Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Every time I try to make a purchase, it asks for updates and these updates never end.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
6ab91f24034a0fbe82d3595108cbb16040912af6d10d24c71e9623f0ee87c3b5
Signature (Ed25519, base64)
jy1XeOmLziuKWs0fYQ3TRDvMykVshvfCGdDQ2fpkuGTjGyaDSGpiYmcrvd29052+/sKZ1TupXVA8qq85ycvdDg==
Merkle root
2f068f3de56bebe7a575ba4a979c9244445d2350140e36238e088fa40fbfdd88
Merkle path
["6ab9cbbd7c95d043899c2ad88bb7ab54f03b0fa112eaa2cf92c1533b98e33d4a","8175caebad9c7f34a24a2db9c14be4768ee8c1e2d1511afe9d23909d3e8070c1","4d209411912992e02ccf941488745041f2f9ebcd24cebbb79aa87bf935077e50","66148770fdb582f6b9973cc652edeb6005cc4c131a8c480f29a75c74202d12bd","2a7b681571b978574b68998cde085f9bd1f1dbeade4b4c78cdc67177b6d489c7","15ba589601929ca405c29ba9effbe3c6ff6bf61bd581f31a13e03a52f41b2c1e","22704d11f4a1a96a1903425f7741ccc6a237f333c198667d74ce851e3fea4926","240edb087fe5193a4f17facf1391701ff85ae46cd648d147ca49da4e4083053f","b9d1a91321c057fc7ccb695afb556698cd9635001ffc21e7d09331b985962f8d","9ef93459679269877aedc9cded166044e465c7e68ce7c2782c9e40247bdf57a6","d91a35a18a8324fcb9000880e4f71f927fcb25a89d933d485678711818c15eaf","ca212d39522aa6a7477953ed7c65b7eed667a9e6669e3b5f3bd86eae7b2d0765","d1960e2348cd4a71c41d10f1fdeb248b829ec3849e0b1a948157b58e7b767ef1","f2c4543851e26fd9d1e3721e592d66b00f142e537786e975d115c14b9cb61c0e","98191c82333f4385e47f318835e01d44ca8835262c6d0df40edfd5f6a4dc5c19"]
Anchored
2026-09-20
Public log entry
search.sigstore.dev, log index 2893887498 · entry 108e9186e8c5677af79f…
Expected log hash
90099e0300c6e23b62e79318296ebab91bff130379d248ada57f044f77e72ccd The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1789796056710","kind":"published-quote","locale":"en","page":"theme:uairango/quality/en","quote":"Every time I try to make a purchase, it asks for updates and these updates never end.","rating":1,"review_date":"2026-04-07","source":"Apple App Store","source_url":"https://apps.apple.com/br/app/id1207090602?see-all=reviews","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (2f068f3de56b…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.