Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Non intrusive Ads in this app.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
0d8dc7f9fd4947b6571bfa940b57c599a938546ca7e165463312eae3078048e0
Signature (Ed25519, base64)
0OqMs+9CT3oZXn68cL630UMv4NEykHjhDrm5mbIfW6ExQmxC7JgVwLaKUK/4W9pJ96ly9/zQxHyHzxYIew+wDw==
Merkle root
249a627257bd2a9dbd9bc74ec65dce63e29c9ccd8f402432a46bbf1cfa12c86d
Merkle path
["0d8d86dc834e5b1fb758262709d594504b9b5bc0afd6f394156d878e0ef19514","f11a1112436392f2792f12c18c94dcafafcc00e64adc57b1418869a449291a01","72194621cb739ff49a8316ee3bf800382648fa1f06c0fa2f8bedccae05fdf5d4","9d820542d1a6b4001c8cb2502af844426fe420b8c42cfcb463afefbd44299c63","561626b1a428fe01e07483761e8c61544fbe23da0cf6ce7b199acf7e856d2f09","fa32201a759fdc2611719c6f0ba71df0b1331d9a9804b2c8d8221788e985c839","a9e794fe8934327b238937e96abc04d8a2db8cf386e5b88c84b639d1104680ac","63acb8dbc08c17e4c81a5ff2722ba5b240c67472763abebd6538a1fdf24b0187","a456f908fd4ba5c6268726c355e55d6f28127c7987e864b7321d3bacac89753c","08edefd4693fa0aa7333d87469629603fb226935c66348339583991e4074ff89","69e410b5b5c48b40f8e52c4f9c155f124fae82584906da27750633db67b1b9dd","93da08a32a88984f43cb8cf77dc9f15f59275e83068c84de6557b04be928f845","eb7727f04a590b9f55c190f90839cbf73f485e828dfdac586db4b55a34076c29","c94857f058a09552518db3b6411014dc84d9bd9a71b10e488f83e40faa66dd70","98481510f61448eaf55101f28c348e05af213e498327b1646c7ec76c471de7a8"]
Anchored
2026-08-26
Public log entry
search.sigstore.dev, log index 2595205423 · entry 108e9186e8c5677a9f26…
Expected log hash
fbc678ced8e0822086692e4ab6d232b628f26b1a50cd2c52eadc2f6910e32e8a The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787717877847","kind":"published-quote","locale":"en","page":"product:meteomatics/weather-api/en","quote":"Non intrusive Ads in this app.","rating":5,"review_date":"2026-06-26","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.meteomatics.app","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (249a627257bd…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.