Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“logging in has become a nightmare — the app keeps showing error messages… in German.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
2ed56145913e6c64ab889a19b25a9ab4ec7a443aaa904017d57a8e3709880c44
Signature (Ed25519, base64)
RGRqgToA4+UXqsO+wQgaQjSaBlWrxBgxcEzfGKzQhqMw8XJXbs3fkCYJihE0zFnRgNsO4hwgpIoljDTc5EDdBw==
Merkle root
2f068f3de56bebe7a575ba4a979c9244445d2350140e36238e088fa40fbfdd88
Merkle path
["2ed4c1c73d495f8492594a6b1058d0c9dd911435c5be359f9e91c50322f29f54","c3467fcc93cae120afdd8022448d11a6545373b752dc9c150ee585a542e70f8e","3272d3298eab66a01992aa37c2e8faa676123018c5a7609daa84c6a03af78393","192100e5690490bc5d480072fd6d337fa1bc156a4443f9252f6ddf76fb482e49","200812cc2c315611aa48e474a3f14794a23c16a89bf6545fd049960037ac1de9","bc4953e26c409f8e3394e1fd79abef26aa60dbbc38b20b9faeedfded0a418aec","c518aa9a1f230ee54e61b1536a7372d192c1ca437955a0995eb66368154463e7","f5fee83fb94af0ecde6e13054a9d7c9dcdc68dc2b36766664d36a3ba25f17b5a","463016b1b7c3a69f8fcacafff2e63f88493f135c41713baedeb7d1809a4cf65f","398671219ca23f0cdc017271e5271c257f722c2474bb46e50ce96077c20b6054","198ec620523c93713c12a5fdef13ab3b73c38312f8c69950c0a24237f8311f64","ba64597144ad55469e4304807853557493bdf960abe724dca5437e442c223165","67b7564c01b814702c17628742fb6a8cbfa0e8a213c06511e31c90cf9f3e3578","03c5fc675733b417d9af5e071de3aba38ae7f09fa5781cbd0133ff9d4e234e36","98191c82333f4385e47f318835e01d44ca8835262c6d0df40edfd5f6a4dc5c19"]
Anchored
2026-09-20
Public log entry
search.sigstore.dev, log index 2893887498 · entry 108e9186e8c5677af79f…
Expected log hash
90099e0300c6e23b62e79318296ebab91bff130379d248ada57f044f77e72ccd The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1789796056710","kind":"published-quote","locale":"de","page":"theme:concordia/ordering/de","quote":"logging in has become a nightmare — the app keeps showing error messages… in German.","rating":1,"review_date":"2025-10-17","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=ch.concordia.myconcordia","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (2f068f3de56b…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.