laravel 7 api CSRF token mismatch on POST request

You should use api.php file for api routes, as they are not checked for csrf_token middleware by default in app/http/kernel.php:

protected $middlewareGroups = [
        'web' => [

        'api' => [

