php - Laravel api for non login web application

one text

I still studing Laravel. Currently use Larvel 6 with passport for web and api auth, and now need to create a kiosk like web application to show public information that do not require protected by login/password. The problem is api route config makes my api call return 'unauthorized'. Is there any ways overrided the api authorize ? Should I set up something like device auth ? Thank you very much !

API.PHP

<?php
use Illuminate\Http\Request;
use Illuminate\Support\Facades\Route;
Route::get('/public_companies/index/{trashed?}','Admin\CompanyController@public_index');

CompanyController.php

<?php
namespace App\Http\Controllers\Admin;
use App\Admin\Company;
use App\Http\Controllers\Controller;
use Illuminate\Http\Request;
use Illuminate\Support\Facades\Auth;
class CompanyController extends Controller
{
  public function public_index()// NOT authorize, for public listing
    {       // $this->authorize('publicViewAny','App\Admin\Company');
            $result = Company::with('company_addresses')->get(); 
            return  ['public_companies' => $result]; 
        }
    }
}

Kernel.php

<?php
namespace App\Http;
use Illuminate\Foundation\Http\Kernel as HttpKernel;
class Kernel extends HttpKernel
{
    protected $middleware = [
        \App\Http\Middleware\TrustProxies::class,
        \App\Http\Middleware\CheckForMaintenanceMode::class,
        \Illuminate\Foundation\Http\Middleware\ValidatePostSize::class,
        \App\Http\Middleware\TrimStrings::class,
        \Illuminate\Foundation\Http\Middleware\ConvertEmptyStringsToNull::class,       
    ];
    protected $middlewareGroups = [
        'web' => [
            \App\Http\Middleware\EncryptCookies::class,
            \Illuminate\Cookie\Middleware\AddQueuedCookiesToResponse::class,
            \Illuminate\Session\Middleware\StartSession::class,
            // \Illuminate\Session\Middleware\AuthenticateSession::class,
            \Illuminate\View\Middleware\ShareErrorsFromSession::class,
            \App\Http\Middleware\VerifyCsrfToken::class,
            \Illuminate\Routing\Middleware\SubstituteBindings::class,
            \Laravel\Passport\Http\Middleware\CreateFreshApiToken::class,
        ],
        'api' => [
            'throttle:60,1',
            'bindings',
            'auth:api',
        ],
    ];
    protected $routeMiddleware = [
        'auth' => \App\Http\Middleware\Authenticate::class,
        'auth.basic' => \Illuminate\Auth\Middleware\AuthenticateWithBasicAuth::class,
        'bindings' => \Illuminate\Routing\Middleware\SubstituteBindings::class,
        'cache.headers' => \Illuminate\Http\Middleware\SetCacheHeaders::class,
        'can' => \Illuminate\Auth\Middleware\Authorize::class,
        'guest' => \App\Http\Middleware\RedirectIfAuthenticated::class,
        'signed' => \Illuminate\Routing\Middleware\ValidateSignature::class,
        'throttle' => \Illuminate\Routing\Middleware\ThrottleRequests::class,
        'verified' => \Illuminate\Auth\Middleware\EnsureEmailIsVerified::class,
    ];

UPDATE : Finally work around by adding a custom route file to handle this route, as well as use Auth::once() in the controller of Laravel to get one time authrization.

Source