Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Very complicated application.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
01404202769575e16078b3ced07f34b138174e5b30563b082e8f4630a6421720
Signature (Ed25519, base64)
iThouj1guQHbrMQSj86XYjoecN95zvpB9RniwTYCJj2Zm5ZPuW6KfYdgW0iBhQrXPKfKInjvLgBkz17IhNzpBQ==
Merkle root
2f068f3de56bebe7a575ba4a979c9244445d2350140e36238e088fa40fbfdd88
Merkle path
["013a0f5b00721e5f1f231d66a4582a6bea9c8f98833bfccb6f63da86e4dcfde2","ef97ff5172746bfff1718cda827d3c9e72d3ae2d95ca9fda42d7981596a3ce8e","cc998effbf1df72e10007863e36530dd07b620c4035075e3843e3946a72263a6","bce4a815263a71a5f1d58428dd4cc154528cdb982a5b3c99fc43e8ca8a1c1e24","3b26e92a07bb5f84c96a07ac8b9d933f16ffc88cbe72adb05901737edfcf6acc","6ebd24a1775026afe9c2a5f1beebe372fb94132afddb708047b53528c23c7c38","11ea0df65ac8da075857a7467bfb77412beea7a08fbe191bc1285c92dfca7707","f226bc27469262dca16ff7cb39416ec50977083be9619ed67ab6a64b3e7af62f","6074f736bd5c6ee0af0e869c4fef15e6024a34b2557868115ffaf8e6ddbbebd5","f9495fcec948241bcacb6ae2112b8336cf3e60befe07e8d0829fcb147b08ad9e","690933983f0a244df3aebae4e72a9804c1ad8d0da62122c4e2d474a25aa23342","db8b9402749163dd7028471f175d7d75f6482cc73467c43e4ddee59d4a6d5020","3b092fa48a78448b4db01d94e347dbde2c39988a6fba76ec91ab78b6f236682c","03c5fc675733b417d9af5e071de3aba38ae7f09fa5781cbd0133ff9d4e234e36","98191c82333f4385e47f318835e01d44ca8835262c6d0df40edfd5f6a4dc5c19"]
Anchored
2026-09-20
Public log entry
search.sigstore.dev, log index 2893887498 · entry 108e9186e8c5677af79f…
Expected log hash
90099e0300c6e23b62e79318296ebab91bff130379d248ada57f044f77e72ccd The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1789796056710","kind":"published-quote","locale":"en","page":"brand:atupri","quote":"Very complicated application.","rating":5,"review_date":"2026-03-04","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=ch.atupri.myatupri","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (2f068f3de56b…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.