The global stack is not written anywhere in your application; the builder supplies it. Ask the HTTP kernel for the live list (php artisan route:list -v shows each route's groups and route middleware):
php artisan tinker --execute='echo implode(PHP_EOL,
app(Illuminate\Contracts\Http\Kernel::class)->getGlobalMiddleware());'Illuminate\Http\Middleware\ValidatePathEncoding Illuminate\Foundation\Http\Middleware\InvokeDeferredCallbacks Illuminate\Http\Middleware\TrustProxies Illuminate\Http\Middleware\HandleCors Illuminate\Foundation\Http\Middleware\PreventRequestsDuringMaintenance Illuminate\Http\Middleware\ValidatePostSize Illuminate\Foundation\Http\Middleware\TrimStrings Illuminate\Foundation\Http\Middleware\ConvertEmptyStringsToNull App\Http\Middleware\AddServerTiming
The defaults reject a path that is not valid UTF-8, run defer() callbacks after the response, honor X-Forwarded-* from trusted proxies (ProxyPass), answer CORS from config/cors.php, return 503 during php artisan down, refuse bodies over post_max_size with 413, and trim strings and null empty ones. The online documentation's copy of the list omits ValidatePathEncoding: trust the kernel.
A group is a named list. web holds EncryptCookies, AddQueuedCookiesToResponse, StartSession, ShareErrorsFromSession, PreventRequestForgery and SubstituteBindings; api holds only SubstituteBindings, since a token API needs no session (throttleApi() and statefulApi() add more, Sanctum for SPAs). The bookshop's catalog group, applied with Route::middleware('catalog'), bundles the key check and the locale switch. ->withoutMiddleware([...]) exempts one route from route and group middleware, never from global ones.