Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Very practical application”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
6ef08dd5b81d04cf26dc86259cb17ce5e04683293ebe48e71c6710e258433fff
Signature (Ed25519, base64)
+Tvedo3Rjr4wci7QOJJ6WbwXx2HdokubGDwqdFBZDBCFXZdaTvAI9BTERFT+LMXBB6I7nUHBTaOvJjnOsbdUBw==
Merkle root
2f068f3de56bebe7a575ba4a979c9244445d2350140e36238e088fa40fbfdd88
Merkle path
["6eedf7cb1443f5cff4cfd4582bd918de6296b6ad026828c086160bbb11a67ab5","8b2945f77026560911557b6f81edae32e0d5e7922aaf9920463226c1dd0b667b","0a4fb7e12b7588dfb03fa2126540ba3e7548d7fae80175a8af93fbd9392a18fd","92d3c9abe6930523a0fec3d0a5d363800ac4fceaca6fd39fbc4f68361ffb665a","44a2ac73c01490767053bc35ace1c6a0de60dd26705d5ce52305d4004da5d8e0","38e6791c0f3164283547b411761c132e5750783f5b7d8ae9e86e992217abc5ab","cc6afac4271cac439f35f7bf0d9284db436f6c9a1c0c81297d3bd72d30f85e39","a1582b7c363ef60d04f15ac859edd4ae7cac839d5a0a7979424e60b7e8883d44","6ebbb5af87d8f13c5730ae1093281534a5432a521d6c9522e1e37615d5e262cc","8536532eb2a22e91919d4abd7c09524a5d8e3523a70bd368a2ce4101adfb645e","06b6f6d584977ae367194680dfa67ace6b01d63ed0e55b7d9e3bb1ac505c121e","3c6ddbcfa48be5df39d5d13fece3ba9fab7f6eec0e8fcf21a13cdbcc6729a93c","c5d2216bf0003f30213891a39e09a3edafbc50505093b2ae98f61a9c067b5a3c","f2c4543851e26fd9d1e3721e592d66b00f142e537786e975d115c14b9cb61c0e","98191c82333f4385e47f318835e01d44ca8835262c6d0df40edfd5f6a4dc5c19"]
Anchored
2026-09-20
Public log entry
search.sigstore.dev, log index 2893887498 · entry 108e9186e8c5677af79f…
Expected log hash
90099e0300c6e23b62e79318296ebab91bff130379d248ada57f044f77e72ccd The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1789796056710","kind":"published-quote","locale":"en","page":"theme:atupri/quality/en","quote":"Very practical application","rating":5,"review_date":"2025-07-23","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=ch.atupri.myatupri","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (2f068f3de56b…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.