Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Login funktioniert selten”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
56ba797270658142dc0b5774356ac70003ee45f7ae1c4429119eb275d59b3592
Signature (Ed25519, base64)
kOf9oq3HtVwN33CTTH2UkmA05fVgkkhNc/cMVtZ5Ziq3GmFglLfZmgyftriwSgzBWZHSpbza2/NmU1Rh8JtGCQ==
Merkle root
2f068f3de56bebe7a575ba4a979c9244445d2350140e36238e088fa40fbfdd88
Merkle path
["56bb5a6ab25c5b851214af4a55a29eacabe84d099f09c8d98d33967b21cde2d4","6b4ee8d83408046219d0d56afc7888e1766025c28fc7137750f7b1632072eb63","c175b5f205f65d5d1e055abf910009dcb4faab798bcedfc001adb703dcd196b0","627770061de7db90cc6e30f2508978602c5a83bf53a98ab722343b4c9f902903","756e5aacbca3a092e051f9d4e9c5108d682fe29fb87f4457ea7fd72143f42df5","22a14deae3f3eff9abe861d6398cff6c603c1d36a3075eb2edd85346d41ce358","74a731f70d10e3cb5b755e9875765cc84349bb369048d4587ff873dcb89524f7","f4a12aca059ed83d5e60ef9cf30a9371ca47bc35308b63efef1af53506cf4c94","343656370c9d0f1a89f109b1cf03e52245ff67c569aaa8d995334ab9bac6125c","6b3e2bce1ac9ca2a9257de122da2c471410b43cc705687d4d595ffdc1885303a","49bbbf804812620aeb11a2e2155b2fa548b38360b9d358bf90988e833f01e60c","ddad24b033c054e618d3abbc2cd0303f49551ff001beb238cabbc4b73bc7d951","d1960e2348cd4a71c41d10f1fdeb248b829ec3849e0b1a948157b58e7b767ef1","f2c4543851e26fd9d1e3721e592d66b00f142e537786e975d115c14b9cb61c0e","98191c82333f4385e47f318835e01d44ca8835262c6d0df40edfd5f6a4dc5c19"]
Anchored
2026-09-20
Public log entry
search.sigstore.dev, log index 2893887498 · entry 108e9186e8c5677af79f…
Expected log hash
90099e0300c6e23b62e79318296ebab91bff130379d248ada57f044f77e72ccd The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1789796056710","kind":"published-quote","locale":"de","page":"theme:atupri/service/de","quote":"Login funktioniert selten","rating":1,"review_date":"2026-02-16","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=ch.atupri.myatupri","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (2f068f3de56b…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.