Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“I don't want to lose my music library again, please give me a solution”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
12f2313ea215121ca8e3e881ea632199a4e6b9c3b01ac203977be44a6476a64a
Signature (Ed25519, base64)
Ta2Tt85VqlB+UXnFhQQN0/l9JdS0LYqpvMKA5UoH1DKleOVRs2LWljLjR79GP00WY9sfU6NNBf3WW9lZPhRXDA==
Merkle root
f26292e960b34f73f9768b4afc64585e265549d794b35b8167826c2bcda92ef5
Merkle path
["12f12b6f625a42e35dce98dddbe6211c54012f249b8d1ba17779f880a90794ce","5a76878b6f296ca282996f32a1cdb5528c5e68e7829caac5e7974d8a4fbb63dc","4e3f4af6a49c28fc6494398d7f52ca7a616d971d4dfa2205d5bd582f0de1cbf7","8443f11f0d9895a7ebcb79351c7c1542618d9f7ccf1370119a67da82382ef3df","616dbbb5de8e524b9f241a3487ad2ff209bd5cda771606a531645729d887766e","db02c0c0785d1cb7310e97d6c18e9bf1d4139d5d432e5946a79cbae7b3443ae5","7f134aed09af842aa4f3a0a68669b41caeddf17abdf31f3736dcc9f9b7049c29","b6dc8939c21032c7256e91280cd6b44dae569d191604b95ef694a24e2b0a17e9","e409793997c06e100a2abf1fb60e0da36ce410d793b1c981e15b9ee65e213aae","85f54fcaac6430853598bd6eb6139021fd656b334ce0988d3c27568c8d53314e","c90e81bfa64c51799293603678ad2b0cdfdc922d2552151e3eac37f4222dc5ef","dffbc784da6e78ce004c2715fd64b08f8014ea3a60655e0f193168cea47c89e8","14d95cb3ffe81dc7ba7bda02f51c7ab9c1977951e0a9ce587124764e85380fa3","0cf751b4d000491c43eea40a33568458d763987b542601ca0644e491c0b04ce6","e95e880a53b013b49906f2e6b9dcc652726333d77986f48029bb634dc427e2de"]
Anchored
2026-09-23
Public log entry
search.sigstore.dev, log index 2913636507 · entry 108e9186e8c5677aea51…
Expected log hash
417fac9b806377ff48d30ded01faf8424eb98406df713fe2564ee9077747e6a6 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1790070376053","kind":"published-quote","locale":"en","page":"theme:deezer/returns/en","quote":"I don't want to lose my music library again, please give me a solution","rating":1,"review_date":"2026-08-12","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=deezer.android.app","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (f26292e960b3…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.