Developer API
The same engines as the tools on this site, as a REST API: GTIN and GS1 validation, barcode generation, ZPL rendering and validation, barcode-to-ZPL and batch checks.
Base URL: https://barcode.tob-apps.com/api/v1
API key
Create a key on your account page (free account with a confirmed email address). The key is shown once; we store only a hash. Send it with every request:
Authorization: Bearer bpk_…
Content-Type: application/json
Limits
| Plan | Requests per day (UTC) | Requests per minute |
|---|---|---|
| Free | 1,000 | 60 |
Every response carries X-RateLimit-Limit and X-RateLimit-Remaining. Over a limit you get 429 with Retry-After in seconds. Request bodies may be up to 1 MB.
Privacy: request and response contents are not stored or logged. We count requests per key and day, nothing else.
OpenAPI: /api/v1/openapi.json (OpenAPI 3.1) for Postman, Insomnia or code generators.
Endpoints
All endpoints take POST with a JSON body.
| Endpoint | Body | Returns |
|---|---|---|
/gtin/validate | { "gtin": "4006381333931" } | valid, type, error, expectedCheckDigit, gtin14 |
/gs1/parse | { "data": "(01)09521234543213(10)ABC123" } (element string, raw scanner data or GS1 Digital Link URI) | valid, elements (AI, title, value), dataStr, digitalLink or error |
/barcode/generate | { "symbology": "QR Code", "data": "…", "scale": 2, "includeText": true, "rotate": "N" } | SVG image |
/barcode/decode | { "image": "<base64 PNG or JPEG>" } (max 5 MB) | barcodes (format, text, symbology identifier, position, GS1 data). No confidence value: the decoder reports none. |
/zpl/render | { "zpl": "^XA…^XZ", "dpmm": 8, "widthMm": 101.6, "heightMm": 152.4 } | labels (SVG in printer dots), issues |
/zpl/validate | same as render | valid (no errors), labels (count), issues, commands |
/barcode-to-zpl | { "symbology": "GS1-128", "data": "(01)…", "dpmm": 8, "x": 40, "y": 40, "module": 3, "height": 120, "hri": true, "orientation": "N" } | zpl |
/batch/validate | { "values": ["4006381333931", "(01)…"] } (up to 10,000) | rows, summary |
Symbologies for /barcode/generate and /barcode-to-zpl: see supported symbologies. dpmm is 6, 8, 12 or 24 (152, 203, 300, 600 dpi). GS1 engine messages are English.
Examples
curl -s https://barcode.tob-apps.com/api/v1/gs1/parse \
-H "Authorization: Bearer $API_KEY" -H "Content-Type: application/json" \
-d '{"data":"(01)09521234543213(17)261231(10)ABC123"}'
curl -s https://barcode.tob-apps.com/api/v1/barcode/generate \
-H "Authorization: Bearer $API_KEY" -H "Content-Type: application/json" \
-d '{"symbology":"GS1 DataMatrix","data":"(01)09521234543213(10)ABC123"}' > code.svg
Errors
Errors are JSON: { "error": "code" }, sometimes with detail.
| Status | error | Meaning |
|---|---|---|
| 400 | invalid_<field> | A field is missing or out of range |
| 413 / 415 | image_too_large, invalid_image | Image over the size limit, or not PNG/JPEG |
| 401 | api_key_required, invalid_api_key | No key, unknown or revoked key |
| 415 | json_required | Body is not JSON |
| 422 | cannot_encode | The symbology cannot encode the data; detail says why |
| 429 | rate_limited, daily_quota_exceeded | Limit reached, see Retry-After |
Results report what the engines can tell: valid, invalid, warnings and unsupported commands. ZPL text is rendered with substitute fonts (Zebra fonts are proprietary); positions, lines and barcodes are exact. Validation is not a formal barcode verification or certification.