Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Your support took me in circles with useless troubleshooting just to get nowhere.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
1fbb6d24c2fa41815ab5c8d58d99868c96b9812bd206197308973aa182c41b4e
Signature (Ed25519, base64)
10fzyZWpJio8vhe/4L3LkPpe+WebjNC5t/6jNEge1h3A3Dsy/f8dJ93noLxaZQsYeC7k5dzFaLbXxlSCDkp5CQ==
Merkle root
f26292e960b34f73f9768b4afc64585e265549d794b35b8167826c2bcda92ef5
Merkle path
["1fb9d4f1322558b48e03f8978684c03bcbf28f3a374cf8c4b3387908310f19a7","1bb527cdf12893ff5437e9460ebc0a63ed0b4ae790b7a0c87a7d8bf132de8523","974c93fe5775b8987cbf56971981998599091ce43d4e52fa635f9e3d6c47cdc6","1936f4dcbc6b7fe3b7670f7ad1acd240df9e9f523d8246da2a53fe0ae17ad1f1","806f41db6648e28d393484e266fdcc4372a54f0b38fb6d36211776244f05c432","501da5b2e026a3d6e5deed6ea9cbf634fe259611d1a6a4fd9243a8879130d54b","40b6c9be85d1d1ed86926a9a30745f137e81657cc072a882cd9e8152cf662818","a453d2d55eb0466905b181978453fc81f88d1fd2a8b736aebef3fab76ea6bd20","fa72a6d3a5c783a0a452b57a571c4ae3cf72135427b655453c1a6b71fad834a5","69fb82ffeed9d91d2c0cc53be6cf126c07d070102e831cc91a4438c40e15f462","87663b8060c34bd52c43cfcf9acc13e2c203c164aac9770ed6b0742f89820281","dffbc784da6e78ce004c2715fd64b08f8014ea3a60655e0f193168cea47c89e8","14d95cb3ffe81dc7ba7bda02f51c7ab9c1977951e0a9ce587124764e85380fa3","0cf751b4d000491c43eea40a33568458d763987b542601ca0644e491c0b04ce6","e95e880a53b013b49906f2e6b9dcc652726333d77986f48029bb634dc427e2de"]
Anchored
2026-09-23
Public log entry
search.sigstore.dev, log index 2913636507 · entry 108e9186e8c5677aea51…
Expected log hash
417fac9b806377ff48d30ded01faf8424eb98406df713fe2564ee9077747e6a6 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1790070376053","kind":"published-quote","locale":"en","page":"theme:spotify/service/en","quote":"Your support took me in circles with useless troubleshooting just to get nowhere.","rating":1,"review_date":"2026-09-20","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.spotify.music","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (f26292e960b3…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.