Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“At first it was useless because you couldn't create quotes.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
507e412ff73d97f8f58ad534e29bfc546e795add158dc87e2045b2eee56aa2e7
Signature (Ed25519, base64)
u3g8DZBhuQzL6u0vGbOf+EDVOn1uZekc7ZUhfWTvzjgxid4JUQ9D6q3rbne4QmkOv4fEoloiv91yPV8SujvpDQ==
Merkle root
30b81ce96f52ff8c37a1dce6a2cf1045c2f51663c1ddbd5ca071d040e32c05d6
Merkle path
["507e8bb01342ab65878651df31bc4fd7ade8ca96131fb6ad76e44130f811c85f","96f73c742ca535d0636275606baa5e3b45213ec642a0b35844b6e86537bfeffd","b12c3b30271287933d80673f9a45f44379514db021fd927ddb74309beba33341","dff79a72f2a912230fc51bb0c703984a2430daa93df5b791ed14c5ebebc25bb5","52eca5c510ab82bdb79cd22e18eb37bca7745813c21ff418abe826a402fa25b4","beed8e87352452d9d03afa6043aa0c6daa7eada9066863798531277951d73034","ba5a91948fa9c3ca1b4269215a36f9a79463d1a91911c50bcdf194f82d7f6d1e","0230d6ccc3a52b06cc844db579fd595bacca916a764ffd2efa17e2bb5a5f15ac","505fd6a92ccc4a44928c9a0257d34301ad12ced69d31fdc2996b3a296e553ca6","0c3dd3f4819c7b18e8e86a163c10e339710376b062d715d8d4d9df747379c102","c63f933a640a41f475141dcc7c88b31e6f92b2986b95fec323fc8f9b20688b4d","bd01e5af341b0040835e356bf2d0bb82243c96eb7749b36ead48942b5f9e156c","21ae9b3d04542d62b8bdcb6f03aa786a4e9bda8ae0e825d8c3abb8e6e1018da2","d2f0bde8db363c9acc10fb20e031bdddc43b684fa5984306f2efdec113caa9a4","dd9b0a9d584b044c4116e1c10c4b8cf4a06383a771a07c9f3d39f998f23cf36d"]
Anchored
2026-08-19
Public log entry
search.sigstore.dev, log index 2515243153 · entry 108e9186e8c5677a8eb5…
Expected log hash
314ca716b1ad71ca29fff6da960e81a719fe30fa5fc14d8646acca79a7c09353 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787138594002","kind":"published-quote","locale":"en","page":"product:sevdesk/kostenlose-tools/en","quote":"At first it was useless because you couldn't create quotes.","rating":1,"review_date":"2025-10-21","source":"Apple App Store","source_url":"https://apps.apple.com/de/app/id731738076?see-all=reviews","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (30b81ce96f52…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.