<?php

return [

    /*
    |--------------------------------------------------------------------------
    | Guardrails
    |--------------------------------------------------------------------------
    |
    | Checked inside the API client, below every platform adapter and below the
    | agent, so there is no path around them and a new platform inherits them by
    | existing. Neither a language model nor a user typing in the chat box can
    | get past these.
    |
    */

    'guardrails' => [

        /** Only these accounts may be reached at all. Reads included. */
        'allowed_ad_accounts' => array_values(array_filter(array_map(
            trim(...),
            explode(',', (string) env('PLATFORM_ALLOWED_AD_ACCOUNTS', '')),
        ))),

        /** Ceiling on a single campaign's daily budget, in whole currency units. */
        'max_daily_budget' => (float) env('PLATFORM_MAX_DAILY_BUDGET', 20),

        /** Most ads one publish may create. */
        'max_ads_per_publish' => (int) env('PLATFORM_MAX_ADS_PER_PUBLISH', 5),

        /**
         * Our share of the platform's hourly limit, so anything else using the
         * same token keeps its own headroom.
         */
        'max_calls_per_hour' => (int) env('PLATFORM_MAX_CALLS_PER_HOUR', 60),
    ],

    /*
    |--------------------------------------------------------------------------
    | Meta
    |--------------------------------------------------------------------------
    |
    | Two tokens, on purpose. The system user token is long lived and is what
    | Graph calls use. The MCP requires a user token carrying the
    | ads_mcp_management scope, which expires and has to be renewed.
    |
    */

    'meta' => [
        'token' => env('META_ACCESS_TOKEN'),
        'version' => env('META_API_VERSION', 'v23.0'),

        'mcp' => [
            'enabled' => (bool) env('META_USE_MCP', true),
            'token' => env('META_MCP_TOKEN'),
            'endpoint' => env('META_MCP_ENDPOINT', 'https://mcp.facebook.com/ads'),
        ],
    ],

];
