What is GS1-based product authentication?
Most QR codes on packaging identify a product line: every unit of the same SKU carries the identical image. GS1-based product authentication adds one more layer — a unique serial number per physical unit, encoded as Application Identifier (21) alongside the GTIN (01). The result is a code that identifies not just what the product is, but which specific unit it is.
That distinction is what makes verification meaningful. A scanner checking a GTIN-only code can confirm the product type is real. A scanner checking a GTIN-plus-serial code can confirm this exact item was allocated a valid identity by the brand — and can compare it against every other scan of that same serial to see whether something looks wrong.
How serialized QR codes work (AI 21)
As a GS1 Digital Link, a serialized code looks like an ordinary URL with the GTIN and serial embedded as path segments:
https://id.yourbrand.com/01/09521234543213/21/SN-88213Opened on a phone, it resolves to a verification page. Read by a GS1-aware scanner, the GTIN and serial are extracted as structured data. Behind the scenes, every resolution of that URI is logged — which serial, when, and roughly where — building a scan history unique to that one unit rather than to the product line as a whole.
Warranty registration in one scan
Because the code already identifies the exact unit, the first scan can serve double duty: confirm authenticity and register the warranty in the same interaction. The customer scans, sees the product is genuine, and is offered a short form that ties their contact details and purchase date to that serial number — no separate warranty card, no typing a serial by hand.
Detecting duplicates and grey-market diversion
Two patterns matter most in the scan log. The first is duplication: the same serial scanned an implausible number of times, or from locations that could not represent one item moving naturally through a supply chain. The second is diversion: a serial's first verified scan happening outside the region it was distributed to, which suggests the unit was sold through an unauthorized channel. Neither proves fraud on its own, but both are the kind of concrete signal that a generic, non-serialized code simply cannot produce.
Before relying on the signal, confirm the basics are in place:
- Serials are allocated once. The platform should refuse to issue the same GTIN-plus-serial combination twice.
- Print artwork is verified. Scan a sample of the final print run to confirm the encoded serial matches what was intended before a full batch ships.
- Flags route to a real review process. An anomaly alert is only useful if someone looks at it — decide who reviews flagged serials before you launch.
- Distribution regions are documented. Diversion detection depends on knowing where a serial was meant to end up.
Do you need a GS1 membership?
For a fully GS1-compliant identifier accepted at retail, you need a GTIN allocated through a GS1 member organization — QRBold does not issue GTINs. What QRBold adds on top is the serial allocation, the verification page, the warranty capture, and the anomaly detection that turns a compliant GTIN into a working authentication system.
If retail compliance is not a requirement, a QRBold-issued unique identifier can carry the same per-unit serialization, duplicate-scan alerts, and warranty workflow without a GS1 allocation at all.