Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Please add the function to upload/add from pictures to the inbox”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
0e0117cf2992f1c3ee11d11dc6a574bdbc262d7edb18fbe9d5890f957eda0e75
Signature (Ed25519, base64)
UqcsJVAQVcxBEGPvIivM/hssX2mdFr1MGLAcg9SQU8vjguNag/I8j7S0FYszDg4Fkp3dodFJh/wa4Jn2XTcbAg==
Merkle root
17f5621c24e3eff18a9eb7bd68066975964859abb177620140d484c818bd5279
Merkle path
["0e0335e4f03fee6250d3f53f3a9743611130bb1e8ca92665ba02986ed5e64a21","8e16d4bf8da44b1bc4318922ed2535b2acccd3b900668916d64c672651dc3495","05549595ac5e511c8474b8924d8ff7aac1b946aafafd4c01fb3ad622205fd163","3b22b757eb6ba1acb046c436550649e3618a2385422032ca7e609b7e133ba3af","94074d97ff06f6b802872460c1df890f0475df085b063361c53389681226dbf4","e64e132970b84171280daf0bccd9cb6a3b6b081b07dd828a1b5676fdd95e1395","424148879e4d4827ba02a46a0d724701565bb20e7b8163cdbd1210f8228824a6","01f428acb52bd6e24370a9a4fac205aaa934b0ea66cec24bdf202ceadc47e160","10da373fdc28ea8074f32ab698a70d25823f4aa5c3fb3338efe0a5b37ee5bbdc","327cd27e6b944f458bcfd79fcfea2a8bd298753fc9cb3023fe63857e9ce16a83","4ff7f58674f77360a47cbb5674357871fc79d038c63cacd20c5da4d21091e9be","e0b1951729c99fbb01de815b31b388c4e1893e038f596c642187fe535682a60c","79be0fb1f5b41c5aba25203027289d744232254bbf10ab32b1815d2c378767d2","589b0bc49a2f8c320bab032e186f6f9156dfac35cfff015dffeba8a096d0654e","02fd17cca8bdc04921d1d0245205fa97c0cdb96191365c231d548c0ad4b381f5"]
Anchored
2026-08-24
Public log entry
search.sigstore.dev, log index 2579439915 · entry 108e9186e8c5677acb33…
Expected log hash
a5a7b749ed8256b8527671a66249deb9067f26413922e3ca3f056cbfae182396 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787539629003","kind":"published-quote","locale":"de","page":"theme:bexio/ordering/de","quote":"Please add the function to upload/add from pictures to the inbox","rating":2,"review_date":"2026-03-31","source":"Apple App Store","source_url":"https://apps.apple.com/us/app/id1481169504?see-all=reviews","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (17f5621c24e3…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.