Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“No device detected.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
1a112d70899541044a349e6a175882a6df25fe3b516a8d1381a8f5f67d9af7e7
Signature (Ed25519, base64)
t/SZbybLskMgAzLnJ5yIKovN/1zE9z393WY747jVRs4NCyiG1t12lev5EIYzWDZ6c6slJJ6QP8Z8ulNSZslmDg==
Merkle root
f26292e960b34f73f9768b4afc64585e265549d794b35b8167826c2bcda92ef5
Merkle path
["1a0fa463daa0fc9126487caf76352dd2a057c4277af5bc9648ad5448f38097e0","c43575e86ca67205e7ef933af52a708bf4c58f23a6d0f3898f63f78837917554","684230c3e7590670bdb05803f2d4fd0274527a55ab4685221207601666caf3fd","f546f306017203a1f33a439623473367c23a5a3054885fbbec14eddbb252161e","ac0a18f3e8931bd152d3de281ae97aa4e4b5bcb58aa0c4db1ba18073fc21beae","3e3f9f9d3b194c39cc7ddfd45cdc6f9971679781835a9226a27887d0518983a4","143f602f4f6ad0bb58ab15c94625b98787f1fbe2fa7c05286c3b39fd4700691d","241a5bd64b8be1b1c59ff8ab297580d7b5fe8c15043dd0912f20037ee308e9e9","c10390adc33e1a7f50f86be2db94265f55bd1e60fa81f4a1a1e3f1d1e6b4974f","0a0177e4e3b1ba5b0a066ae69a29bd962f6a207ac266d658caf865d762934a0c","c90e81bfa64c51799293603678ad2b0cdfdc922d2552151e3eac37f4222dc5ef","dffbc784da6e78ce004c2715fd64b08f8014ea3a60655e0f193168cea47c89e8","14d95cb3ffe81dc7ba7bda02f51c7ab9c1977951e0a9ce587124764e85380fa3","0cf751b4d000491c43eea40a33568458d763987b542601ca0644e491c0b04ce6","e95e880a53b013b49906f2e6b9dcc652726333d77986f48029bb634dc427e2de"]
Anchored
2026-09-23
Public log entry
search.sigstore.dev, log index 2913636507 · entry 108e9186e8c5677aea51…
Expected log hash
417fac9b806377ff48d30ded01faf8424eb98406df713fe2564ee9077747e6a6 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1790070376053","kind":"published-quote","locale":"en","page":"theme:deezer/service/en","quote":"No device detected.","rating":4,"review_date":"2026-09-20","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=deezer.android.app","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (f26292e960b3…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.