Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Very user-friendly!”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
14da6e7fa747a13b97112e7fa8f7779739bdde87b6a7fe3b5f5bdb236857baf8
Signature (Ed25519, base64)
G2VkZKtGAPLPdA9ScbRnhYkmUep5z/RDPNfsoUavx5iq8TAgJs9by1n861goUPqsqRINCfzS5JIVTPzZngBNBQ==
Merkle root
404e3c13e38cb64105d39456b35227bf21885d8da4853edbdc28c1291169b69f
Merkle path
["14da5e8c1438aa9e9b98478b98cfbeeaa37b46b28537f62e2968307399d91fa9","a762894af20c1d992c9ddc88bbbc12c04bac67c134d5a626d572b5e901f6bba7","b58fd30e0c1d1cac7d37e5371328acce2bb3dadb0b05e655282d7edfbcc01d53","889d53dd48c71427f7d39177a01402a5f420022efea8e64724e73a2f28aec1a4","07a8611d039744a854bdd9e3f9f47ebab84d33dd6472b967f142227599587333","e5f37492d9cd0482dfca5e86ddb5a77c9c987b1b9998d3e687196f44e50d3fa8","00716c66fbe74959a71d284a0f269891660e0172de5cf90f04967c1aeac14930","3e2cb7cc2e87399551a8ebc2069d879e985b611ccbf429eefb74bb7196ee61ae","d944819bfd1fba48fc0fc2302d6c2026421220c05637c45e69ed419fdd17d06f","7844160e378f838f65161b15a5320c7c30bbdaa192c01d1a6b7e5d033ab1e919","11c47928bd826f741227628c368e58528290f8bf29356fefe3840f76325cfcd5","052d330da17a9b608bc649dbe97727e89083d8738efc5c56bfbfac105e0c2b9d","15d2e7111dd71c6ca8e6466c194f5ce08d202efe38071f7b3fe773e133385ebd","bde050f080e8537023a46ea459bb1518e1d885f47b2ddaedca03653a64f35bdd","63269a191012537d921c10ea30214f6deffddee0c8302c1d6e8c9845e6049806"]
Anchored
2026-09-02
Public log entry
search.sigstore.dev, log index 2684163355 · entry 108e9186e8c5677a55e5…
Expected log hash
4066e61b2031c5768194188ceb0300adcf0b5443c63f9d6a4476a0f6ecc5beac The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1788335271191","kind":"published-quote","locale":"en","page":"subtheme:meteomatics/ordering/data-accuracy-predictions/en","quote":"Very user-friendly!","rating":5,"review_date":"2026-05-14","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.meteomatics.app","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (404e3c13e38c…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.