# GET /passport/01/{gtin}/10/{lot}

Read the digital passport published for a production batch, from the GTIN of its model and the lot number. No API key for the public tier.

Source: https://docs.sealtrust.io/en/reference/get-passport-gtin-lot/

---

You read the digital passport published for a production batch. The batch is
designated by the GTIN of its model and by its lot number, as in its GS1
Digital Link. When you leave this page, you will know how to fetch the content
of the batch's passport, how to recognise that it is a batch, and why this
address never falls back on the model.

Full address:

```http
GET https://api.sealtrust.io/v1/passport/01/{gtin}/10/{lot}
```

The same endpoint also answers without the `/v1` prefix. Use the `/v1` form for
a new integration.

> [!INFO] This endpoint describes a batch
> A batch passport is shared by every item of one production batch. It is
> attached to the model through the batch: it starts from the model's data, and
> it carries what is specific to the batch, for example its substances, its
> manufacturing sites or its operators. Its lot number and the model's GTIN are
> written in its own data, under `product_identity`, hence in its hash and in
> the proof that dates it.
>
> This address serves **only** the batch's passport. If the batch has none
> published, it answers 404, without serving the model's in its place: a
> model's data must not be displayed under a batch's name. It is the printed
> link, [`GET /01/{gtin}/10/{lot}`](/en/reference/get-gs1-gtin-lot/), that falls
> back on the model.

## Authorization

None for the public tier, which is the default tier. The access tiers and the
accounts that obtain them are exactly those of
[`GET /passport/01/{gtin}`](/en/reference/get-passport-gtin/): the same check
applies to both addresses, through the same code.

## Rate limit

600 calls per window of 60 seconds, counted per calling IP address. This counter
is shared by every read (`GET`) whose address starts with `/passport`.

## Path and query parameters

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `gtin` | `string` | yes | The GTIN of the batch's model, brought to fourteen digits before the search. Its check digit is verified. |
| `lot` | `string` | yes | The lot number, compared exactly, case included. Encode the characters that need it. |
| `access_tier` | `string` | no | The access tier: `public` by default. Same values as for a model's passport. |

## Request body

None. This request has no body.

## Example request

Reading the passport of batch `LOT-26A` of GTIN `03701234567891`, at the public
tier.

:::onglets
```bash title="curl"
curl -i "https://api.sealtrust.io/v1/passport/01/03701234567891/10/LOT-26A"
```
```typescript
const gtin = "03701234567891";
const lot = "LOT-26A";

const response = await fetch(
  `https://api.sealtrust.io/v1/passport/01/${gtin}/10/${encodeURIComponent(lot)}`,
);

if (response.status === 404) {
  console.log("No passport published for this batch.");
} else {
  const passport = await response.json();
  console.log(passport.level, passport.batch_code, passport.passport_version);
}
```
```python
from urllib.parse import quote

import requests

gtin = "03701234567891"
lot = "LOT-26A"

response = requests.get(
    f"https://api.sealtrust.io/v1/passport/01/{gtin}/10/{quote(lot, safe='')}",
    timeout=30,
)

if response.status_code == 404:
    print("No passport published for this batch.")
else:
    passport = response.json()
    print(passport["level"], passport["batch_code"], passport["passport_version"])
```
:::

> [!INFO] The TypeScript SDK does not cover this endpoint
> `@sealtrust-io/sdk` exposes no method for this address. The examples use
> `fetch`, without any dependency.

## Example response

HTTP code `200`.

```json
{
  "id": 412,
  "product_id": null,
  "product_model_id": 7,
  "gtin": "03701234567891",
  "level": "batch",
  "brand_id": 3,
  "brand_code": "K7Q2M9XH4B",
  "schema_version": "1.0",
  "passport_version": 2,
  "data": {
    "product_identity": {
      "gtin": "03701234567891",
      "batch_or_serial_identifier": "LOT-26A",
      "production_facility": "Atelier de Porto",
      "made_in": "PT"
    }
  },
  "data_hash": "9f2c1e7d4b8a6f0e3d5c2b1a9e8f7d6c5b4a3f2e1d0c9b8a7f6e5d4c3b2a1f0e",
  "ipfs_uri": null,
  "visibility": "public",
  "published_at": "2026-09-26T08:00:00+00:00",
  "product_name": "T-shirt coton",
  "brand_name": "Atelier",
  "image_url": "https://atelier.test/images/cotton-t-shirt.jpg",
  "product_batch_id": 11,
  "batch_code": "LOT-26A"
}
```

Every value in this example is fictitious.

| Field | Type | Description |
| --- | --- | --- |
| `level` | `string` | Always `batch` here. A model's passport carries `model`. |
| `product_id` | `integer` | Always `null`: a batch passport is attached to no item. |
| `product_model_id` | `integer` | The model of the batch, reached through the batch. |
| `product_batch_id` | `integer` | The batch this passport is attached to. |
| `batch_code` | `string` | The lot number, as it appears in the GS1 link. |
| `gtin` | `string` | The model's GTIN, in its fourteen digit form. |
| `image_url` | `string \| null` | The photograph of the lot's model, computed as on the model's passport. `null` when the model has none, or when it belongs to a brand other than this passport's. It is the light copy of the photo (WebP, 800 pixels at most on the long side, 100 KB at most, no EXIF data) when it exists, else the original. An address of another site is returned as given. |
| `data` | `object` | The content of the passport, filtered by access tier. |
| `ipfs_uri` | `string` | The address of the IPFS copy, returned only at the authenticated tiers, as for the model. |
| `access_tier` | `string` | The tier actually served: the one asked for, or `public` by default. |
| `available_tiers` | `array` of `string` | The tiers YOUR call may ask for on this passport, in the order `public`, `end_user`, `repairer`, `recycler`, `upstream`, `authority`: `["public"]` without authentication, `end_user` added for a signed-in account, the trade the brand accredited for a partner, all of them for an authority. The list grants nothing: every tier asked is still checked. A response carrying it for a signed-in account must go to no shared cache. |
| `passport_service_provider` | `object` or `null` | The passport service provider keeping the back-up copy of this version (Regulation (EU) 2024/1781, article 10(4) and Annex III point (l)): `identifier`, its reference, `name`, its legal name, and `backed_up_at`, the date of the copy in ISO 8601 format. `null` until the copy of this version exists, or when its last check failed. Outside `data`, so outside the `data_hash` fingerprint. |

The other fields have the same meaning as in the response of
[`GET /passport/01/{gtin}`](/en/reference/get-passport-gtin/).

## Errors

| Code | Condition | What to do |
| --- | --- | --- |
| 400 | The GTIN check digit does not match. | Copy the GTIN again from the barcode. |
| 401 | A tier that requires an account, requested without a session. | Sign in, or request the `public` tier. |
| 403 | A tier your account does not open for this brand. | Request a tier your account is entitled to. |
| 404 | No published and public passport for this batch, a batch of another brand than the one of the called domain, or a batch of another brand than the one that publishes the model passport of this GTIN. | Check the lot number, case included, and the publication in the console. |
| 429 | More than 600 calls in 60 seconds from the same IP address. | Wait the number of seconds given by `Retry-After`. |

## See also

- [`GET /passport/01/{gtin}/10/{lot}/proof`](/en/reference/get-passport-gtin-lot-proof/),
  the public proofs of a batch's passport.
- [`GET /01/{gtin}/10/{lot}`](/en/reference/get-gs1-gtin-lot/),
  the GS1 link of the batch.
- [`GET /passport/01/{gtin}`](/en/reference/get-passport-gtin/),
  the passport of the model.
