Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“And it works very well.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
220b8a485d7a92fe0390b4cb9fa64df16d387b79e37821893442025163263605
Signature (Ed25519, base64)
wPCU7YWMgttKrH80k3H+IKQT8LR6KJ9bqIj4mzAhVjOkD0XLzXl3Icatm8H0D3qo/b9V3pSu+r4TnZknLxUGAQ==
Merkle root
aacc11945f125ee3fcdef86ba030016c440bcc608f4e51f0ffffdb4cdc5e9321
Merkle path
["220daffed5a870fc37f7888417989240e1bdd4df79f7b31b8da2adcf1233db5d","0bb4d8fff90dce5be12f9667e5c995745ece34bb121dd5e628ed7f53ae789afc","51ca4d3fa26e211ee083a845fef6a88a2237c67fe3d7ef7b6ee9cc95dcf3fb96","90af14572cb624c1479bf70d64f91d2f86deb3166244e0d7c8267f1020006c53","4cf0a98034f5959162d89fd45f592555306bc9707c79da93a962131f6b4b7993","1cb8dbd9fe1528362db5aaa5f127d1c02a14964b9f1aa99abe3535e77338f574","d5f8d4d936a9311fe4c3750130a3c5bc578e50c64fcdb5958defc5f9ae1342e8","061bb8abe5b50320552c59bdaef58bf82ee5731b2003244e94cae0cfee67ddf8","6ab90d969615a84c123812f466af3c7d5b2eeb92175f25fc25c23abc1a3d9818","e38aa428f0405a2e95f8372ea7886cecb538761f92581d6d7d7d59a70cd0d04a","0298a26818a13ea3025566ab2db6a034faf816e34b7a1e19a16f7e3fcbd87002","7b8ded1b49351694655c52a46b67cd12e02f2a4c9ca9c29916bfa197957ebfc1","24192d1fe3fa8596b225aa5d8055e7e92d26709ec190f1226b913a3e227f64c3","5366af6eb1ce50b0f459da15c1d7eb12649d0477ecd930804e506d3f2ff66aa2","2309962142b16600f7fc4d57273f3042f382acb91be89aac7f00112f61b58f1d"]
Anchored
2026-08-21
Public log entry
search.sigstore.dev, log index 2543547848 · entry 108e9186e8c5677a921a…
Expected log hash
bb93f13ee7a4a636e28586b842e19662b148eb18166a89b3ae7d189bb8e81689 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787286345433","kind":"published-quote","locale":"en","page":"theme:relai/quality/en","quote":"And it works very well.","rating":5,"review_date":"2026-03-19","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.relai","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (aacc11945f12…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.