← All articles

GS1 & SUPPLY CHAIN

Introducing ObjectID – GS1 Integration Hub

Originally published on LinkedIn ↗ on 25 February 2026.


GS1-native traceability, with on-chain notarization and authenticity built in.

Across the GS1 ecosystem, the question keeps coming back in different forms: how do we get tamper-evident, cross-company trust in supply-chain events—without breaking existing standards and without forcing everyone into a new platform? The industry has been exploring “blockchain-based” approaches for years, but most attempts either stayed in pilots, became permissioned databases with extra steps, or required too much process change to scale.

ObjectID – GS1 Integration Hub is a practical answer to that gap.

For anyone who hasn’t come across it yet, ObjectID is a decentralized identity-anchored notarization layer on IOTA: it lets organizations create tamper-evident, verifiable digital objects and event records tied to a domain-linked DID, independently of any specific industry standard.        

ObjectID GS1 Integration Hub is a GS1-native integration layer designed for companies running ERP stacks like SAP (and suppliers/3PLs using standard GS1 tooling). It keeps the operational surface exactly where it should be: GS1 identifiers, GS1 Digital Link, EPCIS events, standard APIs. But it adds what GS1 implementations typically lack when disputes, counterfeits, or grey-market diversion show up: independent proof.

In short, the hub:

  • exposes standard GS1/EPCIS interfaces for resources and events (so existing enterprise flows remain intact),
  • creates an on-chain registry that links a GS1 Resource URL / Digital Link to an ObjectID (IOTA object) and back,
  • notarizes EPCIS events on-chain so their integrity can be verified outside any single company’s infrastructure,
  • can bind issuance and event responsibility to a domain-linked decentralized identity (DID).

For a CTO, this means you can roll out GS1 the “classic” way (IDs → master data → documents → EPCIS), and then upgrade the trust layer without redesigning ERP processes or rewriting partner integrations.

Baseline GS1 Delivery: What’s Implemented First (and What’s Typically Deferred)

In a standard GS1 program, the organization delivers the core interoperability layer first, then postpones the higher-assurance elements that require additional governance, partner alignment, and budget.

Delivered in the initial rollout

  • GS1 identification keys are established as the common reference model: GTIN (items), GLN (parties/locations), SSCC (logistic units).
  • Master data alignment is implemented to a practical level (often via GDSN or GS1-aligned exchanges) to reduce mismatches across trading partners.
  • Document exchange is standardized (EDI and/or API mappings) for the transactional backbone: orders, despatch advice/ASN, invoices.
  • EPCIS traceability is introduced where it generates immediate value, typically starting from shipping/receiving and selective aggregation.

Commonly deferred because it is costly to implement “properly”

  • Evidence-grade integrity (tamper-evident records beyond internal logs and databases) for events and key documents.
  • Network-wide accountability where each partner is cryptographically bound to the events it emits, rather than relying on repository trust and contractual audits.

These deferred elements are precisely the ones that the ObjectID GS1 Integration Hub enables to add later, incrementally, without changing the GS1 operational interfaces already adopted by ERPs and partners.

Completing GS1: Notarization, Authenticity, and Accountability, without rework

With the ObjectID GS1 Integration Hub in place, the GS1 operating model remains unchanged for ERPs and partners, but the program can be completed with the assurance capabilities that are typically deferred in a standard rollout.

Delivered immediately (without disrupting existing GS1 integrations)

  • GS1 interfaces remain native: EPCIS capture/query and GS1 Digital Link patterns continue to be used as-is, so ERP and partner integrations do not need to be redesigned.
  • On-chain GS1 resource registry is introduced: a bidirectional mapping between GS1 Resource URLs / Digital Link and ObjectID objects on IOTA blockchain, enabling consistent resolution from GS1 identifiers to verifiable digital objects.
  • EPCIS event notarization becomes available by default: events can be anchored with tamper-evident proofs while keeping the same operational EPCIS workflows for capture and query.
  • Issuer authenticity is strengthened through a domain-linked decentralized identity (DID), allowing events and objects to be attributed to a verifiable organizational identity.

Capabilities that become practical to add later (the “deferred” items, solved)

  • Evidence-grade integrity at scale: notarization provides an independent proof layer for critical events (and, if desired, selected documents), reducing reliance on internal logs and bilateral audits.
  • Network-wide accountability, phased: the rollout can start in a brand-notarized model and evolve to a federated model where suppliers sign their own events—without changing the GS1 data model or ERP interfaces.
  • Anti-counterfeit on finished goods: the same GS1-compatible identifier surface (Digital Link / QR) can be paired with an ObjectID verification flow, enabling authenticity checks and verified provenance without departing from GS1 conventions.

In practice, the hub changes the economics of a GS1 program: you can go live quickly on interoperability, and then complete the “trust and proof” layer incrementally—without supplier disruption and without turning the project into a multi-year governance exercise.

Article content
Example of GS1 resource data validation performed by ObjdctID dApp against on-chain data.

The Business Case: Why the Integration Hub Pays Back

With GS1 alone, you achieve interoperability. With the ObjectID GS1 Integration Hub, you upgrade that interoperability into verifiable evidence and brand-grade authenticity, without changing the GS1 operating model.

Delivered as a direct improvement to risk, cost, and control

  • Tamper-evident event integrity: EPCIS events can be anchored with independent proofs, making post-facto manipulation detectable and reducing reliance on internal logs and bilateral “trust me” exchanges.
  • Faster dispute resolution: when ASN vs. receipt, custody handoffs, or deviations are contested, proofs reduce time-to-resolution and limit operational downtime.
  • Audit simplification: evidence becomes portable and independently verifiable, reducing the scope and frequency of heavy reconciliation cycles.

Anti-counterfeit on finished goods (without breaking GS1 conventions)

  • GS1 Digital Link as the carrier: you keep a GS1-compatible identifier in a 2D code (QR/DataMatrix) and attach an ObjectID verification flow on top of it.
  • Authenticity checks at the edge: retail, after-sales, and even consumers can validate whether an item is genuinely issued by the brand identity.
  • Provenance as a feature: selected supply-chain milestones can be exposed as verifiable claims, supporting premium lines, controlled distribution, and warranty/returns integrity.

A practical path to partner accountability

  • Start simple (brand-notarized): suppliers do not need new tooling on day one; you notarize what you receive.
  • Upgrade later (federated): strategic suppliers can progressively adopt identity-based signing, creating a stronger chain of responsibility without changing the GS1 data model.

Net effect: the hub turns GS1 data from “operational records” into “evidence”—and adds an authenticity layer that materially reduces counterfeit and channel risk while improving customer-facing value.

Decentralization: the keyword for security and compliance

Regulatory pressure is moving supply chains from “good operational traceability” to evidence-grade traceability. The EU’s Digital Product Passport (DPP), introduced under the Ecodesign for Sustainable Products Regulation (EU) 2024/1781, pushes toward a standardized, product-linked digital record that supports sustainability, circularity, and legal compliance across the value chain. (EUR-Lex) In parallel, regulated sectors already operate under strict traceability and authenticity rules: EU food law treats traceability as a cornerstone of food safety, and the pharmaceutical sector enforces pack-level safety features and verification under the Falsified Medicines framework and its delegated acts. (Food Safety)

Externalizing data silos is not enough

Most compliance programs start by integrating systems and externalizing data into shared platforms (portals, data lakes, EPCIS repositories). This improves interoperability, but it does not solve the core compliance problem: trust.

For compliance-grade evidence, two properties must hold simultaneously:

  1. Author identity must be verifiable (who created a claim/event, under which organizational authority).
  2. The record must be immutable over time, even for the author (because in real disputes the issuer is not a neutral party).

If the same organization that produces the data can silently rewrite it later, the system may be useful operationally, but it remains weak as a compliance and enforcement backbone.

A “root of trust” needs identity + immutability

This is where decentralization becomes a practical requirement rather than a philosophical preference.

  • Identity: Europe is standardizing a cross-border trust framework through the eIDAS 2.0 revision (Regulation (EU) 2024/1183) and the European Digital Identity ecosystem. (EUR-Lex) ObjectID binds supply-chain objects and records to decentralized identities (DIDs) anchored to organizational control (e.g., domain-linked), and is designed to align with eIDAS2-style assurance and attribution models (so the “issuer” is not just an API key—it is a verifiable organizational identity).
  • Immutability: notarization on a decentralized ledger creates a record whose integrity can be verified independently. The point is not “storage on-chain of everything”, but a cryptographic proof that makes later alteration detectable—including alteration attempted by the original author.

In practice, this combination is what turns traceability data into compliance-grade evidence.

Practical adoption: no token procurement for suppliers

A recurring blocker for regulated industries is “crypto-touch” in procurement and operations. The ObjectID Integration Hub can be deployed so that partners do not need to buy or hold tokens: using IOTA Gas Station / sponsored transactions, the application/operator can cover fees while partners continue to interact through standard GS1/EPCIS interfaces. (docs.iota.org)

Why this was impractical before (and why it isn’t now)

Industrial compliance is a scale problem: high volumes, low latency, predictable costs. Historically, blockchain initiatives hit the trilemma—trading decentralization for performance, or performance for cost, or decentralization for control—often ending up with permissioned ledgers that weakened the “independent evidence” promise.

With IOTA Rebased, IOTA positions itself as fully decentralized while targeting very high throughput and sub-second finality with low fees—characteristics that are explicitly meant to make large-scale notarization viable in production. (IOTA Blog)

Bottom line: as DPP and sector regulations push toward stronger traceability and accountability, the differentiator will not be “more data sharing” but verifiable trust. ObjectID provides that trust through decentralization: identity-backed authorship plus tamper-evident permanence, delivered in a way that remains compatible with GS1 operational standards via the Integration Hub.

Practical benefits

Integrating ObjectID into an existing GS1-powered system is straightforward and effective, while providing advantages that centralized SaaS solutions cannot match.

The integration process is very straightforward: create an ObjectID Identity first (here is a video tutorial on that topic: https://www.youtube.com/watch?v=pkk1MxMVd-k), then clone the GitHub repository https://github.com/ObjectID-io/GS1-integratrion-hub, and follow the simple setup instructions to launch your private ObjectID GS1 Integration Hub.

Beyond the technical benefits already described, there is an important economic advantage: every operation on ObjectID is paid using credits, and the result is stored permanently on the IOTA blockchain. This means the GS1 Integration Hub addresses one of the biggest criticisms of Digital Product Passport (DPP) projects: the recurring and ever-increasing cost of maintaining product history over time.

Finally, ObjectID delivers an additional benefit that goes beyond the technical/GS1 layer and directly improves the user experience: verifiable authenticity of product information and history.

Want to see how it looks in practice? Just scan this QR code.

Article content


The resource dataset displayed by the ObjectID dApp, which opens automatically when the QR code is scanned, was created by calling the /twin endpoint of the GS1 Integration Hub running on localhost.

HUB="http://localhost:8080"
curl -sS -X POST "$HUB/twin" \
  -H "Content-Type: application/json" \
  --data-binary @- <<'JSON'
{
  "epcUri": "urn:epc:id:sgtin:0614141.112345.400",
  "immutable": {
    "gtin": "00614141123458",
    "serial_number": "400",
    "brand_owner_gln": "0614141073462"
  },
  "mutablePatch": {
    "note": "created by GS1 integration hub"
  }
}
JSON        

The object representing the resource is also visible on-chain at the following link: https://explorer.iota.org/object/0xf3ef30cc600b9dc4ca56952f404a16a9da867433d1faa0085b322740f2ac3cbb?network=testnet

You can also see the resource has an event, created with:

curl -sS -X POST "$HUB/capture" \
  -H "Content-Type: application/json" \
  --data-binary @- <<'JSON'
{
  "eventList": [
    {
      "type": "ObjectEvent",
      "eventTime": "2026-02-25T09:20:00.000Z",
      "eventTimeZoneOffset": "+00:00",
      "eventID": "ea283aea-3bbc-49a8-9bfa-bc7ec958ac93",
      "action": "ADD",
      "bizStep": "urn:epcglobal:cbv:bizstep:commissioning",
      "disposition": "urn:epcglobal:cbv:disp:active",
      "epcList": ["urn:epc:id:sgtin:0614141.112345.400"],
      "readPoint": { "id": "0801234000008" },
      "bizLocation": { "id": "0801234000008" },
      "ilmd": { "note": "commissioning event example" }
    }
  ]
}
JSON        

The object representing the resource is also visible on-chain at the following link: https://explorer.iota.org/object/0x1b059280bbdfa2a029c11f62b6da4a44ce49a4261ffcff3e4ea12f23184c221a?network=testnet

Please note that both the GS1 resource data and the GS1 event data include an Author DID and a Producer DID.

These are the Decentralized Identifiers (DIDs) of the entities that published the data. More specifically, they are the identities used by the GS1 Integration Hub to request and obtain, from the ObjectID smart contract, the creation of the corresponding objects on the IOTA blockchain.

You will also notice a small document-shaped icon next to each DID. Clicking it opens a dialog box showing the public on-chain data of that identity. Among the available fields, pay attention to the service of type LinkedDomains: this field indicates the internet domain linked to that identity.

Article content

If you then click “View validation details”, you ask the dapp to verify the DID’s validity, specifically, that the website publishes a Verifiable Credential confirming the link between the DID and the domain. This verification is done completelly in a decentralized way, colleting data from the web server and the blockchain.

Article content

This bidirectional verification is tamper-proof and ensures that no one can create resources or events referencing that domain without being authorized.


Conclusion

So, if you’re planning to introduce GS1 standards into your supply chain, or if you already use GS1 and are looking for a solution to notarize resources and events, feel free to reach out to us at info@objectid.io or contact us here on LinkedIn.


← Back to the blogDiscuss on LinkedIn ↗