curl --request POST \
--url https://www.closient.com/scanner/api/v1/resolve-url \
--header 'Content-Type: application/json' \
--header 'X-API-Key: <api-key>' \
--data '
{
"url": "https://qr.brand.example/p/12345"
}
'import requests
url = "https://www.closient.com/scanner/api/v1/resolve-url"
payload = { "url": "https://qr.brand.example/p/12345" }
headers = {
"X-API-Key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'X-API-Key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({url: 'https://qr.brand.example/p/12345'})
};
fetch('https://www.closient.com/scanner/api/v1/resolve-url', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://www.closient.com/scanner/api/v1/resolve-url",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'url' => 'https://qr.brand.example/p/12345'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://www.closient.com/scanner/api/v1/resolve-url"
payload := strings.NewReader("{\n \"url\": \"https://qr.brand.example/p/12345\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-API-Key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://www.closient.com/scanner/api/v1/resolve-url")
.header("X-API-Key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"url\": \"https://qr.brand.example/p/12345\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://www.closient.com/scanner/api/v1/resolve-url")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-API-Key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"url\": \"https://qr.brand.example/p/12345\"\n}"
response = http.request(request)
puts response.read_body{
"chain": [
"https://qr.brand.example/p/12345",
"http://brand.example/products/widget",
"https://www.brand.example/products/widget"
],
"error_message": "",
"final_url": "https://www.brand.example/products/widget",
"hops": 2,
"initial_url": "https://qr.brand.example/p/12345",
"succeeded": true
}{
"detail": "The requested resource was not found.",
"error_code": "not_found",
"retryable": false,
"status": 404,
"timestamp": "2026-03-31T12:00:00+00:00",
"title": "Not Found",
"type": "https://closient.com/docs/errors/not_found"
}{
"detail": "The requested resource was not found.",
"error_code": "not_found",
"retryable": false,
"status": 404,
"timestamp": "2026-03-31T12:00:00+00:00",
"title": "Not Found",
"type": "https://closient.com/docs/errors/not_found"
}{
"detail": "The requested resource was not found.",
"error_code": "not_found",
"retryable": false,
"status": 404,
"timestamp": "2026-03-31T12:00:00+00:00",
"title": "Not Found",
"type": "https://closient.com/docs/errors/not_found"
}{
"detail": "The requested resource was not found.",
"error_code": "not_found",
"retryable": false,
"status": 404,
"timestamp": "2026-03-31T12:00:00+00:00",
"title": "Not Found",
"type": "https://closient.com/docs/errors/not_found"
}{
"detail": "The requested resource was not found.",
"error_code": "not_found",
"retryable": false,
"status": 404,
"timestamp": "2026-03-31T12:00:00+00:00",
"title": "Not Found",
"type": "https://closient.com/docs/errors/not_found"
}{}{
"detail": "The requested resource was not found.",
"error_code": "not_found",
"retryable": false,
"status": 404,
"timestamp": "2026-03-31T12:00:00+00:00",
"title": "Not Found",
"type": "https://closient.com/docs/errors/not_found"
}Resolve a QR code URL
Follow the HTTP redirect chain for a QR code URL captured from product packaging and return the final canonical URL plus the intermediate hops.
Used by the dual-scan flow: after the operator scans a QR code, the client posts the URL here, displays the resolved value, and (if accepted) calls /captures/{id}/save-redirect to persist it as a redirect rule on the trade item.
Behavior:
- Follows up to 10 HTTP 3xx redirects (301/302/303/307/308).
- Refuses any hop whose host resolves to a non-public address (loopback, private, link-local/cloud-metadata, CGNAT, IPv6 ULA and similar); each redirect is re-checked and the connection is pinned to the checked address. The refusal reason is returned in
error_message(e.g.Refused: URL resolves to a non-public address.). - 5-second timeout per connect/read and 10 seconds for the whole chain; surfaces the error in
error_messagerather than failing the request when the URL is unreachable. - The final page body is not downloaded.
- HTTPS upgrades (302 →
https://) are followed transparently. - meta-refresh HTML redirects are NOT followed in v1 — known limitation; document this in the brand-manager UI.
- Tracking-parameter stripping is out of scope for v1; the URL is returned exactly as the final hop reports it.
curl --request POST \
--url https://www.closient.com/scanner/api/v1/resolve-url \
--header 'Content-Type: application/json' \
--header 'X-API-Key: <api-key>' \
--data '
{
"url": "https://qr.brand.example/p/12345"
}
'import requests
url = "https://www.closient.com/scanner/api/v1/resolve-url"
payload = { "url": "https://qr.brand.example/p/12345" }
headers = {
"X-API-Key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'X-API-Key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({url: 'https://qr.brand.example/p/12345'})
};
fetch('https://www.closient.com/scanner/api/v1/resolve-url', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://www.closient.com/scanner/api/v1/resolve-url",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'url' => 'https://qr.brand.example/p/12345'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://www.closient.com/scanner/api/v1/resolve-url"
payload := strings.NewReader("{\n \"url\": \"https://qr.brand.example/p/12345\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-API-Key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://www.closient.com/scanner/api/v1/resolve-url")
.header("X-API-Key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"url\": \"https://qr.brand.example/p/12345\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://www.closient.com/scanner/api/v1/resolve-url")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-API-Key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"url\": \"https://qr.brand.example/p/12345\"\n}"
response = http.request(request)
puts response.read_body{
"chain": [
"https://qr.brand.example/p/12345",
"http://brand.example/products/widget",
"https://www.brand.example/products/widget"
],
"error_message": "",
"final_url": "https://www.brand.example/products/widget",
"hops": 2,
"initial_url": "https://qr.brand.example/p/12345",
"succeeded": true
}{
"detail": "The requested resource was not found.",
"error_code": "not_found",
"retryable": false,
"status": 404,
"timestamp": "2026-03-31T12:00:00+00:00",
"title": "Not Found",
"type": "https://closient.com/docs/errors/not_found"
}{
"detail": "The requested resource was not found.",
"error_code": "not_found",
"retryable": false,
"status": 404,
"timestamp": "2026-03-31T12:00:00+00:00",
"title": "Not Found",
"type": "https://closient.com/docs/errors/not_found"
}{
"detail": "The requested resource was not found.",
"error_code": "not_found",
"retryable": false,
"status": 404,
"timestamp": "2026-03-31T12:00:00+00:00",
"title": "Not Found",
"type": "https://closient.com/docs/errors/not_found"
}{
"detail": "The requested resource was not found.",
"error_code": "not_found",
"retryable": false,
"status": 404,
"timestamp": "2026-03-31T12:00:00+00:00",
"title": "Not Found",
"type": "https://closient.com/docs/errors/not_found"
}{
"detail": "The requested resource was not found.",
"error_code": "not_found",
"retryable": false,
"status": 404,
"timestamp": "2026-03-31T12:00:00+00:00",
"title": "Not Found",
"type": "https://closient.com/docs/errors/not_found"
}{}{
"detail": "The requested resource was not found.",
"error_code": "not_found",
"retryable": false,
"status": 404,
"timestamp": "2026-03-31T12:00:00+00:00",
"title": "Not Found",
"type": "https://closient.com/docs/errors/not_found"
}Authorizations
Body
Request body for following the redirect chain of a captured QR URL.
QR code URL to resolve. Must be http:// or https://; non-HTTP schemes are rejected with error_message populated in the response (the request itself does not 4xx — failure modes are surfaced uniformly so the UI can render a single error path).
1 - 2048Response
OK
Result of following the redirect chain for a QR code URL.
The URL submitted by the caller.
Final URL after following all redirects. Equal to initial_url when no redirects were followed and when an error short-circuited the chain (so the UI always has a URL to show alongside error_message).
Number of HTTP 3xx redirects followed before reaching the final URL. Capped at 10 — chains longer than that surface as an error_message rather than a partial result.
x >= 0Empty on success. On failure, a human-readable description of the error (timeout, connection refused, too many redirects, malformed URL). The UI surfaces this string directly to the operator.
True when error_message is empty.
Ordered list of URLs visited, starting with initial_url and ending with final_url. Empty when an error short-circuited resolution before any response was received.