Authenticate every request with Authorization: Bearer <your-api-key>. Create a key from API keys (Business plan and above). Responses are JSON, wrapped as { data: ... } or { error: ... }. Requests are rate-limited per key (60/min by default) and every call is logged to ApiUsage for your own audit visibility.
List vendors.
Get a vendor, including domains and aliases.
List laboratories.
Get a laboratory, including domains and verification endpoints.
List compounds.
Get a compound.
Get a batch and its public certificates.
Get a published report's full evidence (404 if not public).
Look up a published report by its laboratory-issued report number.
Submit a COA for analysis (multipart form field `file`). Requires the Business plan.
Get the status/result of a submitted analysis you own.
Get duplicate-detection matches for a document you own.
Business and Enterprise organizations can subscribe to analysis.completed, verification.updated, batch.updated, document.added, document.changed, and fingerprint.match_detected events. Each delivery is signed — verify the X-PeptideProof-Signature header (HMAC-SHA256 over the raw body, using your webhook's secret) before trusting the payload.