One thesis: running a GS1-conformant Digital Link resolver requires no permission, no membership, and no license fee — the standard is royalty-free by GS1's own IP policy and ownership-agnostic by its own text — so the diligence question for a resolver layer is never "may we operate one?" but "what may lawfully populate the links?"
This post exists because the first question a careful engineering executive asks about this category is a legal one, and the answer happens to be unusually clean and unusually well documented. Here are the documents.
The standard, and what conformance actually requires
The GS1-Conformant Resolver standard, version 1.2.0, ratified January 2026, is freely downloadable from ref.gs1.org/standards/resolver. It defines roughly twenty-five normative requirements; the load-bearing ones, restated in our own words:
- A resolver description file at
/.well-known/gs1resolver(the RFC 8615 well-known-URI mechanism), declaring which primary key types this resolver serves. The description file is the resolver's honest scope statement, machine-readable, at a path every client knows to check. - Linkset behavior per RFC 9264. When a client asks for the link catalog —
linkType=linkset, or content-negotiatesapplication/linkset+json— the resolver "SHALL NOT redirect but SHALL return a full list of links." The list, not a guess: the client gets every typed door and chooses. - Typed links from the GS1 Web Vocabulary, with exactly one
gs1:defaultLinkper entity — the answer when the client expresses no preference — and redirect-to-default behavior unless the request selects something better. - Honest failure semantics: 404 when a requested linkType is not available for that identifier — never a soft landing on a marketing page — and 400 for a syntactically invalid Digital Link URI.
Nothing in that list is exotic engineering. It is web plumbing with discipline — which is rather the point: the standard makes a resolver a predictable piece of infrastructure rather than a clever one.
The permission question, answered from the IP policy
The GS1 IP Policy governs implementation of GS1 standards, and its terms are quotable: §4.A grants a license that is "non-exclusive, worldwide, royalty-free, fully paid-up, perpetual, irrevocable"; §4.C(1) goes further and prohibits covered parties from charging "to use or access GS1 Standards, which are provided freely by GS1." The resolver standard, the Digital Link URI syntax, and the General Specifications all sit under that policy, served as free downloads from GS1's own reference platform.
And the standard is ownership-agnostic. Nothing in its text restricts resolver operation to GTIN owners, GS1 members, or anyone else; the /.well-known/gs1resolver description file exists precisely so that any resolver declares what it serves and clients evaluate it on that declaration. GS1's own resolver at id.gs1.org — whose live description file declares seventeen primary key types — is the canonical default in the ecosystem, not a monopoly in the architecture. The design is plural by construction: brand resolvers, sector resolvers, third-party resolvers, all conformant, all discoverable the same way.
So the category is legally open. Which means the interesting constraint is the one the permission question was hiding.
The actual constraint: license-clean links
A resolver's value is its linkset, and every link in a linkset points at data — and data, unlike the standard, is where licenses live. The GS1 data rails short of a negotiated agreement are display-and-verify scoped; the aggregator tier's terms are redistribution-hostile; none of it can lawfully become resolver-served content. A conformant resolver stuffed with links into data its operator has no right to serve is conformant plumbing wrapped around a liability.
That is the discipline this resolver runs on: link targets come from license-clean sources only — public-domain and openly-licensed rails, brand-published resolvers (resolved through, never replaced), and the family's own record layers — with every link carrying its provenance, so a client can see not just where a door leads but on what authority it is listed. The conformance requirements say what a resolver must do; the license discipline says what this one will and will not point at. Both halves are published.
The boundary, drawn precisely
For GS1 primary keys — GTIN, SSCC, GLN and their kin — this resolver is conformant to the standard: description file, RFC 9264 linksets, gs1:defaultLink, 404/400 semantics as specified. The same contract is then extended to schemes the standard does not cover — a VIN, an ISBN (itself a GTIN-13 by prefix), a UDI, an NDC — through the same /.well-known/-described door with the same linkset shape. Conformant to the standard; explicit about everything beyond it. The extension is labeled as an extension everywhere it appears, because a resolver whose scope statement is honest is the only kind worth federating with — and the description file is exactly where that honesty is machine-checkable. How far the generalization goes is the hub post; what a provenance-carrying linkset looks like, entry by entry, is its own post in this arc.
What this de-risks for you
If your product needs resolution — a scan landing somewhere governed, a pack URL answering to your customer's systems, a linkset your integrations can type against — the diligence summary is one paragraph: the standard is free and royalty-free; operation is unrestricted by ownership; conformance is ~25 checkable requirements; the entire risk surface is the licensing of link targets, which is a data-sourcing discipline, not a standards problem. You could run your own; the standard was written so you could. Whether you should — against the maintenance tax of description files, vocabulary revisions, linkset semantics, and a license posture that has to survive your clients' audits — is the usual build-vs-buy arithmetic on a pinned-spec surface.
The hosted resolution door — resolution itself is id.org.ai's, served through it — is the gated half of this property: conformant for GS1 keys, extended and labeled for the rest, every link provenance-pinned. Tell us who you are, and bring the identifier schemes you actually serve — the branching questions ask.
Keys open the network half of the verb set. Get an API key — say what arrives at your door, and the provisioning order follows the list.
We answer in writing. We take at most five conversations a month, only when you ask for one, and only after you already have the written read.