Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“The only downside is that one can’t pay in from outside of Switzerland.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
12c7aaf7c1be5eca1e5dfada569e1e69f059b96a81841738d75c06d163161e47
Signature (Ed25519, base64)
KucDTPGOO6lELPlE//FKpwVWmAXTr8Mn3EW8xAC1Y0uNfBW2JPuWoP0F5B89BF4YxtTjpL7Ew+36VxuKb/UmBg==
Merkle root
cee60bb6c0816d1bc69326ea12cf0c5c00cbea13afa283147bf24b52e30f839c
Merkle path
["12c9a5f3663c40628386822ba664c22ad7ef567e790624325cd008f1cdca6786","7c6ddd7e4830ff36f0209d30f80847b111b519bc54133d65b9743f8ff35b4ded","be09c7873661c1b2e7b78f860361e556857bd132cd127a85190b92b970137baa","53366074c8c161b29a4e0544db19f0a4e7f4818a7796dd12cdf581452f8a9719","14639b7fb94748fe767ac4ec477acc0b1ce58da1c3f4c38b365821d89223c45a","37eda9674e68041793799a6dad5cf8f74aa9e30c8dd481a99603177e109d80b9","f66a215ea0f73f73123b89d849710accb0b87e5ac6fd8678e07d224b7c4587ba","8a462d94440e615fb2fd0469fc7e9a5a07866696006c9c90ba1ee4970ae39a61","e69d37dc29b1eee0a68d69779a4c4bd577fc47454ba58c7eb0b5baa3a2575213","615de311f2195b8a081f2f99c862c312fc619c5fa99ee048b1764dd18d57a587","c4be5fa985850fc4dfb3ffa618b8d550a69f66d3d82b49db02ff30ed91385483","d91641b993c3e8dfe69bb82ee13578bbb33371688b0fdbbf8fd534bccc3e9c6e","a1c11df65738ffb18228c247fd6ad5fc76428a9130a0079c6abf079e9cdfe043","806b2b46dda360b28a8a38da683f56d42f23ab9c4a7b2fa07453f271a33f5ff0","57e3801fc0af4bd2492130e334ef2d0425fdcd10c95109df38ad0d371e279fbf"]
Anchored
2026-08-21
Public log entry
search.sigstore.dev, log index 2543857133 · entry 108e9186e8c5677a5231…
Expected log hash
d8e1ac8b740526c2915424d7f7c6bce881a4ef05d0a3a3dbd88e4c760e36623e The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787288037224","kind":"published-quote","locale":"de","page":"theme:findependent/price/de","quote":"The only downside is that one can’t pay in from outside of Switzerland.","rating":5,"review_date":"2026-07-15","source":"Apple App Store","source_url":"https://apps.apple.com/ch/app/id1510962836?see-all=reviews","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (cee60bb6c081…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.