Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“The "starred" locations doesn't work for me hence the docked star.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
616bcb028e5b0fe20ca8b8889f85e104f3ce2d5f22be1c86a66711b4ff5a98db
Signature (Ed25519, base64)
dPDr1BWJ4UUFqbJ3TgbuwAl5gdRph4DhCDGaR3z+rwtNIvdtwV8/R8SzNUa5PbmCSxtM5G/o3vJwlZZ5CVMrAw==
Merkle root
c35385e3159410853b606ace3c93abcb561dc35874bbfae2272c5b0050f06a48
Merkle path
["616a117a917371171f4aa642c7187e748473d9d94416c60a59d069cab3d65318","4505f08207b248753bf6fc61807e01c5e3fd9955de323928dd9944ea67665254","fc70e0bbead21362acf22f437252d88d77f138db14a27d70e4d921504560fc1f","5b8aefecdf0b9b430c465759d34ff9ae9d84db059ca1f7f1dba00b75f5d767b2","1339fd0c928c72669fdaf3c4b24dfe0afbfbcc5614981cabd1194fed67f7c327","34017bd74b684ae268d307f8da7b2708a6611bf8edc0f7652b7a08397bd3aede","16e9aec81d80285b0345d10abec4619c23d022b2130419bd4be51dc6a91d8355","97f74abc7e21b867907a24f83bef4e28cd8156f9c8b9426e911dae82905f44d5","ffa5135832389685d50da407ecd5f3d5be006244a2b7e517923035ceade86736","8f647bf351a9a6d9257c1fab67968757b9ac40cd4eb617f879abd52cbd6b5c8e","02dd5bbcbe0d921f9820e53a4da5ad31635601aa86ed293d10e016200d62f20a","8e5f57c1a2e96cf055d7b9737b78ff93242efff1ec17e65db056e13fb18c4839","6cc2706a4ceb9b9114520cebef77f34a5bff54a2bf14e315fba81a7635eddb21","eb865981e8703d40e97f7a1d500cef5e7bd341c0e720b4ca75d23312d5aa5f63","19399f0af13a2147dd8ceb83692caff2214adce3d49571e366dcfb3633df2667"]
Anchored
2026-08-19
Public log entry
search.sigstore.dev, log index 2514083622 · entry 108e9186e8c5677a81ef…
Expected log hash
eb47f42546fcc705387579993679cd6250c0b995d01bbd10805cb4c8d66efe2c The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787123762743","kind":"published-quote","locale":"en","page":"theme:meteoblue/fit/en","quote":"The \"starred\" locations doesn't work for me hence the docked star.","rating":4,"review_date":"2025-05-16","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.meteoblue.droid","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (c35385e31594…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.