Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“sinon pour le reste c'est une application très utile”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
37c6cf4051a6903290d1a9855d87834b0297a5194a9817df3c785ce7a33d75c4
Signature (Ed25519, base64)
0nmZRn815EOe/Oe6lij+pQyaR9X0WBAfWoU1zbyPAB+TNVBlC4G9hk/vXVuBpG3ZS9NR8zbFN5tWVGkA+pYPDg==
Merkle root
f91c744e1108c1bb1ec3259bf4dd752db9e3b06ce3ca7c817c48f3174bb949cd
Merkle path
["37c6dda3f27220b541f35222d87057a1e87fa14a3f1b7174f08e73e7b9ab4464","4081c9e51b9f607a1090d33f42fd186883587765dbc233774ee9dc37717d80c3","f4d1309c023e75979e22471fe318a2f51188a321b3e575b03b48225d2f15b34f","0e81bb0d28db0f724b380f48b720f5507843934af4820d34c12aa876fc30d951","84853cb542a39a34114bff0baac4dce75219a92ff6d0f2e995eaea8dc56d2060","479a97a4f2c5fa47479c716ca3e4f09daee76694a73f8e22c4966a3cf99e2995","966dbae8a0e8894405d1068a89f8cba8ff26f8cfadf696a2d069215c639d346d","2e64fd7f8e514480e10f7443dd447748977e31358b3b28d467c471d73ec5859d","9c1ce81ad971895e7aba0cdd63fd5a231549aca07ddf3577fb631d670662f09f","0c8f28e2fcf69ca642565fa8a5c74be693fb1fbbcb2da20b8abeebb2d02c9080","a2e0bfeb76a35cb99f99b749a29aa18ecae17bad850bfb1e48d8a8c5e1fdb27b","182a246804d2942db75cfbc8a710728bbac99fe0f4bb5f453e86cd23c9990bf0","0e47c34e11f519102858fde77876c8c01feebde2bc4c309f900f224bbf484cb1","939bb6f35c7a9334365aa0f05d437301f5b11fd1649b761216a467d624b12d5a","7e33dd613a6ba5c13ea4ace578351ca5e0375312f966275d25485ca016b59318"]
Anchored
2026-08-30
Public log entry
search.sigstore.dev, log index 2647332298 · entry 108e9186e8c5677ab309…
Expected log hash
5d995478a14ac45f67e2121505e769136cf509c045e6701e0235a25f639d0a15 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1788058735671","kind":"published-quote","locale":"fr","page":"brand:signeasy","quote":"sinon pour le reste c'est une application très utile","rating":3,"review_date":"2026-03-05","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.glykka.easysign","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (f91c744e1108…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.