vialproof
home / Guides / How to read a peptide CoA
guide

How to read a peptide CoA

What a real certificate of analysis contains, and the red flags that separate genuine third-party testing from a decorative PDF.

By Marcus Vela · 2026-07-09 · 7 min read

A certificate of analysis (CoA) is a lab report describing what was found in a specific batch of material. In the research-peptide market it is the single most useful document a buyer can read — and also the easiest to fake with a decorative PDF. This guide walks through what a real CoA contains and the signals that separate substance from theatre.

The parts of a real CoA

  • A named laboratory. The report should identify the lab that ran it — ideally an independent one (Janoshik, MZ Biolabs, TrustPointe, Liquilabs and similar). "Tested by a US third-party lab" with no name is a weak signal.
  • A batch or lot number. The CoA must tie to a specific lot that matches the number on your vial. A single generic certificate reused for every unit of a product tells you little about the vial in your hand.
  • A date. Analytical results describe the batch at a point in time. An undated CoA, or one several years old, is a much weaker guarantee than a recent one.
  • A purity method and result. Usually an HPLC chromatogram with a percentage (e.g. 99.0%). The chromatogram itself — not just the number — is what a reviewer wants to see.
  • An identity method. Mass spectrometry (MS) confirms the molecule is what it claims to be, not merely that the sample is one clean compound. Purity and identity are different questions.

Red flags

  • No lab name, or a lab that cannot be found to exist.
  • A percentage with no chromatogram behind it.
  • The same CoA linked from every product, with no batch number.
  • CoAs only available "by email on request" after purchase.
  • A verification code or QR that leads nowhere, or a portal you can never actually reach.

Verification is the real test

The strongest CoAs can be authenticated on the lab's own website, not just downloaded from the vendor. A verification code that resolves on the lab's domain is very hard to fake. When we score vendors on PeptideTrust, "CoA verifiable at source" is a criterion we test by actually following the code — not by trusting that the mechanism exists.

Sterility and endotoxins are separate

Purity and identity say nothing about whether a solution is sterile or free of bacterial endotoxins. Some vendors publish separate sterility and endotoxin (LAL) reports; many labs explicitly exclude those tests from a standard peptide CoA. Absence of that data is common — just know that a purity CoA is not a sterility guarantee.

Once you can read a CoA, the PeptideTrust scoreboard shows which vendors actually provide one that survives this checklist.

Research & education only. PeptideTrust rates documentary transparency, not product quality or safety. Nothing here is medical advice or a recommendation to purchase or use any substance. Research peptides referenced are for laboratory use.

Frequently Asked Questions

What should a peptide CoA contain?
A named laboratory, a batch/lot number matching your vial, a date, a purity result with an HPLC chromatogram, and ideally a mass-spectrometry identity section. Stronger CoAs can also be verified on the lab's own website.
How can I tell if a CoA is fake?
Watch for no lab name, a purity percentage with no chromatogram, one generic certificate reused across every product, CoAs only sent by email after purchase, and verification codes that lead nowhere.
Does a CoA prove a peptide is safe?
No. A purity/identity CoA describes composition, not sterility, endotoxin load, or safety. Those require separate tests, and nothing in a CoA is medical advice.
See the full scoreboard → 11 vendors ranked by CoA transparency.

Related guides