# Look up a test kit from a GS1 barcode

Operation ID: `diagnostics.lookupTestByGs1`

Parse a GS1 Application Identifier barcode string (?gs1=) and, if the GTIN is recognized, return the matching manufacturer test profile (IFU instructions, analytes, regulatory status) from the catalog. product is null when the GTIN is not recognized. Same PATIENT-pool ownership rule as diagnostics.listDiagnostics applies to {patient_id}, though the lookup itself is not patient-scoped — it queries the shared test-kit catalog.

## Public method

`lookupByGs1`

Signature: `diagnostics.lookupByGs1(patientId, query)`

Return type: `Promise<Gs1LookupResult>`

## Authentication

Classification: **AUTHENTICATED**

Schemes: `bearerAuth`

## Prerequisites

None documented.

## HTTP

`GET /patients/{patient_id}/diagnostics/lookup`

## Path parameters

| Name | Type | Required | Format | Allowed values | Default | Nullable | Description |
|---|---|---:|---|---|---|---:|---|
| `patient_id` | `string` | Yes |  |  |  | No |  |

## Query parameters

| Name | Type | Required | Format | Allowed values | Default | Nullable | Description |
|---|---|---:|---|---|---|---:|---|
| `encounter_id` | `string` | No |  |  |  | No |  |
| `gs1` | `string` | Yes |  |  |  | No | GS1 barcode value (e.g. 01095577222334451721053110ABC123) |

## Body parameters

None.

Request model: None.

## Request example

None declared in canonical OpenAPI.

## Success responses

| Status | Shape | Content type | Description |
|---|---|---|---|
| `200` | [`GS1LookupResponse`](../models/GS1LookupResponse.md) | application/json | GS1 barcode parsed and matched against the test profile catalog |

## Success response examples

### 200

```json
{
  "gs1_parsed": {
    "expiration_date": "2026-01-01",
    "gtin": "string",
    "lot_number": "string",
    "serial_number": "string"
  },
  "product": {},
  "raw_gs1": "string",
  "scan_upload": {
    "expires_in": 0,
    "storage_key": "string",
    "test_id": "00000000-0000-0000-0000-000000000000",
    "upload_url": "string"
  }
}
```

## Common errors

| Status | Shape | Content type | Description |
|---|---|---|---|
| `400` | [`diagnostics.ErrorResponse`](../models/diagnostics.ErrorResponse.md) | application/json | The gs1 query parameter was not supplied |
| `401` | [`diagnostics.ErrorResponse`](../models/diagnostics.ErrorResponse.md) | application/json | Authorization required — missing or invalid Bearer JWT |
| `403` | [`diagnostics.ErrorResponse`](../models/diagnostics.ErrorResponse.md) | application/json | A PATIENT-pool caller attempted to access another patient's data |
| `404` | [`diagnostics.ErrorResponse`](../models/diagnostics.ErrorResponse.md) | application/json | The PATIENT-pool caller's own FHIR Patient record could not be resolved |
| `500` | [`diagnostics.ErrorResponse`](../models/diagnostics.ErrorResponse.md) | application/json | Internal server error |

## Error examples

### 400 — Required query parameter is missing

```json
{
  "error": "Missing required query parameter: gs1"
}
```

### 401 — Missing or invalid access token

```json
{
  "error": "Authorization required"
}
```

### 403 — The caller's own FHIR patient id does not match patient_id

```json
{
  "error": "Cannot access another patient's data"
}
```

### 404 — The caller's own patient record was not found

```json
{
  "error": "Patient not found"
}
```

### 500 — Unexpected service failure (sanitized example)

```json
{
  "error": "Internal server error"
}
```

## NodeJS / TypeScript implementation

```ts
import { HCSDK } from "@healthcloudai/hc-sdk";
```

```ts
const patientId = "<PATIENT_ID>";

const query = {
  "encounter_id": "<ENCOUNTER_ID>",
  "gs1": "<GS1>"
};

const result = await diagnostics.lookupByGs1(patientId, query);
```

## cURL

```bash
curl -X GET \
  -H 'Authorization: Bearer <ACCESS_TOKEN>' \
  'https://dev-api-diagnostics.health.cloud/patients/%3CPATIENT_ID%3E/diagnostics/lookup?encounter_id=%3CENCOUNTER_ID%3E&gs1=%3CGS1%3E'
```

## Notes

- Interim note pending a backend contract update: since the SAFE CDX integration (merged to healthcloud-services main 2026-08-21), for the OraQuick HIV GTIN (00608337001792) the live response also includes a `scan_upload` field — `{test_id, upload_url, expires_in, storage_key}`, a SAFE CDX presigned S3 upload URL generated inline. This field is not yet declared on the `GS1LookupResponse` schema shown on this page; it will appear once the backend contract is re-synced. Confirmed live against DEV on 2026-08-21.

## Prepared Test Console scenario

No canonical scenario is currently associated.

## Real response

No approved real integration response is currently published. Unapproved candidates are never rendered as examples.
