Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Un excellent remplaçant pour mon ancienne application d'authentification.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
07e022d31a507466f051f9f058a1002a7d26651dddbdc6fe36986c73c60ec091
Signature (Ed25519, base64)
dHzXv2oneHPzUSwGHyc1QAzw/XZFxpZ31lnTsYg42Fy2Ib1Pd8qdVteb7Y1H9ALqVKqZrP6r/nm6QIZ4Qoy7Dg==
Merkle root
57e60dc521a4ab8ee39747670ba01310ec9c3f92c64800e03425c0a645a7f8c3
Merkle path
["07e035e3b17457d4ecbac4042caff8e161549a5fb31e091a8f47da50cfd8ea0e","e6b5d2b210b41dc86dadcb1f31e2bfba9b321918747f4f948655bfad0193b482","6a1784f715c4e5b1e2bac1d7ebd347bb7948543b0970d0b43034634e574cee61","dda598d17ab81dd2a4c88c245d320ea809a7e98a9542383320052a8199be0f9b","22fd621276bb03182efe5487e315cf76157720e2b1fbf34ab5e6d547d547bc97","e1408619a2869f2d7b73b624b255e9f52afebdbb16d6b420e00fc37335ea5b69","6e07186071f542f3da22cee9c46e591dd4f3388d8016b5a045ca802572ad4003","bb2c83a0daf7adc110be12eecacc593e7f136c89b05fe65807a74d5b319ed21a","41a19b3cbd4e200f61346b7c7a2c5aa52abc318b0526428d407a6a41fc966585","e29289300e7e5fb4ab57148d1f6ae3dcf174621ea612e26fe246750d901c4882","727fd922a23c440ac2a60248f361a2b3785869137989ecad4faf9b75cf8b3fda","93c63a80b8e3489d0ab8339ec4503845df462143333ed3d531894d0e245f4a12","fe5d111587316ff31f5b38fa29f046572eebf5a2bd99ba16667a173d27f92a5c","dcda2bb48f4a1ab26f6126b1aaafb184e5f8d3630133c0cad42caf115918a81c","a1d5535cf9f405ffdd99d322e20ae6357cbed1419e88c64471b565623f0a674b"]
Anchored
2026-09-02
Public log entry
search.sigstore.dev, log index 2684249937 · entry 108e9186e8c5677a47d4…
Expected log hash
46538ec60065603bf54101fff011eda05a02a8a062bf118596692399059b11c2 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1788336087966","kind":"published-quote","locale":"fr","page":"product:proton/proton-authenticator/fr","quote":"Un excellent remplaçant pour mon ancienne application d'authentification.","rating":5,"review_date":"2026-07-18","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=proton.android.authenticator","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (57e60dc521a4…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.