> ## Documentation Index
> Fetch the complete documentation index at: https://docs.closient.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Validate a GS1 Digital Link URI against the specification

> Grade a candidate URI for GS1 Digital Link conformance and return every issue found, each with a stable `code`, a `severity`, and a human-readable `message`.

A non-conformant URI is a `200` with `is_conformant: false` — that is the *answer* to a validation question, not a failed request.

**Keyless** — no API key, no signup. IP-throttled at 300 requests/minute and cached at the edge for 24h, so repeat calls for the same input do not reach origin. Over-rate callers get a `429` with a `Retry-After` header and a `retry_after` field — it never silently degrades or returns a wrong answer under load.



## OpenAPI

````yaml /openapi/openapi-resolver.json get /resolver/api/v1/public/gs1/validate
openapi: 3.1.0
info:
  title: Resolver API
  version: 1.0.0
  description: >
    GS1 Digital Link resolution with content negotiation and linkset support.


    ## Authentication


    All endpoints require an API key passed via the `X-API-Key` HTTP header,
    unless otherwise noted.


    ```

    X-API-Key: csb_<body>_<checksum>

    ```


    Generate API keys in **Settings > API Keys** in your dashboard, or via the
    Account API.

    Session-based (cookie) authentication is also accepted for browser-based
    access.


    ## Rate Limits


    | Tier        | Requests / minute | Requests / day |

    |-------------|-------------------|----------------|

    | Default     | 300               | 10,000         |

    | Custom      | Contact us        | Contact us     |


    Rate-limit headers are included on every response so callers can
    self-throttle without

    hitting our 429s ("informed governor"):


    - `RateLimit-Policy` — every active window, e.g. `300;w=60, 10000;w=86400`

    - `RateLimit-Limit` — quota for the **most-restrictive** currently-active
    window

    - `RateLimit-Remaining` — requests left in that window

    - `RateLimit-Reset` — seconds until that window resets (relative; clock-skew
    safe)


    Legacy `X-RateLimit-*` aliases are also emitted for back-compat.
    `X-RateLimit-Reset`

    keeps the absolute Unix-timestamp shape to avoid breaking existing
    consumers.


    When rate-limited, you receive `429 Too Many Requests` with a
    `retry_after_seconds` field

    in the error envelope and a `Retry-After` header.


    ## Pagination


    List endpoints return paginated results in this envelope:


    ```json

    {
      "data": [...],
      "pagination": {
        "page": 1,
        "page_size": 25,
        "total_count": 342,
        "total_pages": 14,
        "has_next": true,
        "has_previous": false
      }
    }

    ```


    Use `?page=2&page_size=50` query parameters. Maximum page size is 100.


    ## Error Responses


    All errors conform to [RFC 9457 Problem
    Details](https://www.rfc-editor.org/rfc/rfc9457)

    with `Content-Type: application/problem+json`:


    ```json

    {
      "type": "https://closient.com/docs/errors/not_found",
      "title": "Not Found",
      "status": 404,
      "detail": "The requested resource was not found.",
      "error_code": "not_found",
      "retryable": false,
      "timestamp": "2026-03-31T12:00:00+00:00"
    }

    ```


    Common error codes: `unauthorized` (401), `forbidden` (403), `not_found`
    (404),

    `validation_error` (422), `rate_limited` (429), `internal_error` (500).
  termsOfService: https://www.closient.com/terms/
servers:
  - url: https://www.closient.com
security: []
tags:
  - name: Resolver
    description: GS1 Digital Link resolution with content negotiation and linkset support.
  - name: Custom URLs
    description: >-
      Reusable custom-URL catalog (C-3339) — create, list, edit, and delete the
      custom redirect destinations that resolution rules point at.
  - name: Verification
    description: >-
      Serial verification (`gs1:verificationService`) — tiered, rate-limited
      responses for serialized GTIN scans. Experimental v1; see the
      verification-service guide.
  - name: GS1 Primitives (Public)
    description: >-
      Keyless GS1 Digital Link primitives (C-4295) — parse, validate, build,
      decompress, and check-digit analysis. **No API key, no signup.** Pure
      functions over strings: no database, no network, no catalog data.
      IP-throttled and edge-cached so repeat calls cost nothing. This is the
      reference implementation the resolver itself runs on.
  - name: Resolver Custom Hostnames
    description: >-
      BYO domain (C-4058) — register a customer-owned hostname, publish the
      CNAME records, verify ownership, and serve an org's Digital Link QRs from
      its own DNS.
externalDocs:
  description: Closient Documentation
  url: https://docs.closient.com
paths:
  /resolver/api/v1/public/gs1/validate:
    get:
      tags:
        - GS1 Primitives (Public)
      summary: Validate a GS1 Digital Link URI against the specification
      description: >-
        Grade a candidate URI for GS1 Digital Link conformance and return every
        issue found, each with a stable `code`, a `severity`, and a
        human-readable `message`.


        A non-conformant URI is a `200` with `is_conformant: false` — that is
        the *answer* to a validation question, not a failed request.


        **Keyless** — no API key, no signup. IP-throttled at 300 requests/minute
        and cached at the edge for 24h, so repeat calls for the same input do
        not reach origin. Over-rate callers get a `429` with a `Retry-After`
        header and a `retry_after` field — it never silently degrades or returns
        a wrong answer under load.
      operationId: apps_resolver_api_public_gs1_validate_digital_link_public
      parameters:
        - in: query
          name: uri
          schema:
            description: >-
              The candidate GS1 Digital Link URI to grade. Example:
              `https://id.gs1.org/01/09506000164908/10/LOT1?17=261231`
            maxLength: 4096
            minLength: 1
            title: Uri
            type: string
          required: true
          description: >-
            The candidate GS1 Digital Link URI to grade. Example:
            `https://id.gs1.org/01/09506000164908/10/LOT1?17=261231`
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DigitalLinkReportOut'
components:
  schemas:
    DigitalLinkReportOut:
      description: Full conformance report for a candidate Digital Link URI.
      examples:
        - canonical_path: /01/09506000164908/10/LOT1
          data_attributes:
            - code: '17'
              name: Expiration date
              value: '261231'
          host: id.gs1.org
          is_conformant: true
          issues: []
          primary:
            code: '01'
            description: Global Trade Item Number
            kind: primary
            name: GTIN
            value: '09506000164908'
          qualifiers:
            - code: '10'
              description: Batch or lot number
              kind: qualifier
              name: Batch/Lot
              value: LOT1
          scheme: https
          uri: https://id.gs1.org/01/09506000164908/10/LOT1?17=261231
      properties:
        uri:
          description: The input URI, echoed back unchanged.
          title: Uri
          type: string
        is_conformant:
          description: >-
            True when the URI carries no `error`-severity issues. Warnings do
            not affect this flag.
          title: Is Conformant
          type: boolean
        issues:
          description: >-
            Every issue found, errors and warnings together, in the order the
            validator produced them.
          items:
            $ref: '#/components/schemas/DigitalLinkIssueOut'
          title: Issues
          type: array
        scheme:
          anyOf:
            - type: string
            - type: 'null'
          description: URI scheme, or `null` when the input could not be split.
          examples:
            - https
          title: Scheme
        host:
          anyOf:
            - type: string
            - type: 'null'
          description: URI host, or `null` when the input could not be split.
          examples:
            - id.gs1.org
          title: Host
        primary:
          anyOf:
            - $ref: '#/components/schemas/ParsedAIOut'
            - type: 'null'
          description: The primary identifier AI, or `null` when none was recognised.
        qualifiers:
          description: Qualifier AIs found in the path, in path order.
          items:
            $ref: '#/components/schemas/ParsedAIOut'
          title: Qualifiers
          type: array
        data_attributes:
          description: Data attributes found on the query string.
          items:
            $ref: '#/components/schemas/ParsedDataAttributeOut'
          title: Data Attributes
          type: array
        canonical_path:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            The spec-canonical path for this identifier set, or `null` when no
            primary AI was recognised.
          title: Canonical Path
      required:
        - uri
        - is_conformant
      title: DigitalLinkReportOut
      type: object
    DigitalLinkIssueOut:
      description: One pass/fail row from a validation or build report.
      examples:
        - code: invalid_check_digit
          message: 'GTIN check digit is invalid: expected 8, got 7.'
          severity: error
      properties:
        code:
          description: >-
            Stable machine-readable issue code, safe to branch on (e.g.
            `unknown_primary_ai`).
          title: Code
          type: string
        severity:
          $ref: '#/components/schemas/DigitalLinkIssueSeverityEnum'
          description: >-
            `error` blocks conformance; `warning` is advisory and leaves
            `is_conformant` intact.
        message:
          description: Human-readable explanation of the issue.
          title: Message
          type: string
      required:
        - code
        - severity
        - message
      title: DigitalLinkIssueOut
      type: object
    ParsedAIOut:
      description: One Application Identifier extracted from (or composed into) a URI.
      examples:
        - code: '01'
          description: >-
            Global Trade Item Number — the primary key identifying the trade
            item.
          kind: primary
          name: GTIN
          value: '09506000164908'
      properties:
        code:
          description: The GS1 Application Identifier code.
          examples:
            - '01'
          title: Code
          type: string
        name:
          description: Human-readable AI name.
          examples:
            - GTIN
          title: Name
          type: string
        kind:
          $ref: '#/components/schemas/DigitalLinkAIKindEnum'
          description: >-
            Whether the AI identifies the item (`primary`), narrows it
            (`qualifier`), or describes it (`attribute`).
        value:
          description: The AI's value as it appears in the URI.
          examples:
            - '09506000164908'
          title: Value
          type: string
        description:
          description: What this AI means in the GS1 General Specifications.
          title: Description
          type: string
      required:
        - code
        - name
        - kind
        - value
        - description
      title: ParsedAIOut
      type: object
    ParsedDataAttributeOut:
      description: One query-string data attribute from a parsed URI.
      examples:
        - code: '17'
          name: Expiration date
          value: '261231'
      properties:
        code:
          description: The GS1 Application Identifier code.
          examples:
            - '17'
          title: Code
          type: string
        name:
          description: Human-readable AI name.
          examples:
            - Expiration date
          title: Name
          type: string
        value:
          description: The attribute's value as it appears in the query string.
          examples:
            - '261231'
          title: Value
          type: string
        format_error:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            Why this attribute's value is malformed, or `null` when it conforms
            (or is not graded).
          title: Format Error
      required:
        - code
        - name
        - value
      title: ParsedDataAttributeOut
      type: object
    DigitalLinkIssueSeverityEnum:
      description: |-
        Whether a Digital Link report row blocks conformance or only advises.

        Mirrors the ``Literal["error", "warning"]`` on
        :class:`apps.resolver.gs1_digital_link_validator.ValidationIssue`. An
        ``ERROR`` is what drives ``is_conformant`` to ``false``; a ``WARNING``
        is spec-legal but discouraged (an uppercase host, say) and leaves
        conformance intact.
      enum:
        - error
        - warning
      title: DigitalLinkIssueSeverityEnum
      type: string
    DigitalLinkAIKindEnum:
      description: |-
        Where an Application Identifier sits in a Digital Link URI.

        ``PRIMARY`` is the identifying key (AI 01 GTIN, 414 GLN, 00 SSCC, ...)
        and there is exactly one. ``QUALIFIER`` narrows that key within the URI
        path (AI 10 lot, 21 serial, 22 CPV). ``ATTRIBUTE`` rides on the query
        string and carries data *about* the item (AI 17 expiry, 3103 net
        weight) rather than identifying it.
      enum:
        - primary
        - qualifier
        - attribute
      title: DigitalLinkAIKindEnum
      type: string

````