Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Great you can find pretty much all the music i want to listen to”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
3c0e33bd865eb4a6254076dc79065ce6f0155039c27e958549e501876f7984af
Signature (Ed25519, base64)
kzkooNYGhceHvVPJQeg6BqHdhxyN0ewUBppbLc5IAdqirM7XPiHJN8nHrjUKiI0RGt7QE+hXlW5nZFASue2bBw==
Merkle root
f26292e960b34f73f9768b4afc64585e265549d794b35b8167826c2bcda92ef5
Merkle path
["3c0dd353f9f41c11733a856ab70abcc3ef6f28db0070858a33853bf9e745c6e1","635509ed23e6e982ed536effa9586ecf1c356cea8af2cf8163e1978992119f07","493678173382aada14f6d2bec5d3ffbb148e38ede5cbc7e3b8db5e82dbfde759","70c3f87d2f7a27e3a16ef041a224527d368ada0cd03c2f0a51bc77f6e78f3615","22eafe20d014734d197efbd53afdc4f4149df025299a54964d1518a7b55760f0","82e4ebca98a79634c000b744d2ff50bfdbc08ea58af08d87d3a95769dd0bd9e4","d9d53b8ee9d8fd2ded141c3584333923f668ad50a9599f4a424cd02158951e56","d620412c7622240e7daf46f21db6ad5bd853139b0e39d49df23b86df7ced1eeb","a4e90e183f696246891a7e9bcce417bc312e94b6e8514d8de34e360d8bbc17d5","aaa80dbda8da565e8bba086ad7a2393e0ef1254a132b8f774e2db6b703b1ad9f","d50558677eb3b34fd5289f4b3a387bb41118ee6724c345daea7bd33ef7860d83","00a58474486d38878667c018eb810e71180b9858df79c82d171ce5b4f5fcd15f","5ef2d0b70398ea508e6c490819b91bf39069023f910bbf3a50f0ba400757578e","0cf751b4d000491c43eea40a33568458d763987b542601ca0644e491c0b04ce6","e95e880a53b013b49906f2e6b9dcc652726333d77986f48029bb634dc427e2de"]
Anchored
2026-09-23
Public log entry
search.sigstore.dev, log index 2913636507 · entry 108e9186e8c5677aea51…
Expected log hash
417fac9b806377ff48d30ded01faf8424eb98406df713fe2564ee9077747e6a6 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1790070376053","kind":"published-quote","locale":"en","page":"theme:deezer/quality/en","quote":"Great you can find pretty much all the music i want to listen to","rating":5,"review_date":"2026-09-20","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=deezer.android.app","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (f26292e960b3…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.