Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Curious to see if the refund amount will actually be correct later on.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
6916dd407f0e4b83ac6fad75d15349f7f5fda02271e2dd1035e42dc58c34cf29
Signature (Ed25519, base64)
8juFWFyNWDPePxNws4VRlJgMo13DlKPgFWshVBfav8WJo9hNp3dhn//2CpZCq086Ea4fPNk6PX5DVCXWg2W7DA==
Merkle root
2f068f3de56bebe7a575ba4a979c9244445d2350140e36238e088fa40fbfdd88
Merkle path
["691e4e0f215c49484323117154438e67a1a2435d93a700a2951d3028a1649599","34e74dc2c8e966ec18dd00e16f4c388bc6f55dda57b93c249a685e93b7de74da","4d53551e7edb82077c7af1a1a28a39ccfc4fdfd65a3f33a738bac96e0cccb648","4afa328dd627c125da18b061a5887e568852b1db94d37f91c6ad0927a47e02a8","5641821aaa43ca1ad90da073d05bcae5fb7c925af6f89b8f3780cdd76c67a46d","5405aa2d6bcadd53b7b5ed4b19f28aac2a412f861e522abc6e72202d8e1010f3","3b13d547cf814d9486db60f3311d4b86dcfc54ef04ed34b29dd0ebe2ae6923f4","ab41bd7bf14a75cea6dd8e40ef42188a53744031745bf58930e3c8a992b208e6","9576e5ad59f5f7ed6935c8d546242518ffb9338be0398a7f4a38f50fe55c6581","787ce029c25776c0c21b0d3385bb49632ef22b687a4cdf0021808a5fb71b9ed7","d91a35a18a8324fcb9000880e4f71f927fcb25a89d933d485678711818c15eaf","ca212d39522aa6a7477953ed7c65b7eed667a9e6669e3b5f3bd86eae7b2d0765","d1960e2348cd4a71c41d10f1fdeb248b829ec3849e0b1a948157b58e7b767ef1","f2c4543851e26fd9d1e3721e592d66b00f142e537786e975d115c14b9cb61c0e","98191c82333f4385e47f318835e01d44ca8835262c6d0df40edfd5f6a4dc5c19"]
Anchored
2026-09-20
Public log entry
search.sigstore.dev, log index 2893887498 · entry 108e9186e8c5677af79f…
Expected log hash
90099e0300c6e23b62e79318296ebab91bff130379d248ada57f044f77e72ccd The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1789796056710","kind":"published-quote","locale":"en","page":"theme:taxfix/returns/en","quote":"Curious to see if the refund amount will actually be correct later on.","rating":3,"review_date":"2026-07-24","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=de.taxfix","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (2f068f3de56b…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.