Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“The app works very smoothly”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
2ab31e5968b4bdf895eabfe9e4c8358592ef36bddb929f5aa14a6f9eb8db9227
Signature (Ed25519, base64)
fbhWX5sap6GCWHjr6Hbk1Ug9ktXQIMm5oI5VEQta7TQOs9EbD0TwqbCv0HkZL4Et+38wGdfMa/xwkjsKXbdzCA==
Merkle root
c5671f9a997da9b293a79ebe58b20e4534ae608121169f15a5adc358d42ed147
Merkle path
["2ab4db922646a5f1377a969b9b60af48c300b1e94968b4367e8398c5e147be3a","1dde34007849b5e425b6216073a3c1d0f28e1a6cd0b65b49745e05a7a16520a9","55a16d012222f5c2b796183b9dbf6134f142a566b23bfd0d23342452840768fd","b49d78e43f142722d0ba2a18d8d5cf5664af93c9ca4d63d57430ab7bfa888178","f4394110baf3bd2d86c51cb4a795eda1758cb95d9b1e82c42910e950f477d4c8","2691f037e42cb85373a869aeb7f96f60630f1e59216a44fd2ac4dbfee0feebf4","90e5352e6a13bc20f02c49e8f386b61053cea99d0156644a8066ef9e8bca3ffc","49dbd17ac502ae3555024d632b2a1e8dc5218bd1fb3e116302d9c7a7c744d573","0000ec0f40cb1d7a66452f225e13f204b161ca3fcba884ccde1d19b012f5983d","fa579f289686e8e287cd671c4cfac5c878ee12f3f5826fa9cb1b0c137a45e278","bf2c9bc90fdd5c7a37679ccbb9c46fc21a35ac8444fe9c798584390501b96b5a","f27c5483bb4298c200da6907de131e6691bfc1ea8e72244a621cffe958688b74","fc11f12841aa9e89e5390477ce97b5eb6b13b8707be59ab0e8a4348eb3199751","ea0f272f47ae04446ca8efff4a132a738536c4448017d0d61c5eeeb962e76e8d","064efe6476d8e8bd839601b3c80763b02793c41f87cba57580faab7c00dda24f"]
Anchored
2026-10-05
Public log entry
search.sigstore.dev, log index 3081733041 · entry 108e9186e8c5677a0bbb…
Expected log hash
88ab7ac46d4614551fa6e665889f054d7592b15d91016a45621b5c46a7ae8e2f The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1791174108170","kind":"published-quote","locale":"en","page":"brand:nextory","quote":"The app works very smoothly","rating":5,"review_date":"2026-08-17","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.gtl.nextory","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (c5671f9a997d…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.