Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Super practical and easy to use”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
44616cb0f48c548519c2294f6ef149d6fe0cc68ac48518f59b9735aec1211b80
Signature (Ed25519, base64)
qoot248ebjN+CFtrVcJr6NuCRpwShPs2vcGugO3dE+ftZIhq6FOkppXd4KY3rZeQKGxU597vpb37EkQ8abxiCw==
Merkle root
d312d00ed6ab2beb6e18f20d8087ad3474eb8b04b26d5ad949e9237bf3ca4c52
Merkle path
["4460eef3664dc14d0e5338cd74a4884c311afe9b77a144bfa945f9b6cdedfd4c","761cd0cad71d6215416baf66f8eb9ea751a824b353e2121e3989da4d24b77708","8d7daa4b952f5d9ebce293c4fa2fdf0e5473be4bcf0764505eceb1fed1a15763","00b115573ca0fba244a444e884c860572bff84e4e991d09818cdfc0b3bd12af1","da57cf89556c0ae21265282dc2c8684139086ddc4ae003e676cfa9cbb7769470","01a6e0970f5028dc60451f3c24844449181a3c11719152afb51c925ebc75a6c5","9898229431a3ebbdac287e50c5d7c8baddc8f67b26a110ccc0974e927c6b0ba3","c448ddc2a7e614d0c2f5f545481f11f04b63a324fa2f6bed159287870bc50433","496cd8c0edd77dda7439fc0d30f02daea65436727cbf686759645c1f3a643220","90e6ac06b6b32c80bef7ca97ec93e720427e1a2428eb67adc34e4a868e57b8f7","64d0ac40f71eb1ef389b40dea8c487ec9fa5151d6c1ba99f08262a9bce82d034","4c63202ac45e7de8817b3ca86ff6317680af50cb6ef4f2b2ef3e0c7496f3e318","d54e12ad25196f7df567d5e35a8d4808db0f8ccbe5c48a2fcb5439caaddf7c53","1b52c506e73c97f5d2cc9d574137c52cb370bf5407bebe9b32056b133838b1ec","2fe1a36eecbe6e65e0243c1a81f5f430e558c99de7c492361bda367e122fe03b"]
Anchored
2026-09-29
Public log entry
search.sigstore.dev, log index 2991846025 · entry 108e9186e8c5677a5f08…
Expected log hash
321e41cd200068478c5cf6f353f00dbd75153d3d8a640e241b1a6e8e4f8ac2ea The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1790574513694","kind":"published-quote","locale":"en","page":"theme:delivery-much/quality/en","quote":"Super practical and easy to use","rating":5,"review_date":"2026-07-08","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=br.com.deliverymuch.gastro","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (d312d00ed6ab…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.