Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Since the last update, you can only create invoices in the app.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
0e2499a544caee3cf49e2da2ea5eb15eda00df4826ce3bc4a70728fdfb6704ce
Signature (Ed25519, base64)
YxpNdS4fi29ttvjQyiCpUErpuodBd8nObHW/su9TzeqRIsuB+iCMnMC9v8gUITyeBtz82cI9EgrpvD0F3CFLAg==
Merkle root
2915d94fc718eb48f67362a65d9a83b80dcd4c926c786eb2e38f4d8ced0439b7
Merkle path
["0e203d22e696ca469102a2fdbd8b7af4d00d98e09d2ece6649cccdc44d2755e7","959090ce86905278cc1d4d5c1622a349412b3d8c5e2c08e8e7b84e1fbcc151fa","c30449028bb757a6e9d13f420a86585cbc2699c3bb07dbb8b5610efefc8bdc4b","8d2d5d843a474867ff57b7059c26f7e6a58262acbd73119143c7e0b77749f97c","16ca449f6fb5c3032a306ee3a220b9f478fb00c12071b653037a656e07921c79","632364c585b2e254889d3b2ff3dd8d79f7cf30293744f5b91a9a7385ddc94455","38ddaa7b495bea17589833680e4e82479774f0a384b42da7a07cc0cffba91b28","8fc88e514a486f17ba1546034c0ca485b831b763c6e33548021ca0b688e62c61","c041c9491af308d886b7c6a7db1b4e78110f5e102bcb0114acc77051a17ef0dc","1169672351caca2e061fe652cee99ec9e72c82f2cf1f848d2fa21b6de7c36cb9","051ea78f9b051571a178fbf2ae098d3d2715039e8aa0e55b5a7ab058764b50c6","a67e5025ed174812cc85ffad7fb608d1ec0e7e7057369282aa8c38f78ecb6fb6","dbdc65b9f91ecf7a21686f427f84950f149ff3313cf7cdbaf938355c0225fc98","5b8a2081ec81ef2101256bd7209457c75dcc1be14257b40200d45a88003c0c32","1936eb7713ae59e20354a37b8314d3745433b23d047da205242414a6fea32b67"]
Anchored
2026-08-31
Public log entry
search.sigstore.dev, log index 2657230937 · entry 108e9186e8c5677a80c3…
Expected log hash
1d9aec1bd239e45b6e622f366eaab4292482e627111ddcfb4c651bb1e08e92ad The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1788143889053","kind":"published-quote","locale":"en","page":"product:sevdesk/e-rechnung-software/en","quote":"Since the last update, you can only create invoices in the app.","rating":1,"review_date":"2026-04-29","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=de.sevdesk.sevdeskgo","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (2915d94fc718…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.