Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“How can a provider offer something like this app (it's actually just a website link)!”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
3f5277c2cf2f0b394d81fbba03a6b446b3b85679295aff4baee1f67e5eae0acc
Signature (Ed25519, base64)
YOeMDfsXr7NwudPOc43N6aDqDjkTAEcwx1ZfyMciksdw43TXeWglCUEzgNVvjJcb9IHIbNrs1pWxEX9AfFYsCg==
Merkle root
2f068f3de56bebe7a575ba4a979c9244445d2350140e36238e088fa40fbfdd88
Merkle path
["3f531f0f799bdde909aabfb568139656d10ee900d19f04f0d80cb71ed9ba6ea2","f940c2029c84db68d9aa76fa1315e819e1fb590758fdbd47ab9512170fb42bea","2be0d2a8ef334e44d9f21d0503edd76826540305503f7e9550fce6f092fa4a85","6930417963300a8fbbf651a060f2849a3b65bcb5321884561b7227a8a6c88eb8","8133d53d42566da308a2d3d4c8443df0b3d0eb9feafb77323f07ac88844fa098","24cee1f706190463d615bc79ff37cf7402cf08a9b3e6dfac1d55dc44bde66695","abd1bde7cd4ab804d8f9c7a388124907fa6278405f1ac1464bac6e9f647f7f90","707f90e2843d1aac238aef6a284d6e25798f891f20378bc6637000748e56357a","3aac738183a0002c8d5bc283a8129f382c767c48bc855a1a8dce88dab5935788","771bc6adf193615690af57098eeb146107db7c9ab5ca8947af5a61856688a857","160c0427cdb188ce7f937f06435fa5996b6a19b4bdc7052b0b1e205016d7e024","860272714a28696648d99767aad91d735a5f60322d9fa60ef0218fd7ac5b02f8","67b7564c01b814702c17628742fb6a8cbfa0e8a213c06511e31c90cf9f3e3578","03c5fc675733b417d9af5e071de3aba38ae7f09fa5781cbd0133ff9d4e234e36","98191c82333f4385e47f318835e01d44ca8835262c6d0df40edfd5f6a4dc5c19"]
Anchored
2026-09-20
Public log entry
search.sigstore.dev, log index 2893887498 · entry 108e9186e8c5677af79f…
Expected log hash
90099e0300c6e23b62e79318296ebab91bff130379d248ada57f044f77e72ccd The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1789796056710","kind":"published-quote","locale":"en","page":"theme:atupri/ordering/en","quote":"How can a provider offer something like this app (it's actually just a website link)!","rating":1,"review_date":"2026-06-25","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=ch.atupri.myatupri","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (2f068f3de56b…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.