Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“I cannot proceed with identity verification because it is buggy.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
4a5117607e32ac69937b4a1eb5c9abcbf6661f2c19c08ca4b91d531212a2e318
Signature (Ed25519, base64)
XFX3QvFo8xWMwHjbg90cgg87NFFmFyngCfVmHL4yrv9jEDZuIWffqXoRoAdbiquv+57sBp7TAXqqYnowl2bMBw==
Merkle root
aacc11945f125ee3fcdef86ba030016c440bcc608f4e51f0ffffdb4cdc5e9321
Merkle path
["4a57741f70d892300f80f48926994731a4c112a35148a537a5fa0a7441fa7c4e","5a9e2cf00a750d0b80233a44b92cddd2705fc208f0ca3950ee0f787abfcee474","1400bbc454f1fc9056149a710cca677d06fe1ab9111ac66ee3b9a8f49af1c762","79ee415c28b1ddbd93e5b941ea02541b44a34d279b1989f7d3257607fbb41801","a07d1c4a92b25cb350e4881793f94c01abf29b17c807420414d43dd44ca80b92","d5fdbee9b9ee296c5d4a1c2dced3d56d04cf11ec841e1ab2287ce60fabfbb41e","add714882dd362da91c9765ec69f2281d7285b5280cbfc4c1ac86df7c67bd005","9cebe9a2c019db797524b4955a1f67ca0345928c898f6cff8c364ba3d935d8f0","223d6c327b9b3dd2694f70809344f6bcd3858dfff20a48e49cbab6ae1964922f","c2791ab2c10c32ff96442552896f05678636207a750754db125cb90802f61bb4","61c08d93ea191ae353cbea2aba818a94ddf68e5b0e74c8f4d5c58ef4f57d4507","45624d3966c76d2c1ac3fdb56f60b3e77b8d9f5cea632c887aa7ea67b1243c57","b7222ddebd7fd4beb00c1b60cb288ebc44ad273c20047501c30b3c543f6898ca","5366af6eb1ce50b0f459da15c1d7eb12649d0477ecd930804e506d3f2ff66aa2","2309962142b16600f7fc4d57273f3042f382acb91be89aac7f00112f61b58f1d"]
Anchored
2026-08-21
Public log entry
search.sigstore.dev, log index 2543547848 · entry 108e9186e8c5677a921a…
Expected log hash
bb93f13ee7a4a636e28586b842e19662b148eb18166a89b3ae7d189bb8e81689 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787286345433","kind":"published-quote","locale":"en","page":"theme:relai/returns/en","quote":"I cannot proceed with identity verification because it is buggy.","rating":1,"review_date":"2024-11-11","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.relai","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (aacc11945f12…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.