Founding offer The Founding Partner Program is open — 1,000 companies, 6 months free. Start free →
GS1 Digital Link

GS1 Digital Link: when the barcode becomes a web address

The standard that lets a single code identify a product at the checkout and open a different page for every audience that scans it.

10 min read · Updated October 2026

GS1 Digital Link is a GS1 standard for writing product identifiers as web addresses. It places the GTIN and its qualifiers in the URL path in a fixed order, so one square on a pack can be read by a supermarket checkout, a shopper's phone and a customs system — each getting a different answer from the same code.

GS1 Digital Link URI Architecture

https://passmith.link/01/05412345678908/10/LOT42/21/000317
Resolver Domain
(01) GTIN Identifier
(10) Batch / Lot
(21) Serial Number

How a GS1 Digital Link URI is put together

GS1 Digital Link is a rule for writing identifiers as web addresses. The product number is not hidden in a database lookup — it sits in the URL path, in an order any system can parse.

The domain at the front is yours. Everything after it follows the standard: an Application Identifier, then its value, repeating as needed. A machine reading the path knows that (01) introduces a GTIN and (10) introduces a batch, no matter who issued the code or which country it is scanned in.

The order is not a style choice. One identifier opens the path — the primary key — and only certain identifiers may follow it, in a sequence the standard fixes. Get the order wrong and a conformant resolver will not recognise the address, even though every element in it is valid on its own.

Which identifiers can start a Digital Link, and which cannot

This is the part most explanations skip, and it is the part that breaks implementations. GS1 defines 541 Application Identifiers. Only 16 of them can begin a Digital Link URI. Everything else is either a qualifier that follows the primary key, or a data attribute that belongs in the query string rather than the path.

AIIdentifierFormatRole in a Digital Link URIQualifiers it accepts, in order
01GTINN2+N14Primary key22 → 10 → 21, or 235
00SSCCN2+N18Primary key—
8006ITIPN4+N14+N2+N2Primary key22 → 10 → 21
253GDTIN3+N13[+X..17]Primary key—
8013GMNN4+X..25Primary key—
414LOC No.N3+N13Primary key254, or 7040
8010CPIDN4+Y..30Primary key8011
22CPVN2+X..20Qualifier—
10BATCH/LOTN2+X..20Qualifier—
21SERIALN2+X..20Qualifier—
17USE BY or EXPIRYN2+N6Data attribute — not a path element—

Two consequences are worth pinning down. First, a GTIN-based address may carry a consumer product variant, a batch and a serial — but in that order, 22 before 10 before 21. Second, an expiry date is not a qualifier. It is a data attribute, so it travels in the query string. Putting it in the path is the single most common way a hand-built Digital Link fails against a conformant resolver.

Source: the GS1 Application Identifier dataset published at ref.gs1.org, version 1.2, last modified 26 January 2026. Counts are taken from the dataset itself rather than from a summary of it.

What the resolver does when someone scans

The symbol carries an address. What sits at that address is a resolver: a service that decides where each scan should go.

A resolver sees more than the identifier. It sees the language the browser requests, the country only when the scanning app passes it on, and a link type parameter that a professional system can set explicitly. The resolver matches those signals to a destination you configured.

  • A shopper in Germany scanning at home — the German product page
  • A customs officer with a link type for regulatory data — the compliance record
  • A recycler at end of life — the material composition sheet
  • A checkout — no web request at all; it reads the GTIN from the symbol and never leaves the till

Change a destination and every code already printed follows the new route. The symbol on the pack never has to be reprinted, because the code identifies the product rather than pointing at one fixed page.

Digital Link is three standards, not one

People say “GS1 Digital Link” as though it were a single document. It is a family, first ratified in August 2018, and knowing which part you are being sold matters when you evaluate a vendor.

  • URI Syntax — how the address is written. This is the part covered above: primary keys, qualifiers, order.
  • GS1-Conformant Resolver — how a service must behave when that address is requested: link types, redirects, and what a conformant answer looks like.
  • Compression — a technical standard for expressing EPC binary strings as compressed Digital Link URIs, for cases where the symbol has very little room.

A vendor can be correct on syntax and wrong on resolution. “We generate Digital Link URLs” describes the first standard only; it says nothing about whether anything answers those URLs conformantly in five years' time.

Why this is the format the EU passport lands on

A Digital Product Passport has to stay reachable for the life of the product, serve different data to different audiences, and survive the company that issued it. A fixed marketing URL fails all three.

GS1 Digital Link separates the identifier from the destination, and the harmonised DPP standards (EN 18216 and EN 18219–18223) keep those layers apart too: unique identifiers, data carriers and data storage each have their own standard, and EN 18221 describes decentralised, persistent data storage. That is why the same square that carries your passport link is also the format retail is moving to for Sunrise 2027.

Walkthrough: a cosmetics exporter builds its first Digital Link

A representative scenario. A manufacturer with 1,400 SKUs sells into Germany and France through two distributors, and has been told by both to be ready for a 2D code on pack.

Week one — what the code has to carry. Retail needs the GTIN. The distributors want batch, because recalls are their exposure. Nobody needs a serial number, because these are not serialised goods. So the path is GTIN plus batch: /01/<gtin>/10/<batch>. Serial is dropped, which removes an entire class of print-time variable data.

Week two — the expiry mistake. The first draft puts the expiry date in the path after the batch, because it is printed next to the batch on the carton. It fails validation. Expiry is a data attribute, not a qualifier, so it belongs after a question mark rather than in the path. Catching that in a test harness costs an afternoon; catching it after 400,000 cartons are printed costs the print run.

Week three — the domain decision. The resolver domain is printed on every pack and cannot be recalled, so it outlives contracts, rebrands and vendors. The company registers a short domain it owns outright and points it at a resolver, rather than printing a vendor's domain it would have to keep paying to keep alive.

The counterfactual. Suppose it had printed the vendor's domain. Two years later the contract ends. Every carton in the channel now points at a domain the company does not control, and the only remedy is a reprint of everything still in production plus a redirect the vendor has no obligation to maintain. The identifier was never the risk. The domain in front of it was.

Edge cases

Expiry, weight and price in the path. They are data attributes. Path is for the primary key and its qualifiers only; everything else goes in the query string.

Compressed URIs. Compression exists for symbols with almost no room. It is a separate standard, and not every scanning app decompresses. Use it because space forces you to, not because it looks tidier.

Two symbols on one pack. During migration a pack often carries the linear barcode and the 2D code together. That is expected, and the checkout decides which it reads. It is not a sign that something is misconfigured.

Own domain or GS1's. Either resolves. The question is not ownership but permanence: whoever holds the domain must keep answering for as long as the product exists in the world.

A GTIN you do not own. A Digital Link built on someone else's GTIN resolves to their resolver, not yours. Private-label goods need the brand owner's identifiers, or your own.

Zoom out: the identifier stopped pointing at a page

The older web put a URL on a pack and hoped it would still work. Digital Link inverts that: the pack carries an identifier, and the destination is a decision made at scan time by a service you control.

That inversion is why the same square now has to satisfy a checkout, a regulator and a recycler at once, and it is why the EU passport work assumes resolution rather than fixed links. The square is not marketing collateral any more. It is an entry point into a record that has to survive the product.

How Passmith fits

We are building the resolver and passport layer this page describes: identifiers in, role-aware destinations out, with the record kept where a customs officer or a recycler can reach it. The product is live and anyone can create an account.

Two things are worth saying plainly all the same. Nothing on this page depends on buying it: the syntax is a public standard and the identifier table above comes from GS1's own dataset. And if you only take one action today, make it the domain decision in the walkthrough, because it is the one that is expensive to reverse.

To build a link and its QR code from a GTIN you already license, use our free QR code generator for GS1 Digital Link. It needs no signup, and nothing you enter leaves your browser.

Common questions about GS1 Digital Link

Is GS1 Digital Link a type of QR code?

No — it is a way of writing the web address that a QR code or Data Matrix carries. The symbol is the container; GS1 Digital Link is the rule for what goes inside it.

Do I need my own resolver domain?

You need a domain that answers for your identifiers. It can be your own, or one operated for you. What matters is that it keeps resolving for as long as the product exists, because the address is printed on packaging you cannot recall.

Can one code really serve consumers and customs?

Yes. The code identifies the product; the resolver chooses the destination per request using language and link type, plus the country if the scanning app passes it on. Each audience sees the data meant for them without a separate code being printed for each.

Which GS1 identifiers can start a Digital Link URI?

Sixteen of the 541 Application Identifiers GS1 defines. For retail goods the one that matters is GTIN (01); the others cover logistics units (SSCC), trade item pieces (ITIP), documents (GDTI), models (GMN), locations (414) and components (CPID). Everything else is a qualifier or a data attribute.

In what order do batch and serial go in the URI?

After a GTIN the qualifiers run 22, then 10, then 21 — consumer product variant, then batch or lot, then serial number. A conformant resolver expects that sequence; a different order is not a stylistic variation, it is an address the resolver does not recognise.

Where does the expiry date go?

In the query string, not the path. Expiry (17) is a data attribute rather than a path qualifier, which is the most common mistake in hand-built Digital Link URIs.

You're in time

6 months free

Worth up to€1,4946 × €249

First 6 months€0

Reserved for the first 1,000 companies

Create your account, choose Starter or Growth, and pay €0 for six months. No credit card required.