, AFTER the existing
AWIN dwin1.com script (this reads data that script already saves).
This version uses a per-brand PUBLIC CAPTURE TOKEN, not the internal API
key - safe to leave visible in page source. Generate a token first via:
POST /api/brands/:id/generate-capture-token
-->