Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“das App beim einscannen von Belegen funktioniert nicht richtig”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
0ead409655144d782d92a5081ac572074c4db149e1eddc8526a31e42e55c6e91
Signature (Ed25519, base64)
CBQ31KMtNtG19emkHrzdno5CVLNxqw1RV9dVeuh3A9/VZ7s3kpIfm8OaYSE4DtwWm7hHaE7ispDnQpyOMuRBCw==
Merkle root
d172a7cf956e2b148257f1904430b57957f1397e7267d8861b84c949d8e35e40
Merkle path
["0ead2f519996513e46aadbf0d2f74a2ed1f404b098378cee806f3004e2a95ccd","6c4659f8d8578a586de437eaf39486e5b528f0ce81274e949a4190339e3729e0","f36cc0c3259410552f95d87ff859ced66c85c3ae6de38dee095ec534e314d983","abf185e3b2abb5ec272d57661d7a9d30206bd236a2a1948bac117162aaa31804","75bbb5a38b7364254452a9d7e2ae8e85498b260a89c2b367fd06deca572dcd2a","bf1de3a1885f77020975f7f886e21e3c004c5be4b89a826e8aad9c6b8b58be82","93ec38714b6054177be990206b635b6f6614e6184a56d4c6f39ad316749437da","d8852f7e5b10402b8044d9a878120e3a2972aab47f53b1d1188f245fdd892e78","aa2f17ea909e6f9730dd4b7b6628db9f92a210a0c08a95e796c85dc18ea7fe43","5f8e94eb3956812904a8e0dd0a1833c42619e50ee822e592aef0f0d056660c38","1b884db2791044311f61e64ae2dd1232246723259327fd8ccf25489189fb2cf7","94ae8e4f6adb62d3dedb0d45f6cb3bc7ee886f50c769e386c26dbcd96e444beb","ec9d22a60fb3373395242e0bee52cae203406eed591b174f096249c369d00f81","24b78eb17781ff82da235316ce22b13d8e2206e794b324b0ed78181b6c334313"]
Anchored
2026-08-13
Public log entry
search.sigstore.dev, log index 2445296928 · entry 108e9186e8c5677a0a62…
Expected log hash
c9abcace05ae14f54b0d99899537438e06fb4d27f22b95a0509613937d3e30c6 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1786588795034","kind":"published-quote","locale":"de","page":"theme:bexio/ordering/de","quote":"das App beim einscannen von Belegen funktioniert nicht richtig","rating":1,"review_date":"2026-03-16","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.bexio.bxBexio","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (d172a7cf956e…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.