A GS1 Digital Link resolver is the web service at the domain printed in your QR code, and it decides where each scan goes. This guide covers its rules under the GS1-Conformant Resolver Standard 1.2.1, and how to set up and test one.
It is for manufacturers and exporters printing GS1 Digital Link codes. The URI itself is explained on our GS1 Digital Link page. One rule changed in 2024: an app asking for a link type you never registered gets a 404, not your default page.
Check your encoded URI with our free GS1 Digital Link QR generator.
What is a GS1 Digital Link resolver?
A GS1 Digital Link resolver is a web service at the domain in a GS1 Digital Link code. It reads the GS1 keys in the requested URI and answers with one of the links registered for that item: the default, a typed link, or the full list. It is not the passport, the registry or the code.
Those three are easy to confuse. The Digital Product Passport (DPP) is the record the resolver links to. The EU registry under ESPR (Ecodesign for Sustainable Products Regulation), Regulation (EU) 2024/1781, Article 13, stores identifiers and is not a resolver. The QR code only carries the address.
This article starts at the server. Its rules are the GS1-Conformant Resolver Standard 1.2.1 and the URI Syntax 1.7.0, both ratified in August 2026. Guides written before 2024 describe the old all-in-one standard instead.
What does a GS1 Digital Link resolver answer to each kind of request?
A GS1 Digital Link resolver receives ordinary web traffic. It must answer normal web requests over HTTPS, including requests from apps running in a browser. In the standard's terms, that is HTTP/1.1 or higher for GET, HEAD and OPTIONS, plus CORS.
The basics, one code with many destinations, are in our GS1 Digital Link vs QR code comparison. Here is what the standard expects back for each request.
| Request | What a conformant resolver does | Status |
|---|---|---|
| Plain camera scan, no link type | Redirects to the default link, or to a language variant of it | 307 in the standard's flow chart |
?linkType=gs1:instructions, link registered | Redirects to that link | 307 in the flow chart |
?linkType=gs1:recallStatus, nothing registered | Not Found. No fallback to the default | 404 |
| Malformed URI, such as a wrong check digit | Bad Request | 400 |
| Valid URI, item unknown to this resolver | Not Found | 404 |
| Several links of the requested type, none a clear match | Returns the list of options | 300 Multiple Choices |
Accept: application/linkset+json header | No redirect. Returns the linkset: the full list of links, as JSON in RFC 9264 format | 200 |
?linkType=linkset from a plain browser | No redirect. Should return an HTML page of links | 200 |
?linkType=all | Deprecated name for linkset; resolvers are encouraged to keep supporting it | 200 |
The standard's prose names no redirect code. Only its flow chart labels redirects 307, and id.gs1.org answered 307 when we tested it on 6 October 2026. Nothing requires 301 or 302. The 400 and 404 rules are in the prose, and an error must never return 200 OK.
The 404 for a missing link type is the newer rule. Under the old all-in-one GS1 Digital Link 1.1, the resolver fell back to the default link. The standalone Resolver Standard replaced this from its first release in February 2024.
Languages. A plain scan carries no link type, so the resolver redirects to the default unless the request says more. Under the standard's recommended approach, it then chooses only among links typed gs1:defaultLink and gs1:defaultLinkMulti.
Language versions are told apart only by request headers, such as the phone's language, sent as Accept-Language. So, under the recommended approach, a German product page reaches a German phone only if it is also typed gs1:defaultLinkMulti. Support for that type is optional; ask your provider.
Countries. GS1 says id.gs1.org does not know where a scan comes from, though the calling app may pass it on. The only standard channel is the optional context parameter: its values are not standardised, resolvers need not support it, and id.gs1.org declares none. The standard defines no geolocation.
Which link types should a manufacturer register in a GS1 Digital Link resolver?
Every link you store in a GS1 Digital Link resolver needs a target URL, a link type and a human-readable title. Language, media type and context are optional. Link types come from the GS1 Web Vocabulary, now version 1.18, where gs1: stands for https://ref.gs1.org/voc/.
| Link type | Use it for | Note |
|---|---|---|
gs1:defaultLink | The one default per item | Exactly one; a title and no other attributes |
gs1:defaultLinkMulti | Language variants of the default | Optional for resolvers to support |
gs1:pip | Product information page | Can also serve as your default |
gs1:dpp | Digital Product Passport | Stable since Web Vocabulary 1.14.0 |
gs1:sustainabilityInfo | Sustainability and recycling | Replaces deprecated gs1:productSustainabilityInfo |
gs1:certificationInfo | Certificates | |
gs1:instructions | Assembly instructions, usage tips | |
gs1:serviceInfo | Service and maintenance | |
gs1:safetyInfo | Safety information | |
gs1:recallStatus | Whether the item is recalled | Typically an API |
Delete two names from any configuration copied from an older guide: gs1:productSustainabilityInfo (now gs1:sustainabilityInfo) and gs1:epcis (now gs1:epcisRepository). Do not invent types where GS1 has one; the standard warns that custom types greatly reduce interoperability. Point each link at a page about that item, not your homepage.
How does a GS1 Digital Link resolver handle batch and serial numbers?
Your printed code may carry more than a GTIN: a batch (AI 10), a serial (AI 21) or a consumer product variant (AI 22). Five rules decide what a GS1 Digital Link resolver does with them.
- Links inherit downwards. Batch, serial and variant levels inherit links from the GTIN. Every request, however granular, must find a default at its own level or higher. The simple way is one default per GTIN.
- Qualifiers may be ignored. A resolver that supports GTIN must accept batch, serial and variant, but it may strip them and resolve on the GTIN alone. It should not redirect up to a less granular URI.
- The answer is a union. A request returns the links at its own level plus every less granular combination of the same keys. A recall at GTIN plus batch is therefore also found by a code carrying GTIN, variant and batch.
- A serial-level link stands alone. A link registered for GTIN plus serial may not also carry batch or variant.
- The resolver answers only the query it gets. A link registered at GTIN plus variant plus batch is not found by a code that carries GTIN plus batch.
Rule 5 is the recall trap, shown in the walkthrough below. Rule 2 means you should test a batch URI on your GS1 Digital Link resolver before you print one.
Data attributes are different. An expiry date (AI 17) goes in the query string, such as ?17=271231, and is not part of the identifier. On a redirect, the resolver must pass the whole query string to the target.
In our id.gs1.org test, ?17=271231 reappeared unchanged in the redirect's Location header, the address the redirect points to.
How do you check that a GS1 Digital Link resolver is conformant?
Start with one file. A conformant GS1 Digital Link resolver must publish a Resolver Description File at /.well-known/gs1resolver. GS1's URI Syntax standard names it as one way to tell whether a resolver is there. Two properties are required: resolverRoot and supportedPrimaryKeys.
Run these checks against your own domain, with one of your GTINs. If you do not run your own servers, send the four commands to whoever hosts your site or your GS1 Digital Link resolver, and ask for the output.
# 0. Is there a resolver here at all?
curl -s https://id.example.com/.well-known/gs1resolver
# 1. Plain scan: expect a 3xx redirect (id.gs1.org uses 307) and a Location header
curl -sI "https://id.example.com/01/09520123456788?17=271231"
# 2. Unregistered link type: expect 404, not a redirect
curl -sI "https://id.example.com/01/09520123456788?linkType=gs1:recallStatus"
# 3. Full link list: expect 200 and JSON
curl -s -H "Accept: application/linkset+json" https://id.example.com/01/09520123456788
Any redirect code passes check 1, because the standard's prose names none. What matters is where the Location header points, and that ?17=271231 reappears in it.
If check 2 redirects to your default page, the service still follows the pre-2024 rule, or is a plain redirect rather than a conformant resolver. GS1's id.gs1.org passes all four checks for GS1's demo product, https://id.gs1.org/01/09506000134352, so you can compare answers.
Since Release 1.2.0, the description file must validate against https://ref.gs1.org/standards/resolver/description-file-schema and the link list against https://ref.gs1.org/standards/resolver/linkset-schema.
When you choose a service, ask one more thing. The standard says it should be impossible to register a link against an invalid GS1 identifier. A service that accepts a wrong check digit is not checking for you.
Where should you host it: own domain, GS1 member organisation or id.gs1.org?
The domain of your GS1 Digital Link resolver outlives every other choice here, because it is printed on the product. GS1 says anyone may run a resolver, and assumes brands will use their own domain names.
Own domain (id.yourbrand.com) | GS1 member organisation service | id.gs1.org | |
|---|---|---|---|
| Domain on the pack | Yours | The member organisation's | GS1's reference domain |
| Who sets the links | You, or a provider you choose | You, in the organisation's portal | The identifier's licensee, normally through its member organisation and the Links Registry |
| Availability terms | Whatever you contract | The organisation's terms | No warranty of continuous availability; regulatory use at your own risk |
Pattern hand-off (gs1:handledBy) | Optional | May receive prefixes handed on by id.gs1.org | Hands some GS1 prefixes to member organisation resolvers |
| Switching provider later | Repoint the domain; no reprint | The printed domain stays theirs | The printed domain stays GS1's |
GS1 Sweden's Link management, for example, creates links on GS1 Sweden's own resolver, and its members may run their own instead. Our reading: with a member organisation or id.gs1.org you control the targets, not the domain. The printed domain changes only with new print runs.
The standard does allow a hand-off at company-prefix level, so ask your member organisation whether it would forward your prefix to your own resolver. The hand-off is visible in practice: a German-prefix GTIN requested on id.gs1.org got a 307 to GS1 Germany's resolver, with rel="gs1:handledBy".
Now weigh this against the law. ESPR Article 11(e) says the passport must remain available for the period set in delegated acts, including after insolvency, liquidation or cessation of activity in the Union. Article 10(4) requires a back-up copy through a passport service provider.
ESPR says nothing about resolvers. Our reading is that a code printed on a domain nobody maintains breaks the scan path to the passport, even though the back-up copy still exists.
GS1's own best practice points the same way: build URIs on a domain you own, preferably an id subdomain. A domain is a brand asset that can be transferred if the brand is sold, so the codes need no reprint.
Walkthrough: a hypothetical furniture maker in Poznań
Take a hypothetical furniture maker in Poznań with 420 GTINs, selling in Poland, Germany and beyond. Its codes go on the carton label.
Step 1: the domain. It creates id. on its own brand domain and points it at a GS1 Digital Link resolver. The description file is live before any code is printed.
Step 2: one default per GTIN, plus language variants. The Polish product page is the default for all 420 GTINs, typed gs1:defaultLink with a title only. The Polish, German and English pages are then each typed gs1:pip and gs1:defaultLinkMulti, tagged pl, de and en.
The Polish page is listed twice, as in the standard's own language example, so a Polish phone that also lists English still gets Polish. That makes four links per GTIN: 1,680 in all.
On a resolver that supports gs1:defaultLinkMulti, a German phone now lands on the German page. A French phone lands on the Polish default, because no French variant exists.
Step 3: typed links at GTIN level. One gs1:instructions link per GTIN points to the assembly PDF: 420 more links. A gs1:dpp link is added per GTIN as each passport page goes live. No reprint is needed, because the code already carries the GTIN.
Step 4: the printed code. The carton carries GTIN plus batch, for example https://id.example.com/01/09520123456788/10/2611A.
Step 5: a recall. A hinge fault affects batch 2611A across 12 table GTINs. The maker registers 12 gs1:recallStatus links at GTIN plus batch. Any app that asks for the recall status of a carton from that batch finds it.
Counterfactual one: the recall at the wrong level. Suppose the ERP holds the recall per colour variant, and the links go in at GTIN plus variant plus batch. The cartons carry only GTIN plus batch.
The resolver answers only the query it gets, so the recall link is never found. A recall app gets 404, which reads like "no recall information".
Counterfactual two: one wrong character. A retailer's app requests linkType=gs1:instruction, without the final s. The standard's own example expects 404 for any type that is not registered.
When we tested id.gs1.org on 6 October 2026, it sent that request to the default page instead; a valid but unregistered type such as gs1:recallStatus got 404. Either way, the app does not get the instructions.
A check digit mistyped in the label template is worse: every scan of the run returns 400.
Edge cases
Compressed URIs. A conformant GS1 Digital Link resolver must decompress EPC binary strings, the compact encoding used on RFID tags. Decompressing general compressed URIs is optional, so a compressed code may fail on some resolvers. GS1's provisional DPP standard, not yet ratified, asks for the uncompressed form.
Trailing slash. /01/09520123456788/ is not valid syntax, but resolvers should tolerate it. Do not print it.
No language match. If an app asks for gs1:instructions and you registered Polish and German versions, a French phone may get 300 Multiple Choices with both listed. Add a version for each language you sell in, or accept that some users see a list.
Redirect chains. id.gs1.org can hand a request to a member organisation resolver, which redirects to your page. Each hop adds latency and a point of failure.
Query-string leakage. The whole query string reaches your target page. Make sure the page tolerates parameters like ?17=271231. Never put personal or secret data in a printed URI.
Apps without a resolver. A URI that follows Digital Link syntax does not prove a resolver sits behind it. Apps must not assume one is there; checking /.well-known/gs1resolver is the test the URI Syntax standard describes.
Zoom out: why the resolver must outlive you
A passport is about data. The GS1 Digital Link resolver is about reachability, and reachability is what the law fixes in time.
Adopted law. ESPR Article 9(2)(i) says each delegated act sets how long the passport stays available, at least the product's expected lifetime. Article 10(1) ties the data carrier to a persistent unique product identifier and requires data to move without vendor lock-in.
None of this names a resolver. Our reading is that the domain on the pack, and the GS1 Digital Link resolver behind it, is where these duties meet in practice.
Adopted law, voluntary standards. Commission Implementing Decision (EU) 2026/1736 cites six harmonised DPP standards: EN 18216, EN 18219, EN 18220, EN 18221, EN 18222 and EN 18223. Following them gives a presumption of conformity with ESPR Articles 10 and 11.
The full texts of those standards are paywalled, and we attribute no resolver rules to them.
Unknown. gs1:dpp exists, but we found no delegated act that mandates it or any specific resolver behaviour. Under ESPR Article 9(2)(b), each delegated act specifies the data carriers for its product group.
Expected. GS1's DPP application standard is provisional and says so. It favours the full URI on the brand owner's domain, QR Code or Data Matrix, and uncompressed URIs.
The battery passport runs under a separate regulation, (EU) 2023/1542, with a fixed date in law: . Its Article 77(3) already names the data carrier: a QR code.
For the framework, read our ESPR guide and what a digital product passport is.
What to do this quarter
- Own the
id.subdomain on your brand domain before you print another code. - Set one default per GTIN, and type each language page, the default's language included, as
gs1:defaultLinkMulti. - Register typed links with current GS1 names:
gs1:instructions,gs1:sustainabilityInfo, andgs1:dppwhen passports exist. - Publish or verify
/.well-known/gs1resolverand validate it against GS1's schema. - Test your GS1 Digital Link resolver with the four checks above, and check each encoded URI with the free generator. It needs no signup and runs in your browser.
Passmith also offers a free plan if you want to go further.
Further reading: GS1 Digital Link vs QR code · GS1 Digital Link explained · GS1 2D barcodes guide · DPP for non-EU manufacturers · Free GS1 Digital Link QR generator
Frequently asked questions
Do I need a GS1 Digital Link resolver, or is a redirect enough?
What HTTP status code does a GS1 Digital Link resolver use for redirects?
Is there a link type for the Digital Product Passport?
Can I use id.gs1.org instead of my own domain?
What happens if an app asks for a link type I have not registered?
Does the resolver know which country the scan comes from?
How do I check that a GS1 Digital Link resolver is conformant?
Sources
- GS1-Conformant Resolver Standard, Release 1.2.1 (HTML) — 2026-10-06
- GS1-Conformant Resolver Standard, Release 1.2.1 (PDF, incl. Figure 2-1 flow chart) — 2026-10-06
- GS1 Digital Link Standard: URI Syntax, Release 1.7.0 — 2026-10-06
- GS1 Digital Link standards family, incl. the legacy all-in-one standard — 2026-10-06
- GS1 Web Vocabulary: link types — 2026-10-06
- GS1 Web Vocabulary (JSON-LD), deprecated terms — 2026-10-06
- IETF RFC 9264: Linkset, the JSON format the Resolver Standard requires for link lists — 2026-10-06
- GS1 Resolver Terms of Use — 2026-10-06
- GS1 System Architecture — 2026-10-06
- GS1 FAQ: Relationship between the Links Registry and the GS1 Global Office resolver — 2026-10-06
- GS1 FAQ: How does the resolver know my location? — 2026-10-06
- GS1 FAQ: Does everyone have to use id.gs1.org? — 2026-10-06
- GS1 FAQ: What guarantee is there that the resolver service won't be discontinued? — 2026-10-06
- GS1: Best practices for creating your QR Code powered by GS1 (2023) — 2026-10-06
- GS1 Sweden: Link management — 2026-10-06
- GS1 provisional DPP standard (change notice, not ratified) — 2026-10-06
- id.gs1.org Resolver Description File (/.well-known/gs1resolver) — 2026-10-06
- id.gs1.org live HTTP responses for GS1's demo GTIN (checked with curl) — 2026-10-06
- Regulation (EU) 2024/1781 (ESPR), Articles 2, 9, 10, 11, 13 — EUR-Lex — 2026-10-06
- Commission Implementing Decision (EU) 2026/1736 on harmonised standards for digital product passports — EUR-Lex — 2026-10-06
- CEN-CENELEC: harmonised DPP standards cited in the Official Journal (news) — 2026-10-06
- Regulation (EU) 2023/1542 (Batteries), Article 77(3) — EUR-Lex — 2026-10-06


