Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Opening it in a web browser on a smartphone doesn't work either.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
1e58407f370253ba1295b91e29cc5bb375d94f8254cb4ab7b1e2884f48827c90
Signature (Ed25519, base64)
SvOMfaXuqzeSg5U6jDR5Bxd6eTGMSnzV5vyMCKbcVABdbwGhN4/+uwrhP5p0tiXc0xBUARnqXszLqoObAdllAw==
Merkle root
8c6268a14330d1a3403c561e774645b0671f81571ec1735d4674ebe1de7502e8
Merkle path
["1e582c982dd883a2698ecc70e61f6d3756f09857084f3b29e353dbbc4f71bb98","413bcbf53426121f6c20022b3fefa91723fb7675247c3a218235b6888fa7d821","74ae033a3a47552848fac6262ebf744db466f3c5b1fe8c48cbf50f82d1fc37b6","e41b46d3775157ecda6b493947f9551a6b6af2185c497be7391a6eaad459397f","937ea6e1c43046c32044cc81749681f9bb41fadfabe49c3083d9136fd6a4c7c1","8eb689ef24355c7bb41bd90048f4d3b0f25c693456e3f5696a206441f02d4014","41e2f8c9390a8fdc0cd8ac5d2a3f8122bb6c73f2636d8b66e39091266dfd6819","c802c06305b2a02d107ca689968c6ff3b166e08f183d8bb66013b4912f64f486","33b08f638b33a1fa57ace4f2f79c754774eb4d58b4c3a8de8690bd8a380d5be2","a57d545e66feda3c3e927f3dec6910452de349084e0e11490d4865a4c03770d3","f099f91df37be0cc3ada86ea6d16de38d4c6fe93e759748d1703bd5249542c05","bf3c0d0e476bfa9165fe7a83bec283edb19a2e95b65079cb5f0aae8086116889","87aa107dfdf756911acc54672d2c33287c6855f38333ff4636b90748c8d70127","894fb50f273584bf006781fb08f5958320d3e5510a31da0d6339bcf63d847254","f548939ab1bb46e2c6638c372c3e2eef0d561ad18c63c15229fececc951e0b3f"]
Anchored
2026-08-19
Public log entry
search.sigstore.dev, log index 2515439294 · entry 108e9186e8c5677a4f15…
Expected log hash
128701fddbb19410bf57cdb2d04d7a0278d13bcfda6410d76f176fa58341e1c9 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787141082461","kind":"published-quote","locale":"en","page":"theme:sevdesk/ordering/en","quote":"Opening it in a web browser on a smartphone doesn't work either.","rating":4,"review_date":"2026-07-16","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=de.sevdesk.sevdeskgo","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (8c6268a14330…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.