Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“the QR code for uploading photos only worked for a short time”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
0ac78679d0c7e3986c0651f034bf526da895b5cf813d1ce4223f943119bb0950
Signature (Ed25519, base64)
JrHVJgWpSVc+Vp+fKZ1GiRgYwKgQUppTEaKAASapXdJR88T8auT1iLidWBnAaMlpxFfwEOFuewFUfbnRqqLBAg==
Merkle root
596f968cccc56e8e000b63b9dd30489d92d97de49657c3c152b38018ff4fca5c
Merkle path
["0ac8ce705978700f2f78dd6900508a7bd410be39cff5d0f1e20d190530df5d93","36c97926560077b173780b05bad86c928337a4ffdbe5300d9d6bfa91ca60bda1","53bd3ac2cb322542c09ad598b271439c4942be37754cc1b5ee95ccd9b1a0c3d5","debdef069cd11763d7ed06c615f39c7ab2172c57f3e247b660f3717bd373af71","6d2e3f5cd8d189852b2adea1b62edf6f52207c8889e9725f2805494470f1abf4","bbac636f403616312a4a832ce84f423f5b95db15457083d78c96a67b2df89cb2","e673ec4b3261244d64598d7e3495301c9560556fb3f3e766633079cdebb587c4","6c7b1f4ed2b7f367647256ee06d967a08947281cb1e7f4c923c9fc88777ddf10","675f15b383bbf75c875396793a669b42e55fd0a31b9cbedcaa85ccc7b5fa9332","69cf08bc7d8bdaaa3ad7c7e6642007d8d96125fa9773504a6ae117a8ccc96d90","a4c1f64acc073d33f0f6aa6b94e5c00c2c63cd553e121e3de38014ead3b0dee5","a2e63b38a500e0e747fa2ee593ce640601b396a882812dccd45f6e723859d791","8e868d52b37c0ca851c758cff6792552e789a45811741cd2ab35462dd346c599","f34a99bc2eb0f4358a151b675878bdf5ad21628e2f02e9070ad22d026160a11f","1def65a8c7022796c92bf89e3ba0ded5702ff898262447be3bcca696fe961465"]
Anchored
2026-09-02
Public log entry
search.sigstore.dev, log index 2682369737 · entry 108e9186e8c5677a1ae2…
Expected log hash
21add9acab3ef5374d6a20f71e18493c941f530ac81d350c83b699eab93536cd The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1788315101182","kind":"published-quote","locale":"en","page":"theme:cewe/material/en","quote":"the QR code for uploading photos only worked for a short time","rating":4,"review_date":"2026-07-31","source":"Trusted Shops","source_url":"https://www.trustedshops.de/bewertung/info_XE3D21EA81A56276ACEED1C9AFB85F941.html","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (596f968cccc5…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.