vialproof
home / Guides / How to Verify a Certificate of Analysis at the Source
guide

How to Verify a Certificate of Analysis at the Source

A step-by-step guide to authenticating a peptide CoA on the testing laboratory's own domain, and reading what a broken verification link really tells you.

By Marcus Vela · 2026-07-26 · 6 min read

A certificate of analysis (CoA) is a document a laboratory issues to describe what a specific batch of material contains: its identity, its purity, the methods used, and the date of testing. To verify a CoA at the source means confirming that the document came from the named laboratory by checking it on that laboratory's own website, usually through a verification code or a QR code printed on the certificate. This guide explains how that check works, why a source-verifiable CoA is far harder to fabricate than a PDF hosted only by a vendor, and how to interpret a verification link that leads nowhere. These materials are sold for research use only.

What does verifying a CoA "at the source" actually mean?

Verifying at the source means the evidence is confirmed on the issuing laboratory's own domain, not on the vendor's website. A credible CoA carries a verification mechanism: a short alphanumeric code, a lookup URL, or a QR code that resolves to a page controlled by the lab. When you enter that code on the lab's portal, the lab itself displays the result it recorded for that batch. The vendor is removed from the chain of custody of the evidence. This matters because transparency is a documentary property, not a marketing claim. A named, independent lab such as Janoshik or MZ Biolabs standing behind a result is a stronger signal than a percentage typed onto a letterhead. To see how this single check fits alongside nine other criteria, PeptideTrust explains its scoring in the scorecard methodology.

Why is a source-verifiable CoA harder to fake than a vendor PDF?

A PDF is trivially editable. Anyone with basic software can change a batch number, lift a laboratory logo, or nudge a purity figure upward, then host the file on their own site where no one else can contradict it. A source verification breaks that control. The number you see must match the number the laboratory independently stored under that verification code, on infrastructure the vendor does not own. To forge it convincingly, a seller would need to compromise or impersonate the lab's own portal, which is a far higher bar than editing a document. This is why the location of the evidence matters as much as its content. A vendor-hosted PDF asks you to trust the seller; a source-verifiable CoA asks you to trust an independent third-party laboratory that has no stake in the sale. The two are not equivalent, even when the printed numbers look identical.

How do you authenticate a CoA on the lab's own domain, step by step?

The process is short and worth doing every time:

  • Find the verification code or QR. It is usually near the header or footer of the CoA, sometimes labelled "verify" or "report ID".
  • Go to the laboratory's domain directly. Type the lab's address yourself, or scan the QR and read the domain it opens. Confirm it is the lab, not a vendor subdomain or a look-alike address.
  • Enter the code on the lab's portal. The lab should return a record for that batch.
  • Compare every field. Check that the batch or lot number, the peptide identity, the purity figure, and the date of analysis on the lab's page match the PDF you were given.
  • Cross-check the vial. The batch number on the CoA should match the number printed on the physical vial.

If all fields agree on the lab's own domain, the certificate is authenticated at the source. Any mismatch is a finding in itself and deserves scrutiny before anything else.

What does a dead verification link tell you?

A verification code, QR, or portal that leads nowhere is one of the clearest transparency red flags. A broken link can mean several things, and it is worth distinguishing them:

  • The code was never valid, and the verification mechanism is decorative.
  • The laboratory named on the certificate cannot be found to exist.
  • The portal exists but returns no record for that batch number.
  • The QR resolves to the vendor's own site rather than the lab's.

None of these outcomes confirms the result. A certificate whose verification path is dead is, for evaluation purposes, an unverified certificate regardless of how professional the PDF looks. It is the documentary equivalent of a reference who never answers the phone. The presence of a verification feature is not the point; what matters is whether it actually resolves to a matching record on the lab's own infrastructure.

What should the verified page actually show you?

Authenticating the source answers who issued this. It does not automatically answer what the result means, so read the verified record carefully. Purity is measured by HPLC (high-performance liquid chromatography), which separates the sample into peaks and reports the target peak as a percentage of total peak area. The chromatogram - the plotted trace - is the real evidence; a bare percentage with no chromatogram behind it is a weak signal. Identity is a different question, confirmed by mass spectrometry (MS or LC-MS), which measures molecular mass to verify the compound is the peptide claimed. A sample can be highly pure and still be the wrong molecule, so both figures matter. If you want the distinction in depth, see the guide on HPLC versus mass spectrometry testing. A verified page showing a named lab, a batch number, a date, a purity value with its chromatogram, and an identity confirmation is a complete piece of evidence.

What a verified CoA does and does not cover

Source verification confirms authenticity and lets you read composition. It does not extend to properties the certificate never tested. A standard purity and identity CoA usually does not include sterility or endotoxin data, and their absence must not be read as any kind of guarantee.

QuestionMethod / standardOn a typical purity CoA?
How pure is the batch?HPLC (% by area)Yes
Is it the right molecule?MS / LC-MSOften
Bacterial endotoxins?LAL assay, USP <85>Usually not
Viable microorganisms?Sterility, USP <71>Usually not

Endotoxin and sterility are separate tests; passing one does not imply the other. A CoA describes composition at a point in time, not safety. Keeping these questions distinct is central to reading lab evidence honestly.

Where does source verification fit in judging a vendor?

Source verification is one line of evidence among several, but it is a decisive one because it removes the seller from control of the proof. A vendor that publishes batch-level CoAs from a named, independent lab with a verification code that resolves on the lab's own domain has demonstrated documentary transparency in the strongest available form. A vendor that offers only a generic PDF, a certificate reused across every product, or CoAs available "by email on request" after purchase has not. Accreditation to ISO/IEC 17025, the standard for testing-laboratory competence, strengthens the signal further. PeptideTrust turns this literacy into a weighted score so you do not have to grade each vendor from scratch; you can see how sellers compare on the ranked transparency scoreboard and apply the source-verification check yourself before you rely on any single certificate.

Research & education only. PeptideTrust rates documentary transparency, not product quality or safety. Nothing here is medical advice or a recommendation to purchase or use any substance. Research peptides referenced are for laboratory use.

Frequently Asked Questions

Where do I find the verification code on a peptide CoA?
It is usually printed near the header or footer of the certificate, sometimes labelled "verify", "report ID", or shown as a QR code. Enter that code on the testing laboratory's own website, not the vendor's. If the certificate carries no code or QR at all, there is no source verification available and the document can only be taken on the vendor's word.
Is a QR code on a CoA proof that the certificate is genuine?
Only if it resolves to a matching record on the laboratory's own domain. Scan it and read the address it opens: it should be the named lab, not the vendor's site or a look-alike domain. A QR that leads to a vendor-hosted PDF, or to nothing, provides no independent confirmation, so always compare the batch number, purity, identity, and date shown on the lab's page against the document you were given.
What should I do if the verification link is dead?
Treat the certificate as unverified. A broken code, missing portal, or a lab that cannot be found to exist all mean the result has not been independently confirmed, regardless of how professional the PDF looks. It is a transparency red flag rather than a neutral technical glitch, and it warrants scrutiny before you rely on the certificate for anything.
Does verifying a CoA at the source tell me the peptide is safe to use?
No. Source verification confirms who issued the certificate and lets you read what was measured, typically purity by HPLC and identity by mass spectrometry. A standard purity and identity CoA describes composition, not safety, and usually excludes sterility and endotoxin testing. These materials are sold for research use only, and a CoA is documentary evidence of transparency, not a safety guarantee.
See the full scoreboard → 11 vendors ranked by CoA transparency.

Related guides