# barcoding.dev — llms.txt > The universal barcode and identifier layer of the visibility.cloud > family (the third dark developer door, beside epcis.dev and transactions.dev). > resolve / verify / generate are pure and local on every scheme — GS1 > (GTIN/GLN/SSCC/Digital Link), VIN, ISBN, UDI, NDC, tracking numbers. enrich > answers from license-clean rails only — USDA FoodData Central (CC0), openFDA > (CC0), NHTSA vPIC (public domain), the Open Facts family (ODbL, as a > segregated source layer) — and every attribute travels inside a provenance > envelope: source, license class, fetched-at, digest. There is no bare value > anywhere in the API. ## The closed verb set resolve · verify · enrich · bridge · hierarchy · party · generate · pins · mcp — --json on every verb; typed errors on stderr; exit 0 ok / 1 negative domain verdict / 2 usage. resolve(generate(x)) === x is the round-trip law. The MCP door exposes the same verbs; resolve/verify carry readOnlyHint: true. ## The registry posture One pinned registry file per scheme: grammar, check digit, canonicalization, symbology bindings, enrichment sources with license class, and the join rule into events and transactions. GS1 is the largest family in the registry, not the boundary. For GS1 keys the /01/* delegating door serves the GS1-Conformant Resolver 1.2.0 surface (RFC 9264 linksets) — resolution itself is id.org.ai's, served through this door; for every other scheme it is the same contract extended, and labeled as such — conformant to the standard; explicit about everything beyond it. ## The joins - events: a serialized 2D scan constructs a valid EPCIS 2.0 ObjectEvent, validated against epcis.dev's pinned schema. who (the attested observer) is distinct from capturedBy (the warrantor account) and the two never collapse. - transactions: the event's bizTransactionList carries PO/ASN/invoice context via transactions.dev. - the Who: id.org.ai — Agent. Human. Thing. ## The family One event record underneath; developer doors beside this one, the commerce layer above. Every page's masthead carries "· by visibility.cloud". - [epcis.dev](https://epcis.dev): the event engine — the capture gateway whose pinned schema this layer's constructed events validate against - [transactions.dev](https://transactions.dev): the business-transaction layer — the PO/ASN/invoice context an event's bizTransactionList carries - [visibility.cloud](https://visibility.cloud): the commerce layer above — the executive side of the same spine - id.org.ai: the identity layer — Agent. Human. Thing. Resolution itself is id.org.ai's, served through this property's delegating doors; this surface only names it. - [auto.dev](https://auto.dev): the vehicle data plane — the family's owned enrichment rail for VIN - [The Org.AI Foundation](https://foundation.org.ai): steward The family thesis, in each register: https://barcoding.dev/blog/the-meaning-behind-the-stripes/ (this property) · https://visibility.cloud/journal/from-stripes-to-grids/ · https://epcis.dev/journal/observability-and-traceability-are-one/ · https://transactions.dev/blog/the-paperwork-is-a-projection/ ## Pages - https://barcoding.dev/ — the landing: verbs, provenance envelope, scheme registry, laws - https://barcoding.dev/blog/ — the explainer arc and worked examples - https://barcoding.dev/schemes/ — the scheme registry: one reference page per scheme, each serving three faces at one address (HTML page, /schemes/.json, /schemes/.md — extension forces, Accept infers, bare curl gets JSON) - https://barcoding.dev/scan/ — the in-browser scan demo: camera and photo decode on the visitor's device, decode-and-discard; specimens rendered by the site's own encoder and decode-verified at build time - https://barcoding.dev/get-access/ — the access list (email first, then a short survey; the record locks at the end) ## Scheme registry rows (page · JSON · markdown) - https://barcoding.dev/schemes/gtin/ · https://barcoding.dev/schemes/gtin.json · https://barcoding.dev/schemes/gtin.md - https://barcoding.dev/schemes/ai/ · https://barcoding.dev/schemes/ai.json · https://barcoding.dev/schemes/ai.md - https://barcoding.dev/schemes/dl/ · https://barcoding.dev/schemes/dl.json · https://barcoding.dev/schemes/dl.md - https://barcoding.dev/schemes/gln/ · https://barcoding.dev/schemes/gln.json · https://barcoding.dev/schemes/gln.md - https://barcoding.dev/schemes/sscc/ · https://barcoding.dev/schemes/sscc.json · https://barcoding.dev/schemes/sscc.md - https://barcoding.dev/schemes/vin/ · https://barcoding.dev/schemes/vin.json · https://barcoding.dev/schemes/vin.md - https://barcoding.dev/schemes/isbn/ · https://barcoding.dev/schemes/isbn.json · https://barcoding.dev/schemes/isbn.md - https://barcoding.dev/schemes/udi/ · https://barcoding.dev/schemes/udi.json · https://barcoding.dev/schemes/udi.md - https://barcoding.dev/schemes/ndc/ · https://barcoding.dev/schemes/ndc.json · https://barcoding.dev/schemes/ndc.md - https://barcoding.dev/schemes/tracking/ · https://barcoding.dev/schemes/tracking.json · https://barcoding.dev/schemes/tracking.md - https://barcoding.dev/schemes/dl-aamva/ · https://barcoding.dev/schemes/dl-aamva.json · https://barcoding.dev/schemes/dl-aamva.md ## Posts - https://barcoding.dev/blog/a-door-not-a-second-path/ — A door, not a second path: the MCP surface (2026-07-31). Every MCP tool re-dispatches through the same core the CLI calls — same verbs, same pinned tables, same typed errors, byte-identical payloads — because a second implementation is a second set of bugs wearing a trust costume. Tool list equals verb list, mechanically enforced. - https://barcoding.dev/blog/a-vehicle-crosses-the-country/ — A vehicle crosses the country: the full-family trace (2026-07-31). One VIN exercises the entire stack — scan the door jamb for identity, book transport with custody events whose who is the attested driver and whose capturedBy is the carrier account, and watch escrow release on the delivery-confirmed event. Vehicle logistics is the family's most complete worked showcase, and the pattern generalizes to any high-value serialized unit. - https://barcoding.dev/blog/agentic-commerce-forgot-the-reference-layer/ — Agentic commerce built the rails and forgot the reference layer (2026-07-31). The 2025–26 agent-commerce wave — ACP, UCP, AP2, A2A, the settlement rails — is building transaction pipes and merchant feeds while the neutral "what is this GTIN?" reference layer stays empty. MCP wrappers over unlicensed aggregators are the entire field, and a reference layer is exactly the thing agents cannot bootstrap for themselves. - https://barcoding.dev/blog/anyone-may-run-a-conformant-resolver/ — Anyone may run a GS1-conformant resolver — the standard says so (2026-07-31). The GS1-Conformant Resolver standard 1.2.0, ratified January 2026, is royalty-free under the GS1 IP Policy and ownership-agnostic — nothing restricts resolver operation to GTIN owners. The real constraint is not permission. It is what lawfully populates the links. - https://barcoding.dev/blog/application-identifiers-grammar/ — GS1 Application Identifiers: the grammar inside the symbol (2026-07-31). AIs are the typed field system of the physical world — (01) GTIN, (10) lot, (17) expiry, (21) serial, (00) SSCC — and an FNC1-delimited element string is a binary wire format with parsing rules, not "text in a barcode." Parsed here byte by byte, from the AIM prefix to the last variable-length field. - https://barcoding.dev/blog/bridge-sku-to-gtin/ — bridge: from SKU to GTIN candidates, with the evidence attached (2026-07-31). For the systems that carry no GTIN at all — small-business accounting, restaurant POS, parcel labels — candidate GTIN resolution with confidence and evidence, never a silent best guess, is the entire product. The bridge contract, the evidence object, and why exit code 1 is a feature. - https://barcoding.dev/blog/camera-to-event/ — Camera to event: the browser scan demo, explained (2026-07-31). A phone browser goes from camera frame to validated EPCIS event in four visible steps — decode, resolve, enrich, emit — and the demo publishes its own network trace, because a pipeline you can inspect is the honesty posture applied to scanning. What BarcodeDetector actually covers, where WASM fills in, and what each step's contract is. - https://barcoding.dev/blog/capture-is-not-the-answer/ — Your scan SDK captures everything and answers nothing (2026-07-31). Capture vendors monetize the decode — SDK seats, shelf cameras — while the question the scan exists to ask still requires someone else's data. Capture and answer are different products, and conflating them is how deployments ship without a data layer. A scope-of-work diff for the bid that closes the gap. - https://barcoding.dev/blog/digital-link-from-the-uri-down/ — GS1 Digital Link, explained from the URI down (2026-07-31). A Digital Link URI is the same AI map as an element string, spelled as an HTTP path — /01/{gtin}/10/{lot}/21/{serial} — which is what makes a barcode web-resolvable without making the web its master. The grammar, the round trip, and what resolution adds. - https://barcoding.dev/blog/dont-build-the-identifier-layer/ — Don't build the identifier layer: the maintenance-tax ledger (2026-07-31). The true cost of an in-house barcode layer is not the parser but the forever-tax — AI-table revisions, prefix-range drift, Digital Link grammar updates, per-source license watch. A pinned, versioned dependency with published sha256 provenance is the artifact that wins the architecture review. - https://barcoding.dev/blog/drivers-licenses-parse-verify-never-store/ — Driver's licenses: parse, verify, never store (2026-07-31). AAMVA PDF417 payloads are the one scheme where the law, not the license file, sets the rule — state statutes criminalize retention beyond age and authenticity checks. The registry row carries a hard no_retention flag, and the enrich verb refuses by design. This post is the refusal, documented for your security review. - https://barcoding.dev/blog/element-string-or-digital-link-uri/ — Element string or Digital Link URI: the encoding decision Sunrise leaves to you (2026-07-31). A 2D symbol can carry the same GTIN+lot+expiry as an FNC1 element string or as a GS1 Digital Link URI. One resolves in a consumer's phone, one does not — and the choice belongs to the GTIN owner, not to the Sunrise 2027 programme. The decision matrix, worked with generate. - https://barcoding.dev/blog/every-scan-is-an-event-without-a-who/ — Every 2D scan is a potential EPCIS event — and the standard has nowhere to put who scanned (2026-07-31). The moment a serialized 2D payload is written down as an event, EPCIS 2.0 §7.2.2's five dimensions record everything except the performer. That absence is structural — there is no field to leave blank — and the section numbers proving it are all public. - https://barcoding.dev/blog/from-scan-to-conformant-event/ — From scan to conformant event: constructing the ObjectEvent (2026-07-31). A parsed 2D payload deterministically populates an EPCIS 2.0 ObjectEvent — epcList or quantityList from the AIs, time, step, and disposition from scanning context — and the event is not done until it validates against the pinned official schema and its CBV §8.9 hash matches the reference vectors. The field-by-field mapping, published. - https://barcoding.dev/blog/gln-the-three-layer-join/ — GLN: the identifier that joins all three layers (2026-07-31). The Global Location Number names the party or place in EPCIS source and destination lists, in an X12 856's N1 loop under qualifier UL, and as Peppol endpoint scheme 0088 — one identifier, three wire formats, and the only cross-layer join the record gets for free. Also — verified across the commercial API landscape — almost nobody carries it. - https://barcoding.dev/blog/gtin-four-lengths-one-identity/ — GTIN: the four lengths, one identity (2026-07-31). GTIN-8, -12, -13 and -14 are one identifier at four encodings. Canonical form is the zero-padded GTIN-14, the check digit is one public mod-10 algorithm anchored at the right, and most of what your bug tracker files as invalid barcode is actually a canonicalization bug. - https://barcoding.dev/blog/hierarchy-each-inner-case-pallet/ — hierarchy: each, inner, case, pallet — and inference that says it is inferring (2026-07-31). Packaging-level relationships come licensed or inferred — the GTIN-14 indicator digit and ITF-14 evidence support inference, GDSN standing supports the licensed graph — and an API that does not label which is which is manufacturing certainty it does not have. One GTIN family resolved to a packaging graph with per-edge provenance. - https://barcoding.dev/blog/identity-questions-come-first/ — Identity questions come first: why an agent's first family touch is a barcode (2026-07-31). Before an agent can capture an event or reconcile a transaction it must answer — what is this, is it real, whose is it. The identifier layer is the family's natural first-touch surface for self-principal agents, its free zone is sized accordingly, and the price of everything gated is stated before the first call. - https://barcoding.dev/blog/isbn-is-a-gtin/ — An ISBN is a GTIN: what Bookland means for a universal resolver (2026-07-31). ISBN-13 is a valid GTIN-13 under the 978/979 prefixes, which means a universal resolver needs no "books mode" — it needs prefix routing. The ISBN row is the cleanest demonstration that scheme detection is a table, not a heuristic, and its enrichment column is the cleanest demonstration of what honest license posture looks like. - https://barcoding.dev/blog/linksets-doors-with-provenance/ — Linksets: the resolver answer is a list of doors, and every door carries its provenance (2026-07-31). RFC 9264 linksets turn "where does this barcode go" into typed navigation. A linkset whose every link carries source, license class, and freshness is a combination no resolver in the field ships — and it is the difference between a list of URLs and an answer an agent can act on. - https://barcoding.dev/blog/ndc-no-check-digit/ — NDC: the identifier with no check digit, and what validation means without one (2026-07-31). The National Drug Code is ten digits in three segments and carries no check digit at all — so "valid" can only ever mean structurally parseable plus present in the registry. The NDC is the scheme that forces a resolver to be honest about validation tiers, and the honesty generalizes. - https://barcoding.dev/blog/no-bare-values/ — No bare values: the per-attribute provenance envelope (2026-07-31). Every attribute an enrich response carries travels inside an envelope — value, source record, dataset version, sha256, license class, fetched-at, confidence — because a product record is a mosaic of licenses, and a license that does not travel with its value is a lawsuit deferred. The schema, the closed enum, and the enforcement rule. - https://barcoding.dev/blog/one-resolver-every-scheme/ — One resolver, every scheme: the universal generalization (2026-07-31). Scheme detection is registry data — grammar, check digit, canonicalization, pinned per scheme — so a single well-known-described door serves a GTIN, a VIN, an ISBN, a UDI, an NDC, and a tracking number with one linkset contract: conformant where a standard exists, explicit where none does. - https://barcoding.dev/blog/one-scan-three-layers/ — One scan, three layers: identity, event, transaction (2026-07-31). A single QR on a case answers three different questions at three layers — which thing (barcoding.dev), what happened and who performed it (epcis.dev + id.org.ai), against which PO and ASN (transactions.dev). The joins are spec-sanctioned core fields, not glue, and the field that offers all three layers together is — as of our last search — empty. - https://barcoding.dev/blog/pharma-already-lives-in-2027/ — Pharma already lives in 2027: DSCSA as the serialization precedent (2026-07-31). Every US prescription-drug package already carries a GS1 DataMatrix with GTIN, serial, lot, and expiry under DSCSA — the one US vertical where serialized 2D is universal at the unit level. Parsed live, with the NDC-inside-GTIN embedding shown, and the lessons a cross-vertical CTO can actually reuse. - https://barcoding.dev/blog/qr-or-datamatrix-who-scans/ — QR or GS1 DataMatrix? One question decides it: who scans (2026-07-31). GS1 DataMatrix clears the POS lane; QR is what a consumer's phone camera reliably decodes. Symbology choice is an audience choice, it belongs to the GTIN owner, and the same GTIN and AIs render as either symbol — two marks, one identity, proven by round-trip. - https://barcoding.dev/blog/resolve-through-not-over/ — Resolved through brand doors, never over them (2026-07-31). Where a brand publishes its own Digital Link redirect, a neutral resolver's duty is to carry that link in the linkset and resolve through it — because allocation is homed with the issuer, and a resolver that replaces the brand's door is just another walled network with better manners. - https://barcoding.dev/blog/resolve-without-asking-permission/ — Why an agent can call resolve without asking permission (2026-07-31). Pure, local, readOnlyHint-true verbs with complete tool descriptions clear agent auto-approval frameworks and fire inside already-granted authority — so identity questions get answered with no human in the loop, by design rather than by workaround. The gate lands on durable state and licensed data, never on compute. - https://barcoding.dev/blog/scan-the-door-jamb/ — Scan the door jamb: VIN to vehicle, listing, and every other door (2026-07-31). A door-jamb Code 39 scan resolves through the whole pipeline — validate, decode, linkset — with a typed failure at every step that can fail. The worked transcript, from framing strip and 49 CFR 565.15 arithmetic to the RFC 9264 linkset of live doors — history, recalls, sticker, valuation, transport. - https://barcoding.dev/blog/see-your-2d-mark-today/ — See your 2D mark today: generating a Digital Link QR from a GTIN (2026-07-31). A brand deciding its Sunrise mark can render its own GTIN as a GS1 Digital Link QR in one command — before any agreement, account, or vendor exists — because constructing the URI and rendering the symbol are royalty-free under GS1's own IP policy. One command, three outputs, and an honest list of what it does not settle. - https://barcoding.dev/blog/serial-or-lot/ — Serial vs lot: what SGTIN and LGTIN actually mean (2026-07-31). "Serialized" is a grain decision. GTIN+serial names this unit; GTIN+lot names this batch; and the choice decides forever which questions your event history can answer, at materially different marking cost. The same physical case, eventized both ways, with the recall-scope difference run as a query. - https://barcoding.dev/blog/sscc-the-unit-of-custody/ — SSCC: the logistic unit is the unit of custody (2026-07-31). The SSCC is the only identifier that names this pallet — not the product class, not the shipment abstraction, the physical unit that crosses your dock. That is why it parents every EPCIS AggregationEvent, why the ASN hangs on it, and why the parcel networks throwing it away severs product identity at the label. - https://barcoding.dev/blog/sunrise-2027-stated-exactly/ — Sunrise 2027, stated exactly: what GS1's program requires, and the six things it doesn't (2026-07-31). GS1's own program expects retail POS to scan and process 2D barcodes by end of December 2027, baseline GTIN extraction. Almost everything else said about it in vendor copy fails a GS1-literate reader's check. The six standing corrections, each paired with its primary source. - https://barcoding.dev/blog/symbology-is-not-the-identifier/ — A symbology is a pipe, not a payload: 1D, 2D, and what each square can carry (2026-07-31). UPC-A carries twelve digits and nothing else; a 2D symbol carries a full AI payload. The symbology registry and the identifier registry are orthogonal, and confusing the pipe with the payload is the root error in every barcode program. Worked here with one GTIN through three carriers. - https://barcoding.dev/blog/the-2026-scanning-stack/ — The 2026 scanning stack: who decodes what, from lane firmware to a browser tab (2026-07-31). Dedicated scanners, phone cameras, browser APIs, and fixed cameras all emit the same payload bytes now — decoding is commoditized. The differentiated question moved one layer up: what happens the millisecond after the decode. The capability matrix, and where the answer layer went missing. - https://barcoding.dev/blog/the-asn-knows-everything-except-who/ — The ASN knows everything about the shipment except who shipped it (2026-07-31). An EDI 856's HL tree maps cleanly onto EPCIS 2.0 — SSCC MAN values to AggregationEvent parents, LIN GTINs to EPC lists, BSN02 to the desadv reference, N1 GLNs to source and destination — and after the whole join lands, there is still no field on either side of the wire that names the person or agent who performed the handling. - https://barcoding.dev/blog/the-case-and-the-pallet/ — The case and the pallet: GS1-128, ITF-14, and generating SSCC labels (2026-07-31). Logistics marking is its own discipline — ITF-14 for the corrugate-printable case GTIN, GS1-128 for AI-bearing labels, SSCC allocation for the logistic unit — and the label is the first artifact where a generation error becomes physical. A complete pallet label generated, decomposed, and round-tripped before the print run. - https://barcoding.dev/blog/the-check-digit-is-public/ — The check digit is public. The answer layer never was. (2026-07-31). Every validation algorithm a barcode system needs is public regulation or a royalty-free standard — worked here, digit by digit, for a VIN and an EAN-13. The layer above it is what has always been walled. That split is the architecture of barcoding.dev. - https://barcoding.dev/blog/the-gs1-licensing-wall/ — Why there is no honest GTIN cache: the GS1 licensing wall, clause by clause (2026-07-31). Every GS1 data rail short of a negotiated agreement licenses display-and-verify only — the anti-caching clause, the internal-use-only clause, the competing-product clause, and the per-brand-owner consent regime, quoted verbatim with links to the agreements. What that means for anyone selling you a cached GTIN database, and what stays genuinely open. - https://barcoding.dev/blog/the-gtin-gap-measured/ — The API economy is SKU-native: the GTIN gap, measured (2026-07-31). Across 37 verified commercial connector surfaces, GS1 identity lives only at the edges — the ERP top end, the regulated verticals, the standards rails — and is optional, unvalidated free text in the middle. Zero commercial APIs carry SSCC; two carry GLN. Product identity must be bridged into the transaction layer, never assumed. - https://barcoding.dev/blog/the-meaning-behind-the-stripes/ — The Meaning Behind the Stripes (2026-07-31). The manifesto. A barcode was never the stripes — it was always an address into meaning, just a short one. Sunrise 2027 makes the address long enough to hold a biography, and the record it feeds still has no line for who was there. - https://barcoding.dev/blog/the-round-trip-law/ — resolve(generate(x)) === x: generation and resolution are one function, tested (2026-07-31). The write side and the read side of an identifier layer must be exact inverses — every generated element string, Digital Link URI, and rendered symbol must resolve back to the identical canonical identity — and that law is a CI gate over a published golden corpus, not a design preference. The harness, the corpus split, and how to check the claim yourself. - https://barcoding.dev/blog/the-upc-is-a-checkout-token/ — The 1D UPC is a checkout token — the brand learns nothing from its own barcode (2026-07-31). A UPC is scanned millions of times by other people's point-of-sale systems, and the mark's owner is the only party it carries no signal for. The information budget of 12 digits versus a decoded 2D payload, computed — and the honest sentence about what nobody can promise you yet. - https://barcoding.dev/blog/the-upstream-question/ — The aggregators never answer the upstream question (2026-07-31). The big barcode-lookup APIs share one silence — no per-attribute provenance, no license metadata, redistribution-hostile terms. An enrichment layer that cannot say where an attribute came from cannot say whether you may use it, and that is the question an RFP should ask first. - https://barcoding.dev/blog/tracking-numbers-scheme-family/ — Tracking numbers are a scheme family too: 1Z, IMpb, and the SSCC nobody keeps (2026-07-31). Carrier tracking formats are proprietary grammars doing a logistic-unit identifier's job — and the parcel APIs that mint them are SKU-poor and GS1-blind. Product identity dies at the label, and the registry treats carrier formats as first-class scheme rows so the death is at least visible. - https://barcoding.dev/blog/two-grains-of-who/ — The two grains of Who: attested observer vs warrantor account (2026-07-31). who is the observer that performed the scan — human, agent, or embodied agent. capturedBy is the account that stands behind the record. An agent may observe under an account it does not own, and collapsing the two destroys exactly the evidence a custody record exists to carry. Worked twice at a receiving dock. - https://barcoding.dev/blog/udi-the-fda-multi-scheme-resolver/ — UDI: the FDA already runs a multi-scheme resolver, and it proves the architecture (2026-07-31). AccessGUDID accepts identifiers from three accredited issuing agencies — GS1, HIBCC, ICCBBA — detects the grammar, splits device identifier from production identifiers, and serves the answer from public-domain data. A working, government-scale precedent for a one-endpoint, every-scheme resolver. - https://barcoding.dev/blog/upc-to-nutrition-license-clean/ — UPC to nutrition facts, license-clean: the flagship chain (2026-07-31). The same label data the syndication networks gate arrives in the public domain through USDA FoodData Central — CC0, GTIN-keyed. The flagship enrichment chain runs entirely on rails like that, and every attribute in the answer carries its own source, license class and fetch time, so an agent can filter by what it is allowed to do. - https://barcoding.dev/blog/vin-the-fully-published-identifier/ — VIN: the 17 characters the US government fully published (2026-07-31). VIN structure and check digit are federal regulation — 49 CFR 565 — and NHTSA vPIC decodes about 140 attributes in the public domain. The best-documented identifier in the registry, worked in full: transliteration, weights, mod-11, and the typed failure surface a caller can branch on. - https://barcoding.dev/blog/what-did-i-just-scan/ — What did I just scan? Payload identification from the first three bytes (2026-07-31). A scanner hands you bytes, not meaning. The AIM symbology identifier, the FNC1 position, Code-39 framing, and URI shape classify any payload deterministically — worked here on ten raw payloads, the way resolve does it, from a pinned decision table rather than folklore. - https://barcoding.dev/blog/when-the-observer-is-a-robot/ — When the observer is a robot: the who that isn't human (2026-07-31). Autonomous MHE and scan tunnels are already the performing observer at custody events, and a record whose only party field is organisation-grain cannot even say that, let alone which unit. The embodied agent is the cleanest proof that the Who dimension is structurally missing, not merely under-filled. - https://barcoding.dev/blog/zebra-proved-the-demand/ — Zebra proved the demand, then turned the lights off (2026-07-31). Zebra's Barcode Intelligence — "instant barcode data enrichment using a single API," in Zebra's own words — validated this exact category, then was discontinued entire on December 4, 2023, leaving the largest deployed scanner base in the industry with no first-party answer to "what did I just scan?" The public record, quoted, and the design lesson it carries. ## The list, disclosed The access form stores exactly what a visitor types — address, answers, timestamps — and nothing derived from the request. Access is provisioned from this list, in order. One email when yours is ready — one, not a drip campaign; no newsletter, no sequence. If we stop working on this, you get one message saying so and your address is deleted. Either way it is one message. Ledger date: 2026-08-01