Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Songs work; however, the widgets do not function, making the app barely usable for me.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
1235ba7eb8c19f6f158a0a4273cbfc51dac1d9bcca29b3ebb84e106621481a90
Signature (Ed25519, base64)
xhg0XTtt8wlmJxb7DshAbTphBQtD23kct9aHRXy79JAJsuAmoSFsDq94Yn+xQZiHMKeWfQj1Azext+1c+Ay/Ag==
Merkle root
61c0358904092135da9dcafe8883af2adb0c61440bf491948394c6fe07255cf0
Merkle path
["1236aaa842e9caab995ee6be8b3bc8ec9caccfd4c572ae1f8c09ec4827149986","d1695d53befb332fbf4b40e356e8ab474bb07dda94e5452550e55fe7b79c1c7c","afea5e5000def1d16ca40f9e0ca4dcb2d4043596da60de65af22e2bdd484529a","785a6b3d92b1cfcc519f3264aea8776fb580c497e266ad3fc03e9f0fdbdd4701","902801124e35934a0fac42e7d113cc9fbc3fb4f5d4fc771200e136d2c8e91b73","9d0f681f624f0f0a3961478dfdbed45a10333e101177bf5ad15b49ea9d8943f9","98a340ab1fff6b4ef1c9e7b03a8cc112c52154220498daaf185e0ed3e09e3239","a8bce49ff4e69dabc459de0911a75ff497b13fc95744281088dcb0bcc247ea9c","15bdf835da70b517836c68f5cd01c89d558955dd3d21e499cce44264ab0b1c78","244fb7174cb748ca1915b1893f0df2c162c6048dca246dde8f4c6281ffaf9578","d271bf6bac47df993447020601c567ff2b4bcb045daf2184834525ac16bd8786","87520a43200c2a64131784e9fcaf857a7240782996abb4557bb54db56d1e2ad0","71cae424255aa4638e3d855f2e4d0d3ec8f410d9b00b335969ebfbb7884e48de","5f85197a8394f334f8f9e8be202ba3ec072c11f71435e83d07f11a0a073ecf02","6b5b9926e6b590cb1bd6278f63edc47584ee36101706f8e0b22f8404af273127"]
Anchored
2026-08-24
Public log entry
search.sigstore.dev, log index 2579329594 · entry 108e9186e8c5677a2f40…
Expected log hash
bb1ce4990105a11e35218e4ee0348633e0f4be8179db75acbed652ddd79f7a87 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787538369368","kind":"published-quote","locale":"en","page":"product:meteomatics/weather-widget/en","quote":"Songs work; however, the widgets do not function, making the app barely usable for me.","rating":2,"review_date":"2026-02-22","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.meteomatics.app","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (61c035890409…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.