Feature · REST API
The COA API for your store, ERP and labels.
The same API that powers the COA Comply dashboard is yours to use. Connect product pages, inventory systems and label printing to always-current certificates of analysis.
30-day free trial · No credit card required
curl https://api.coacomply.com/v1/coas/search?q=B126 \
-H "Authorization: Bearer coa_live_…"
{
"data": [{
"id": "coa_8f2k…",
"product_name": "Raspberry Gummies",
"batch_number": "AZ-RB-B126",
"state": "AZ",
"overall_result": "pass",
"links": {
"landing_url": "https://verify.coacomply.com/Ab3dEf6hIj9kLm2n",
"pdf_url": "https://verify.coacomply.com/Ab3dEf6hIj9kLm2n.pdf",
"qr_svg_url": "…"
}
}],
"has_more": false
}What you can build
Everything in the dashboard, available by API
Upload or import
Send PDFs as multipart uploads or import them by URL. Pass a brand and state, or let AI detect them.
Search every field
Full-text search across products, flavors, batch and lot numbers, certificate IDs, METRC tags and labs, with brand, state and category filters.
Permanent links
Every COA returns its landing page, QR scan URL, direct PDF and QR images. Links never change, even when a COA is amended.
Scoped API keys
Limit keys to specific brands and to read or read-write. Revoke any time; last-used times are tracked.
Structured lab data
Potency by analyte, lab-stated totals, panel results, dates and parties come back as clean JSON with snake_case fields.
OpenAPI docs
An interactive reference with every endpoint, plus rate limit headers, cursor pagination and consistent errors.
API keys
Keys scoped to exactly what each integration needs
Give your storefront a read-only key for one brand and your ERP a read-write key for the company. See when each key was last used and revoke it in one click.
- Per-brand or company-wide
- Read or read-write
- Last-used tracking and instant revoke


FAQ
Frequently asked questions
Yes. The COA Comply REST API lets you upload and import COAs, search them, read every extracted field, publish them, and get permanent landing page, PDF and QR code links.
Each key belongs to one company and can be limited to specific brands and to read-only or read-write access. Keys can be revoked at any time and show when they were last used.
Yes. POST a list of URLs to the import endpoint and COA Comply fetches the PDFs safely and processes them like any upload.
Yes, with an interactive OpenAPI reference covering every endpoint, request and response.
Get an API key in minutes
Start a free trial, create a key from the dashboard and make your first request today.
30-day free trial · No credit card required