Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Great replacement for my previous authenticator app”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
0b55aff46c2cabc682b42114caa85f52917b4bb7a59fd1a4d92c8e24e4642b81
Signature (Ed25519, base64)
/XQ9RHX4Gkinabp/v93ceKFaeW+RK68U8Nauw9FFTUWoKNUsyr+wqdY69nE7pL/UUxiCjTPgipE0kxX4xWk0CA==
Merkle root
b50c49a22fa48572e59110f158a3e38dca411e70b7df05ca4ce3240cde9a105e
Merkle path
["0b57501c54a579c7f918bce88e2f33f3d1782f7ca461331621c5d849908192d8","fbd2b07be5a7aa794c96fee0e62c3a70ba69426865d0d281b2708391de2b593c","322c6e6cd5980d7fe899f93417f5c74d69d231fc05905c3f9d835bdd2ca4d42c","fead55a4e9604fc15c30eea69c05aac25f963f7b793a37b66014869ebc033ecb","2fcd1d253b7e6e1d2c5d1d58ce245637e11b0d28d2422c0cc9f65bc79befdcea","68d1a27614cc5f2c50642b3d52bfa9d9b0bb0a6e668859e2127f7e13fd0d6027","46057ceb4674acf8dc196cd07261384e78d2e74095704dd4763804ed28472e78","aeedf09df410f9d3d1faebe69992d2b5ff276ab7a92140a98f181e4de27a8553","9a455fcc039323f333cd367d248e49016be8686ae8e3ceee17bd61b3c1fb7552","d046ec6e318c4407be1f6a13184d1074ee554987f2ad99fff0eacf83c35f8233","acbd5e0bde731b547ee5730b42b23ac6df0dcf10a4008b1afa6c00985559b5a6","f226f41ab142ab66a4d46788fad93ff5ffb8de098523db434b21c241fd9c672d","2ed82a4b5c03fd2e536cd8ec085ddfeafb1fbf3b5ecf77543d03ac03322a0ba3","0f6faeb45818dfeaf393e3820d4f557973a442246fc59091fc93ac88627b190f","2e701d6eede48cfff654c6f160a417a29bcca8f9f41ec1623b3f3f9f6f4ec566"]
Anchored
2026-09-02
Public log entry
search.sigstore.dev, log index 2683566971 · entry 108e9186e8c5677afaf0…
Expected log hash
3fde45a3d66811fca8014f4f116c6ed165f22a40a67f9ab4532375442c4a7526 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1788326310539","kind":"published-quote","locale":"en","page":"product:proton/proton-authenticator/en","quote":"Great replacement for my previous authenticator app","rating":5,"review_date":"2026-07-18","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=proton.android.authenticator","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (b50c49a22fa4…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.