> ## Documentation Index
> Fetch the complete documentation index at: https://docs.closient.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Which Application Identifiers belong on the pack, per scan context

> Anything that must produce a decision without a network connection goes on the pack. Everything else is a pointer.

Each row classifies one AI for one scan context (consumer scan, retail POS, supply chain AIDC) as `on_pack_required`, `on_pack_recommended` or `server_side_eligible`, with a rationale. Supply chain AIDC is its own context because a receiving dock running a recall check on a pallet with no signal needs the lot on the pack, where a consumer scan does not.

Placement is advisory: the URI grammar decides where an AI sits and which qualifiers are mandatory, and following a recommendation never yields a non-conformant URI. AIs the standard forbids in a Digital Link are omitted.

**Keyless** — no API key, no signup. IP-throttled at 300 requests/minute and cached at the edge for 24h, so repeat calls for the same input do not reach origin. Over-rate callers get a `429` with a `Retry-After` header and a `retry_after` field — it never silently degrades or returns a wrong answer under load.



## OpenAPI

````yaml /openapi/openapi-resolver.json get /resolver/api/v1/public/gs1/placement
openapi: 3.1.0
info:
  title: Resolver API
  version: 1.0.0
  description: >
    GS1 Digital Link resolution with content negotiation and linkset support.


    ## Authentication


    All endpoints require an API key passed via the `X-API-Key` HTTP header,
    unless otherwise noted.


    ```

    X-API-Key: csb_<body>_<checksum>

    ```


    Generate API keys in **Settings > API Keys** in your dashboard, or via the
    Account API.

    Session-based (cookie) authentication is also accepted for browser-based
    access.


    ## Rate Limits


    | Tier        | Requests / minute | Requests / day |

    |-------------|-------------------|----------------|

    | Default     | 300               | 10,000         |

    | Custom      | Contact us        | Contact us     |


    Rate-limit headers are included on every response so callers can
    self-throttle without

    hitting our 429s ("informed governor"):


    - `RateLimit-Policy` — every active window, e.g. `300;w=60, 10000;w=86400`

    - `RateLimit-Limit` — quota for the **most-restrictive** currently-active
    window

    - `RateLimit-Remaining` — requests left in that window

    - `RateLimit-Reset` — seconds until that window resets (relative; clock-skew
    safe)


    Legacy `X-RateLimit-*` aliases are also emitted for back-compat.
    `X-RateLimit-Reset`

    keeps the absolute Unix-timestamp shape to avoid breaking existing
    consumers.


    When rate-limited, you receive `429 Too Many Requests` with a
    `retry_after_seconds` field

    in the error envelope and a `Retry-After` header.


    ## Pagination


    List endpoints return paginated results in this envelope:


    ```json

    {
      "data": [...],
      "pagination": {
        "page": 1,
        "page_size": 25,
        "total_count": 342,
        "total_pages": 14,
        "has_next": true,
        "has_previous": false
      }
    }

    ```


    Use `?page=2&page_size=50` query parameters. Maximum page size is 100.


    ## Error Responses


    All errors conform to [RFC 9457 Problem
    Details](https://www.rfc-editor.org/rfc/rfc9457)

    with `Content-Type: application/problem+json`:


    ```json

    {
      "type": "https://closient.com/docs/errors/not_found",
      "title": "Not Found",
      "status": 404,
      "detail": "The requested resource was not found.",
      "error_code": "not_found",
      "retryable": false,
      "timestamp": "2026-03-31T12:00:00+00:00"
    }

    ```


    Common error codes: `unauthorized` (401), `forbidden` (403), `not_found`
    (404),

    `validation_error` (422), `rate_limited` (429), `internal_error` (500).
  termsOfService: https://www.closient.com/terms/
servers:
  - url: https://www.closient.com
security: []
tags:
  - name: Resolver
    description: GS1 Digital Link resolution with content negotiation and linkset support.
  - name: Custom URLs
    description: >-
      Reusable custom-URL catalog (C-3339) — create, list, edit, and delete the
      custom redirect destinations that resolution rules point at.
  - name: Verification
    description: >-
      Serial verification (`gs1:verificationService`) — tiered, rate-limited
      responses for serialized GTIN scans. Experimental v1; see the
      verification-service guide.
  - name: GS1 Primitives (Public)
    description: >-
      Keyless GS1 Digital Link primitives (C-4295) — parse, validate, build,
      decompress, and check-digit analysis. **No API key, no signup.** Pure
      functions over strings: no database, no network, no catalog data.
      IP-throttled and edge-cached so repeat calls cost nothing. This is the
      reference implementation the resolver itself runs on.
  - name: Resolver Custom Hostnames
    description: >-
      BYO domain (C-4058) — register a customer-owned hostname, publish the
      CNAME records, verify ownership, and serve an org's Digital Link QRs from
      its own DNS.
externalDocs:
  description: Closient Documentation
  url: https://docs.closient.com
paths:
  /resolver/api/v1/public/gs1/placement:
    get:
      tags:
        - GS1 Primitives (Public)
      summary: Which Application Identifiers belong on the pack, per scan context
      description: >-
        Anything that must produce a decision without a network connection goes
        on the pack. Everything else is a pointer.


        Each row classifies one AI for one scan context (consumer scan, retail
        POS, supply chain AIDC) as `on_pack_required`, `on_pack_recommended` or
        `server_side_eligible`, with a rationale. Supply chain AIDC is its own
        context because a receiving dock running a recall check on a pallet with
        no signal needs the lot on the pack, where a consumer scan does not.


        Placement is advisory: the URI grammar decides where an AI sits and
        which qualifiers are mandatory, and following a recommendation never
        yields a non-conformant URI. AIs the standard forbids in a Digital Link
        are omitted.


        **Keyless** — no API key, no signup. IP-throttled at 300 requests/minute
        and cached at the edge for 24h, so repeat calls for the same input do
        not reach origin. Over-rate callers get a `429` with a `Retry-After`
        header and a `retry_after` field — it never silently degrades or returns
        a wrong answer under load.
      operationId: apps_resolver_api_public_gs1_ai_placement_public
      parameters:
        - in: query
          name: ai
          schema:
            description: Only this Application Identifier, e.g. `10`.
            title: Ai
            maxLength: 8
            type: string
            pattern: ^[^\x00]{0,8}$
          required: false
          description: Only this Application Identifier, e.g. `10`.
        - in: query
          name: context
          schema:
            description: Only this scan context.
            allOf:
              - $ref: '#/components/schemas/AIScanContextEnum'
          required: false
          description: Only this scan context.
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AIPlacementOut'
        '400':
          description: Bad Request
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '404':
          description: Not Found
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '405':
          description: Method Not Allowed
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '422':
          description: Unprocessable Content
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '429':
          description: Too Many Requests
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
components:
  schemas:
    AIScanContextEnum:
      description: Who is scanning, and so what they can rely on being online.
      enum:
        - consumer_scan
        - retail_pos
        - supply_chain_aidc
      title: AIScanContextEnum
      type: string
    AIPlacementOut:
      examples:
        - principle: >-
            Anything that must produce a decision without a network connection
            goes on the pack. Everything else is a pointer.
          rows:
            - ai: '01'
              context: retail_pos
              grammar_forced: true
              grammar_position: path_key
              placement: on_pack_required
              rationale: >-
                The GTIN is the primary key of the Digital Link; the grammar
                requires it.
      properties:
        principle:
          description: The rule every row derives from.
          title: Principle
          type: string
        rows:
          description: >-
            One row per AI per scan context, after the `ai` and `context`
            filters.
          items:
            $ref: '#/components/schemas/AIPlacementRowOut'
          title: Rows
          type: array
      required:
        - principle
        - rows
      title: AIPlacementOut
      type: object
    ErrorOut:
      description: |-
        RFC 9457 Problem Details response.

        All API errors are returned in this format with Content-Type:
        application/problem+json.
      examples:
        - detail: The requested resource was not found.
          error_code: not_found
          retryable: false
          status: 404
          timestamp: '2026-03-31T12:00:00+00:00'
          title: Not Found
          type: https://closient.com/docs/errors/not_found
        - detail: Validation error.
          details:
            - loc:
                - body
                - name
              msg: Field required
              type: missing
          error_code: validation_error
          retryable: false
          status: 422
          timestamp: '2026-03-31T12:00:00+00:00'
          title: Validation Error
          type: https://closient.com/docs/errors/validation_error
        - detail: Rate limit exceeded. Please try again later.
          error_code: rate_limited
          retry_after: 31
          retryable: true
          status: 429
          timestamp: '2026-03-31T12:00:00+00:00'
          title: Rate Limited
          type: https://closient.com/docs/errors/rate_limited
      properties:
        type:
          description: URI reference identifying the error type.
          title: Type
          type: string
        title:
          description: Short human-readable summary of the error.
          title: Title
          type: string
        status:
          description: HTTP status code.
          title: Status
          type: integer
        detail:
          description: Human-readable explanation of this specific occurrence.
          title: Detail
          type: string
        error_code:
          description: Machine-readable error code (e.g. not_found, unauthorized).
          title: Error Code
          type: string
        retryable:
          default: false
          description: Whether retrying the same request can succeed.
          title: Retryable
          type: boolean
        timestamp:
          description: ISO 8601 timestamp of when the error occurred.
          title: Timestamp
          type: string
        retry_after:
          anyOf:
            - type: integer
            - type: 'null'
          description: Seconds to wait before retrying (when applicable).
          title: Retry After
        owner_action_required:
          anyOf:
            - type: boolean
            - type: 'null'
          description: Whether the error requires account owner intervention.
          title: Owner Action Required
        details:
          description: Additional context (validation errors, etc.).
          title: Details
      required:
        - type
        - title
        - status
        - detail
        - error_code
        - timestamp
      title: ErrorOut
      type: object
    AIPlacementRowOut:
      description: One AI's placement recommendation in one scan context.
      examples:
        - ai: '17'
          context: consumer_scan
          grammar_forced: false
          grammar_position: query_attribute
          placement: server_side_eligible
          rationale: >-
            Expiry can be looked up when the scanner is online; a consumer scan
            has a network.
      properties:
        ai:
          description: The Application Identifier, e.g. `17`.
          title: Ai
          type: string
        context:
          $ref: '#/components/schemas/AIScanContextEnum'
          description: The scan context this row applies to.
        placement:
          $ref: '#/components/schemas/AIPlacementEnum'
          description: Where to put this AI for this context.
        rationale:
          description: Why. Every row carries one; none is an unexplained opinion.
          title: Rationale
          type: string
        grammar_position:
          $ref: '#/components/schemas/AIGrammarPositionEnum'
          description: >-
            Where the URI grammar places the AI if it is encoded. Fixed by the
            standard, not by placement: data attributes are only ever in the
            query string (URI Syntax 1.7.0 section 4.10).
        grammar_forced:
          description: >-
            True when the grammar makes this AI mandatory, so it is on-pack
            whatever else applies.
          title: Grammar Forced
          type: boolean
      required:
        - ai
        - context
        - placement
        - rationale
        - grammar_position
        - grammar_forced
      title: AIPlacementRowOut
      type: object
    AIPlacementEnum:
      description: |-
        Where an Application Identifier belongs for a scan context (C-4782).

        Advisory only: the URI grammar decides where an AI sits and which are
        mandatory, and a recommendation never produces a non-conformant URI.
      enum:
        - on_pack_required
        - on_pack_recommended
        - server_side_eligible
      title: AIPlacementEnum
      type: string
    AIGrammarPositionEnum:
      description: Where the URI grammar puts the AI, whatever its placement.
      enum:
        - path_key
        - path_qualifier
        - query_attribute
      title: AIGrammarPositionEnum
      type: string

````