLACK_WEBHOOK_URL' => env('SLACK_WEBHOOK_URL'),
    ],

    'meta' => [
        'access_token' => env('META_ACCESS_TOKEN'),
        'ad_account_id' => env('META_AD_ACCOUNT_ID'),
        'graph_url' => env('META_GRAPH_URL', 'https://graph.facebook.com/v26.0'),
        'ad_library_url' => env('META_AD_LIBRARY_URL', 'https://graph.facebook.com/v26.0/ads_archive'),
    ],

    'apify' => [
        'token' => env('APIFY_TOKEN'),
    ],

    'vertex_ai' => [
        'project_id' => env('VERTEX_APP_ID'),
        'location' => env('VERTEX_AI_LOCATION', 'us-central1'),
        // Absolute path to the downloaded service-account JSON key — never web-exposed, kept
        // under storage/app/private (gitignored) rather than the project root or public/.
        'credentials_path' => env('VERTEX_AI_CREDENTIALS_PATH', storage_path('app/private/gcp-service-account.json')),
    ],

    'google_ads' => [
        'developer_token' => env('GOOGLE_ADS_DEVELOPER_TOKEN'),
        'oauth_client_id' => env('GOOGLE_ADS_OAUTH_CLIENT_ID'),
        'oauth_client_secret' => env('GOOGLE_ADS_OAUTH_CLIENT_SECRET'),
        'refresh_token' => env('GOOGLE_ADS_REFRESH_TOKEN'),
        'api_version' => env('GOOGLE_ADS_API_VERSION', 'v25'),
        'login_customer_id' => env('GOOGLE_ADS_LOGIN_CUSTOMER_ID'),

        /*
         * The account campaigns are created on.
         *
         * One common account, the same shape as META_ACCESS_TOKEN above.
         * Google was built here expecting each user to connect their own via
         * OAuth, which is not how this product buys media.
         */
        'customer_id' => env('GOOGLE_ADS_CUSTOMER_ID'),
    ],

];
