> ## Documentation Index
> Fetch the complete documentation index at: https://docs.closient.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Verify a serialized unit for returns

> Decide whether a scanned GTIN + serial was sold by the authenticated organization, when, under which transaction, and whether it has already been returned. Intended for a return desk scanner or POS plugin: one call, one decision object.

Decisions are computed **only** from the querying organization's own EPCIS events — another retailer's sale of the same GTIN + serial is never visible here, and a unit this organization has no events for is reported as ``unknown_serial`` rather than falling back to anyone else's history. Recall status is the one deliberate exception: it is public product-safety information, so an open recall covering the unit is reported regardless of which organization published it.

The lifecycle states ride GS1 CBV 2.0 dispositions — ``retail_sold`` for a sale (bizStep ``retail_selling``) and ``returned`` for a return (bizStep ``returning``). Caller must hold an OWNER or MANAGER membership on the organization.



## OpenAPI

````yaml /openapi/openapi-epcis.json get /epcis/api/2.0/verification/serial
openapi: 3.1.0
info:
  title: EPCIS 2.0 API
  version: 2.0.0
  description: >
    GS1-conformant EPCIS 2.0 event capture and query API.


    ## Authentication


    All endpoints require an API key passed via the `X-API-Key` HTTP header,
    unless otherwise noted.


    ```

    X-API-Key: csb_<body>_<checksum>

    ```


    Generate API keys in **Settings > API Keys** in your dashboard, or via the
    Account API.

    Session-based (cookie) authentication is also accepted for browser-based
    access.


    ## Rate Limits


    | Tier        | Requests / minute | Requests / day |

    |-------------|-------------------|----------------|

    | Default     | 300               | 10,000         |

    | Custom      | Contact us        | Contact us     |


    Rate-limit headers are included on every response so callers can
    self-throttle without

    hitting our 429s ("informed governor"):


    - `RateLimit-Policy` — every active window, e.g. `300;w=60, 10000;w=86400`

    - `RateLimit-Limit` — quota for the **most-restrictive** currently-active
    window

    - `RateLimit-Remaining` — requests left in that window

    - `RateLimit-Reset` — seconds until that window resets (relative; clock-skew
    safe)


    Legacy `X-RateLimit-*` aliases are also emitted for back-compat.
    `X-RateLimit-Reset`

    keeps the absolute Unix-timestamp shape to avoid breaking existing
    consumers.


    When rate-limited, you receive `429 Too Many Requests` with a
    `retry_after_seconds` field

    in the error envelope and a `Retry-After` header.


    ## Pagination


    List endpoints return paginated results in this envelope:


    ```json

    {
      "data": [...],
      "pagination": {
        "page": 1,
        "page_size": 25,
        "total_count": 342,
        "total_pages": 14,
        "has_next": true,
        "has_previous": false
      }
    }

    ```


    Use `?page=2&page_size=50` query parameters. Maximum page size is 100.


    ## Error Responses


    All errors conform to [RFC 9457 Problem
    Details](https://www.rfc-editor.org/rfc/rfc9457)

    with `Content-Type: application/problem+json`:


    ```json

    {
      "type": "https://closient.com/docs/errors/not_found",
      "title": "Not Found",
      "status": 404,
      "detail": "The requested resource was not found.",
      "error_code": "not_found",
      "retryable": false,
      "timestamp": "2026-03-31T12:00:00+00:00"
    }

    ```


    Common error codes: `unauthorized` (401), `forbidden` (403), `not_found`
    (404),

    `validation_error` (422), `rate_limited` (429), `internal_error` (500).
  termsOfService: https://www.closient.com/terms/
servers:
  - url: https://www.closient.com
security: []
externalDocs:
  description: Closient Documentation
  url: https://docs.closient.com
paths:
  /epcis/api/2.0/verification/serial:
    get:
      tags:
        - EPCIS 2.0
      summary: Verify a serialized unit for returns
      description: >-
        Decide whether a scanned GTIN + serial was sold by the authenticated
        organization, when, under which transaction, and whether it has already
        been returned. Intended for a return desk scanner or POS plugin: one
        call, one decision object.


        Decisions are computed **only** from the querying organization's own
        EPCIS events — another retailer's sale of the same GTIN + serial is
        never visible here, and a unit this organization has no events for is
        reported as ``unknown_serial`` rather than falling back to anyone else's
        history. Recall status is the one deliberate exception: it is public
        product-safety information, so an open recall covering the unit is
        reported regardless of which organization published it.


        The lifecycle states ride GS1 CBV 2.0 dispositions — ``retail_sold`` for
        a sale (bizStep ``retail_selling``) and ``returned`` for a return
        (bizStep ``returning``). Caller must hold an OWNER or MANAGER membership
        on the organization.
      operationId: apps_epcis_api_verification_epcis_verify_serial
      parameters:
        - in: query
          name: gtin
          schema:
            description: >-
              GTIN-8/12/13/14 of the scanned unit. Normalized to GTIN-14; check
              digit is validated.
            pattern: ^[0-9]{8}$|^[0-9]{12,14}$
            title: Gtin
            type: string
          required: true
          description: >-
            GTIN-8/12/13/14 of the scanned unit. Normalized to GTIN-14; check
            digit is validated.
        - in: query
          name: serial
          schema:
            description: GS1 AI(21) serial number of the scanned unit.
            maxLength: 255
            minLength: 1
            title: Serial
            type: string
          required: true
          description: GS1 AI(21) serial number of the scanned unit.
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SerialVerificationSchema'
        '400':
          description: Bad Request
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '401':
          description: Unauthorized
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '403':
          description: Forbidden
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '404':
          description: Not Found
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '405':
          description: Method Not Allowed
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '422':
          description: Unprocessable Content
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '429':
          description: Too Many Requests
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
      security:
        - APIKeyHeaderAuth: []
        - OAuthTokenAuth: []
        - CookieGatedSessionAuth: []
components:
  schemas:
    SerialVerificationSchema:
      description: Decision object for one GTIN + serial.
      examples:
        - decision: sold
          gtin: '00614524740108'
          lot: L2847
          sale_transaction_reference: TXN-88213
          serial: ABC123XYZ
          sold_at: '2026-07-15T14:32:00Z'
      properties:
        decision:
          $ref: '#/components/schemas/VerificationDecisionEnum'
          description: >-
            The verdict. ``recalled_lot`` outranks the lifecycle states — when a
            unit is under an open recall it is reported as such whether or not
            it was sold, and the sale/return fields below remain populated.
        gtin:
          description: Normalized GTIN-14 the decision was computed for.
          title: Gtin
          type: string
        serial:
          description: GS1 AI(21) serial number the decision was computed for.
          title: Serial
          type: string
        lot:
          anyOf:
            - type: string
            - type: 'null'
          description: GS1 AI(10) lot identifier recorded for this unit, when known.
          title: Lot
        sold_at:
          anyOf:
            - format: date-time
              type: string
            - type: 'null'
          description: Event time of the sale, when this organization has recorded one.
          title: Sold At
        sale_transaction_reference:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            bizTransaction identifier carried on the sale event, scoped to this
            organization.
          title: Sale Transaction Reference
        returned_at:
          anyOf:
            - format: date-time
              type: string
            - type: 'null'
          description: >-
            Event time of the recorded return, when the unit has already come
            back.
          title: Returned At
        recall:
          anyOf:
            - $ref: '#/components/schemas/RecallNoticeSchema'
            - type: 'null'
          description: Populated only when ``decision`` is ``recalled_lot``.
      required:
        - decision
        - gtin
        - serial
      title: SerialVerificationSchema
      type: object
    ErrorOut:
      description: |-
        RFC 9457 Problem Details response.

        All API errors are returned in this format with Content-Type:
        application/problem+json.
      examples:
        - detail: The requested resource was not found.
          error_code: not_found
          retryable: false
          status: 404
          timestamp: '2026-03-31T12:00:00+00:00'
          title: Not Found
          type: https://closient.com/docs/errors/not_found
        - detail: Validation error.
          details:
            - loc:
                - body
                - name
              msg: Field required
              type: missing
          error_code: validation_error
          retryable: false
          status: 422
          timestamp: '2026-03-31T12:00:00+00:00'
          title: Validation Error
          type: https://closient.com/docs/errors/validation_error
        - detail: Rate limit exceeded. Please try again later.
          error_code: rate_limited
          retry_after: 31
          retryable: true
          status: 429
          timestamp: '2026-03-31T12:00:00+00:00'
          title: Rate Limited
          type: https://closient.com/docs/errors/rate_limited
      properties:
        type:
          description: URI reference identifying the error type.
          title: Type
          type: string
        title:
          description: Short human-readable summary of the error.
          title: Title
          type: string
        status:
          description: HTTP status code.
          title: Status
          type: integer
        detail:
          description: Human-readable explanation of this specific occurrence.
          title: Detail
          type: string
        error_code:
          description: Machine-readable error code (e.g. not_found, unauthorized).
          title: Error Code
          type: string
        retryable:
          default: false
          description: Whether retrying the same request can succeed.
          title: Retryable
          type: boolean
        timestamp:
          description: ISO 8601 timestamp of when the error occurred.
          title: Timestamp
          type: string
        retry_after:
          anyOf:
            - type: integer
            - type: 'null'
          description: Seconds to wait before retrying (when applicable).
          title: Retry After
        owner_action_required:
          anyOf:
            - type: boolean
            - type: 'null'
          description: Whether the error requires account owner intervention.
          title: Owner Action Required
        details:
          description: Additional context (validation errors, etc.).
          title: Details
      required:
        - type
        - title
        - status
        - detail
        - error_code
        - timestamp
      title: ErrorOut
      type: object
    VerificationDecisionEnum:
      description: |-
        Verdict for one GTIN + serial verification.

        Exactly one value is returned per call. ``RECALLED_LOT`` is evaluated
        first and outranks every lifecycle state — see :func:`verify_serial`.
      enum:
        - sold
        - already_returned
        - never_sold
        - unknown_serial
        - recalled_lot
      title: VerificationDecisionEnum
      type: string
    RecallNoticeSchema:
      description: The open recall that produced a ``recalled_lot`` decision.
      examples:
        - lot: L2847
          recall_id: RCL-2026-04821
          severity: FDA Class II
          title: 'Voluntary recall: undeclared allergen'
      properties:
        recall_id:
          description: Identifier of the open recall covering this unit.
          title: Recall Id
          type: string
        title:
          description: Human-readable recall title.
          title: Title
          type: string
        severity:
          description: Recall severity classification (e.g. FDA Class I/II/III).
          title: Severity
          type: string
        lot:
          description: Lot identifier of the unit that matched the recall's scope.
          title: Lot
          type: string
      required:
        - recall_id
        - title
        - severity
        - lot
      title: RecallNoticeSchema
      type: object
  securitySchemes:
    APIKeyHeaderAuth:
      type: apiKey
      in: header
      name: X-API-Key
    OAuthTokenAuth:
      type: http
      scheme: bearer
    CookieGatedSessionAuth:
      type: apiKey
      in: cookie
      name: sessionid

````