Founding offer The Founding Partner Program is open — 1,000 companies, 6 months free. Start free →
GS1

GS1 Digital Link Resolver: How It Answers Every Scan, and How to Test One

The resolver decides where each scan of your QR code goes. What the GS1 standard requires it to answer, which link types to register, how batch codes behave, and where to host it.

13 min read · Updated Oct 2026
Wooden furniture in a showroom

A GS1 Digital Link resolver is the web service at the domain printed in your QR code, and it decides where each scan goes. This guide covers its rules under the GS1-Conformant Resolver Standard 1.2.1, and how to set up and test one.

It is for manufacturers and exporters printing GS1 Digital Link codes. The URI itself is explained on our GS1 Digital Link page. One rule changed in 2024: an app asking for a link type you never registered gets a 404, not your default page.

Check your encoded URI with our free GS1 Digital Link QR generator.

A GS1 Digital Link resolver is a web service at the domain in a GS1 Digital Link code. It reads the GS1 keys in the requested URI and answers with one of the links registered for that item: the default, a typed link, or the full list. It is not the passport, the registry or the code.

Those three are easy to confuse. The Digital Product Passport (DPP) is the record the resolver links to. The EU registry under ESPR (Ecodesign for Sustainable Products Regulation), Regulation (EU) 2024/1781, Article 13, stores identifiers and is not a resolver. The QR code only carries the address.

This article starts at the server. Its rules are the GS1-Conformant Resolver Standard 1.2.1 and the URI Syntax 1.7.0, both ratified in August 2026. Guides written before 2024 describe the old all-in-one standard instead.

A GS1 Digital Link resolver receives ordinary web traffic. It must answer normal web requests over HTTPS, including requests from apps running in a browser. In the standard's terms, that is HTTP/1.1 or higher for GET, HEAD and OPTIONS, plus CORS.

The basics, one code with many destinations, are in our GS1 Digital Link vs QR code comparison. Here is what the standard expects back for each request.

RequestWhat a conformant resolver doesStatus
Plain camera scan, no link typeRedirects to the default link, or to a language variant of it307 in the standard's flow chart
?linkType=gs1:instructions, link registeredRedirects to that link307 in the flow chart
?linkType=gs1:recallStatus, nothing registeredNot Found. No fallback to the default404
Malformed URI, such as a wrong check digitBad Request400
Valid URI, item unknown to this resolverNot Found404
Several links of the requested type, none a clear matchReturns the list of options300 Multiple Choices
Accept: application/linkset+json headerNo redirect. Returns the linkset: the full list of links, as JSON in RFC 9264 format200
?linkType=linkset from a plain browserNo redirect. Should return an HTML page of links200
?linkType=allDeprecated name for linkset; resolvers are encouraged to keep supporting it200

The standard's prose names no redirect code. Only its flow chart labels redirects 307, and id.gs1.org answered 307 when we tested it on 6 October 2026. Nothing requires 301 or 302. The 400 and 404 rules are in the prose, and an error must never return 200 OK.

The 404 for a missing link type is the newer rule. Under the old all-in-one GS1 Digital Link 1.1, the resolver fell back to the default link. The standalone Resolver Standard replaced this from its first release in February 2024.

Languages. A plain scan carries no link type, so the resolver redirects to the default unless the request says more. Under the standard's recommended approach, it then chooses only among links typed gs1:defaultLink and gs1:defaultLinkMulti.

Language versions are told apart only by request headers, such as the phone's language, sent as Accept-Language. So, under the recommended approach, a German product page reaches a German phone only if it is also typed gs1:defaultLinkMulti. Support for that type is optional; ask your provider.

Countries. GS1 says id.gs1.org does not know where a scan comes from, though the calling app may pass it on. The only standard channel is the optional context parameter: its values are not standardised, resolvers need not support it, and id.gs1.org declares none. The standard defines no geolocation.

Every link you store in a GS1 Digital Link resolver needs a target URL, a link type and a human-readable title. Language, media type and context are optional. Link types come from the GS1 Web Vocabulary, now version 1.18, where gs1: stands for https://ref.gs1.org/voc/.

Link typeUse it forNote
gs1:defaultLinkThe one default per itemExactly one; a title and no other attributes
gs1:defaultLinkMultiLanguage variants of the defaultOptional for resolvers to support
gs1:pipProduct information pageCan also serve as your default
gs1:dppDigital Product PassportStable since Web Vocabulary 1.14.0
gs1:sustainabilityInfoSustainability and recyclingReplaces deprecated gs1:productSustainabilityInfo
gs1:certificationInfoCertificates
gs1:instructionsAssembly instructions, usage tips
gs1:serviceInfoService and maintenance
gs1:safetyInfoSafety information
gs1:recallStatusWhether the item is recalledTypically an API

Delete two names from any configuration copied from an older guide: gs1:productSustainabilityInfo (now gs1:sustainabilityInfo) and gs1:epcis (now gs1:epcisRepository). Do not invent types where GS1 has one; the standard warns that custom types greatly reduce interoperability. Point each link at a page about that item, not your homepage.

Your printed code may carry more than a GTIN: a batch (AI 10), a serial (AI 21) or a consumer product variant (AI 22). Five rules decide what a GS1 Digital Link resolver does with them.

  1. Links inherit downwards. Batch, serial and variant levels inherit links from the GTIN. Every request, however granular, must find a default at its own level or higher. The simple way is one default per GTIN.
  2. Qualifiers may be ignored. A resolver that supports GTIN must accept batch, serial and variant, but it may strip them and resolve on the GTIN alone. It should not redirect up to a less granular URI.
  3. The answer is a union. A request returns the links at its own level plus every less granular combination of the same keys. A recall at GTIN plus batch is therefore also found by a code carrying GTIN, variant and batch.
  4. A serial-level link stands alone. A link registered for GTIN plus serial may not also carry batch or variant.
  5. The resolver answers only the query it gets. A link registered at GTIN plus variant plus batch is not found by a code that carries GTIN plus batch.

Rule 5 is the recall trap, shown in the walkthrough below. Rule 2 means you should test a batch URI on your GS1 Digital Link resolver before you print one.

Data attributes are different. An expiry date (AI 17) goes in the query string, such as ?17=271231, and is not part of the identifier. On a redirect, the resolver must pass the whole query string to the target.

In our id.gs1.org test, ?17=271231 reappeared unchanged in the redirect's Location header, the address the redirect points to.

Start with one file. A conformant GS1 Digital Link resolver must publish a Resolver Description File at /.well-known/gs1resolver. GS1's URI Syntax standard names it as one way to tell whether a resolver is there. Two properties are required: resolverRoot and supportedPrimaryKeys.

Run these checks against your own domain, with one of your GTINs. If you do not run your own servers, send the four commands to whoever hosts your site or your GS1 Digital Link resolver, and ask for the output.

# 0. Is there a resolver here at all?
curl -s https://id.example.com/.well-known/gs1resolver

# 1. Plain scan: expect a 3xx redirect (id.gs1.org uses 307) and a Location header
curl -sI "https://id.example.com/01/09520123456788?17=271231"

# 2. Unregistered link type: expect 404, not a redirect
curl -sI "https://id.example.com/01/09520123456788?linkType=gs1:recallStatus"

# 3. Full link list: expect 200 and JSON
curl -s -H "Accept: application/linkset+json" https://id.example.com/01/09520123456788

Any redirect code passes check 1, because the standard's prose names none. What matters is where the Location header points, and that ?17=271231 reappears in it.

If check 2 redirects to your default page, the service still follows the pre-2024 rule, or is a plain redirect rather than a conformant resolver. GS1's id.gs1.org passes all four checks for GS1's demo product, https://id.gs1.org/01/09506000134352, so you can compare answers.

Since Release 1.2.0, the description file must validate against https://ref.gs1.org/standards/resolver/description-file-schema and the link list against https://ref.gs1.org/standards/resolver/linkset-schema.

When you choose a service, ask one more thing. The standard says it should be impossible to register a link against an invalid GS1 identifier. A service that accepts a wrong check digit is not checking for you.

Where should you host it: own domain, GS1 member organisation or id.gs1.org?

The domain of your GS1 Digital Link resolver outlives every other choice here, because it is printed on the product. GS1 says anyone may run a resolver, and assumes brands will use their own domain names.

Own domain (id.yourbrand.com)GS1 member organisation serviceid.gs1.org
Domain on the packYoursThe member organisation'sGS1's reference domain
Who sets the linksYou, or a provider you chooseYou, in the organisation's portalThe identifier's licensee, normally through its member organisation and the Links Registry
Availability termsWhatever you contractThe organisation's termsNo warranty of continuous availability; regulatory use at your own risk
Pattern hand-off (gs1:handledBy)OptionalMay receive prefixes handed on by id.gs1.orgHands some GS1 prefixes to member organisation resolvers
Switching provider laterRepoint the domain; no reprintThe printed domain stays theirsThe printed domain stays GS1's

GS1 Sweden's Link management, for example, creates links on GS1 Sweden's own resolver, and its members may run their own instead. Our reading: with a member organisation or id.gs1.org you control the targets, not the domain. The printed domain changes only with new print runs.

The standard does allow a hand-off at company-prefix level, so ask your member organisation whether it would forward your prefix to your own resolver. The hand-off is visible in practice: a German-prefix GTIN requested on id.gs1.org got a 307 to GS1 Germany's resolver, with rel="gs1:handledBy".

Now weigh this against the law. ESPR Article 11(e) says the passport must remain available for the period set in delegated acts, including after insolvency, liquidation or cessation of activity in the Union. Article 10(4) requires a back-up copy through a passport service provider.

ESPR says nothing about resolvers. Our reading is that a code printed on a domain nobody maintains breaks the scan path to the passport, even though the back-up copy still exists.

GS1's own best practice points the same way: build URIs on a domain you own, preferably an id subdomain. A domain is a brand asset that can be transferred if the brand is sold, so the codes need no reprint.

Walkthrough: a hypothetical furniture maker in Poznań

Take a hypothetical furniture maker in Poznań with 420 GTINs, selling in Poland, Germany and beyond. Its codes go on the carton label.

Step 1: the domain. It creates id. on its own brand domain and points it at a GS1 Digital Link resolver. The description file is live before any code is printed.

Step 2: one default per GTIN, plus language variants. The Polish product page is the default for all 420 GTINs, typed gs1:defaultLink with a title only. The Polish, German and English pages are then each typed gs1:pip and gs1:defaultLinkMulti, tagged pl, de and en.

The Polish page is listed twice, as in the standard's own language example, so a Polish phone that also lists English still gets Polish. That makes four links per GTIN: 1,680 in all.

On a resolver that supports gs1:defaultLinkMulti, a German phone now lands on the German page. A French phone lands on the Polish default, because no French variant exists.

Step 3: typed links at GTIN level. One gs1:instructions link per GTIN points to the assembly PDF: 420 more links. A gs1:dpp link is added per GTIN as each passport page goes live. No reprint is needed, because the code already carries the GTIN.

Step 4: the printed code. The carton carries GTIN plus batch, for example https://id.example.com/01/09520123456788/10/2611A.

Step 5: a recall. A hinge fault affects batch 2611A across 12 table GTINs. The maker registers 12 gs1:recallStatus links at GTIN plus batch. Any app that asks for the recall status of a carton from that batch finds it.

Counterfactual one: the recall at the wrong level. Suppose the ERP holds the recall per colour variant, and the links go in at GTIN plus variant plus batch. The cartons carry only GTIN plus batch.

The resolver answers only the query it gets, so the recall link is never found. A recall app gets 404, which reads like "no recall information".

Counterfactual two: one wrong character. A retailer's app requests linkType=gs1:instruction, without the final s. The standard's own example expects 404 for any type that is not registered.

When we tested id.gs1.org on 6 October 2026, it sent that request to the default page instead; a valid but unregistered type such as gs1:recallStatus got 404. Either way, the app does not get the instructions.

A check digit mistyped in the label template is worse: every scan of the run returns 400.

Edge cases

Compressed URIs. A conformant GS1 Digital Link resolver must decompress EPC binary strings, the compact encoding used on RFID tags. Decompressing general compressed URIs is optional, so a compressed code may fail on some resolvers. GS1's provisional DPP standard, not yet ratified, asks for the uncompressed form.

Trailing slash. /01/09520123456788/ is not valid syntax, but resolvers should tolerate it. Do not print it.

No language match. If an app asks for gs1:instructions and you registered Polish and German versions, a French phone may get 300 Multiple Choices with both listed. Add a version for each language you sell in, or accept that some users see a list.

Redirect chains. id.gs1.org can hand a request to a member organisation resolver, which redirects to your page. Each hop adds latency and a point of failure.

Query-string leakage. The whole query string reaches your target page. Make sure the page tolerates parameters like ?17=271231. Never put personal or secret data in a printed URI.

Apps without a resolver. A URI that follows Digital Link syntax does not prove a resolver sits behind it. Apps must not assume one is there; checking /.well-known/gs1resolver is the test the URI Syntax standard describes.

Zoom out: why the resolver must outlive you

A passport is about data. The GS1 Digital Link resolver is about reachability, and reachability is what the law fixes in time.

Adopted law. ESPR Article 9(2)(i) says each delegated act sets how long the passport stays available, at least the product's expected lifetime. Article 10(1) ties the data carrier to a persistent unique product identifier and requires data to move without vendor lock-in.

None of this names a resolver. Our reading is that the domain on the pack, and the GS1 Digital Link resolver behind it, is where these duties meet in practice.

Adopted law, voluntary standards. Commission Implementing Decision (EU) 2026/1736 cites six harmonised DPP standards: EN 18216, EN 18219, EN 18220, EN 18221, EN 18222 and EN 18223. Following them gives a presumption of conformity with ESPR Articles 10 and 11.

The full texts of those standards are paywalled, and we attribute no resolver rules to them.

Unknown. gs1:dpp exists, but we found no delegated act that mandates it or any specific resolver behaviour. Under ESPR Article 9(2)(b), each delegated act specifies the data carriers for its product group.

Expected. GS1's DPP application standard is provisional and says so. It favours the full URI on the brand owner's domain, QR Code or Data Matrix, and uncompressed URIs.

The battery passport runs under a separate regulation, (EU) 2023/1542, with a fixed date in law: . Its Article 77(3) already names the data carrier: a QR code.

For the framework, read our ESPR guide and what a digital product passport is.

What to do this quarter

  1. Own the id. subdomain on your brand domain before you print another code.
  2. Set one default per GTIN, and type each language page, the default's language included, as gs1:defaultLinkMulti.
  3. Register typed links with current GS1 names: gs1:instructions, gs1:sustainabilityInfo, and gs1:dpp when passports exist.
  4. Publish or verify /.well-known/gs1resolver and validate it against GS1's schema.
  5. Test your GS1 Digital Link resolver with the four checks above, and check each encoded URI with the free generator. It needs no signup and runs in your browser.

Passmith also offers a free plan if you want to go further.

Further reading: GS1 Digital Link vs QR code · GS1 Digital Link explained · GS1 2D barcodes guide · DPP for non-EU manufacturers · Free GS1 Digital Link QR generator

Frequently asked questions

Do I need a GS1 Digital Link resolver, or is a redirect enough?
A redirect is a valid start. The GS1 standard says not every Digital Link must point to a conformant resolver, or even redirect, though GS1 strongly recommends redirecting. A one-to-one redirect from each URI to the right product page works. You need a conformant resolver once apps should ask one code for typed links, such as instructions, a passport or recall status, or for the full list.
What HTTP status code does a GS1 Digital Link resolver use for redirects?
307 Temporary Redirect is the safe choice: GS1's flow chart labels redirects 307, and id.gs1.org used it when we checked, though the standard's prose requires no specific redirect code. The prose does fix the error codes: 400 for a malformed URI and 404 for an unknown item or a missing link type. It also recommends 300 Multiple Choices when several links fit equally. An error must never come back as 200 OK.
Is there a link type for the Digital Product Passport?
Yes. gs1:dpp means a link to a digital product passport. It has stable status in the GS1 Web Vocabulary, was added in version 1.14.0, and the vocabulary now stands at 1.18. We found no adopted EU act that requires gs1:dpp. Under ESPR, each product group's delegated act sets its data carriers. The Battery Regulation already requires a QR code for the battery passport (Article 77(3)), but prescribes no GS1 link types either.
Can I use id.gs1.org instead of my own domain?
You can. id.gs1.org is GS1's reference domain, and links normally reach it through your GS1 member organisation and the Links Registry. But GS1's resolver terms give no warranty of continuous availability and say regulatory use is at your own risk. GS1's own best practice is a domain you own, ideally an id. subdomain, which can be transferred if the brand is sold.
What happens if an app asks for a link type I have not registered?
If the link type is a valid one you never registered, the resolver must answer 404 Not Found. Under the old all-in-one GS1 Digital Link standard, version 1.1, it fell back to the default link instead. The standalone Resolver Standard changed this from its first release in February 2024, so a retailer or recycler app now gets a clear no rather than your default page.
Does the resolver know which country the scan comes from?
Not by standard. GS1 says id.gs1.org does not know the scanner's location, though the calling app may pass it on. The only standard channel is the optional context query parameter: its values are not standardised and resolvers need not support it. Language is different: it arrives in the phone's Accept-Language header, which resolvers should support. Do not plan country routing on geolocation.
How do I check that a GS1 Digital Link resolver is conformant?
Start with the description file: a conformant resolver must publish one at /.well-known/gs1resolver, with resolverRoot and supportedPrimaryKeys. Then request one of your GTINs three ways. A plain request should redirect with the query string intact. An unregistered link type should return 404. A request with Accept: application/linkset+json should return 200 and the full link list as JSON. Compare the answers with id.gs1.org.

Sources

  1. GS1-Conformant Resolver Standard, Release 1.2.1 (HTML) — 2026-10-06
  2. GS1-Conformant Resolver Standard, Release 1.2.1 (PDF, incl. Figure 2-1 flow chart) — 2026-10-06
  3. GS1 Digital Link Standard: URI Syntax, Release 1.7.0 — 2026-10-06
  4. GS1 Digital Link standards family, incl. the legacy all-in-one standard — 2026-10-06
  5. GS1 Web Vocabulary: link types — 2026-10-06
  6. GS1 Web Vocabulary (JSON-LD), deprecated terms — 2026-10-06
  7. IETF RFC 9264: Linkset, the JSON format the Resolver Standard requires for link lists — 2026-10-06
  8. GS1 Resolver Terms of Use — 2026-10-06
  9. GS1 System Architecture — 2026-10-06
  10. GS1 FAQ: Relationship between the Links Registry and the GS1 Global Office resolver — 2026-10-06
  11. GS1 FAQ: How does the resolver know my location? — 2026-10-06
  12. GS1 FAQ: Does everyone have to use id.gs1.org? — 2026-10-06
  13. GS1 FAQ: What guarantee is there that the resolver service won't be discontinued? — 2026-10-06
  14. GS1: Best practices for creating your QR Code powered by GS1 (2023) — 2026-10-06
  15. GS1 Sweden: Link management — 2026-10-06
  16. GS1 provisional DPP standard (change notice, not ratified) — 2026-10-06
  17. id.gs1.org Resolver Description File (/.well-known/gs1resolver) — 2026-10-06
  18. id.gs1.org live HTTP responses for GS1's demo GTIN (checked with curl) — 2026-10-06
  19. Regulation (EU) 2024/1781 (ESPR), Articles 2, 9, 10, 11, 13 — EUR-Lex — 2026-10-06
  20. Commission Implementing Decision (EU) 2026/1736 on harmonised standards for digital product passports — EUR-Lex — 2026-10-06
  21. CEN-CENELEC: harmonised DPP standards cited in the Official Journal (news) — 2026-10-06
  22. Regulation (EU) 2023/1542 (Batteries), Article 77(3) — EUR-Lex — 2026-10-06
Digital Product Passport platform

Built on GS1 Digital Link and EN 18216, 18219–18223, from offices in the Netherlands, Türkiye and Azerbaijan.

Last updated:

You're in time

6 months free

Worth up to€1,4946 × €249

First 6 months€0

Reserved for the first 1,000 companies

Create your account, choose Starter or Growth, and pay €0 for six months. No credit card required.