Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Works wonderfully.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
6f980b54596cc9212a0860536c873947fd479499f39f1d7f1e2707b474c2fa74
Signature (Ed25519, base64)
npAZY1Stx8U5lVkEuUcPM/gSpA0abA44hG5WhfzFvzoHteKIrYuLyKM2dSCrNCxj8t/nwslYltJi80A8jtNiAQ==
Merkle root
b9a08f9d6d76dd148110a496219c42cf3205c6f982800d84d5c85d77e9461e02
Merkle path
["6f99f2d6c4425f99dfb7c59d01d3e31d1572dad0caad4f9f316f18980d308541","fea7e421769185e87a4abcad57a74d42c633c194eda2f802eddabccfab25ddf5","a5e8f0c3335faf00404196aa3b4ae3343f605c61d3608c16da327655e7f28f00","9b933fad337257eb12e963158da7b4afbc14a6660dfb37517ceb1cece50a6b98","49913784c97d9a51840af31bb72d41099dd78c6c0112e22397a23ab69b671aba","d880350a3503dcd1a53539096af7ff9aee30cbb76426e03bead6bee48d3aff59","aa7008b8d41faa6d38367dda78e6c9a55fd4b157b9787cbbd022efd22500b107","6a3c34891bfbc519fd3ad03e02ff4c4428fb44278adb6d6fc4d6d720b37924b6","4823e581ec530bc730f83fbc1948180c59159cc87bbe6c0b23ee874889ec3297","6f1f113bf589be73619a3d47944b58f51691f155ed302b17ee4c67851c0133ab","16e76181c9e0c3e4486f4b7a6922be8a933d0a9c0c664aeebbf3709042661f8a","f8cfc666649943796cc64798f4b6be7235ebee26ef544e99b42bab2155b6cbad","8b252735b283ab7584d9f6925f08ed38c911c64db001463eafabe5061cb6f9fe","6c299608515c69a03540be35865f96ca4932f3e0403f8f39fb0e1c2e2aedffb4","43a562d6822dab12c673c1efa0a3171d1ef69b949f676fb01847e1e5b56274de"]
Anchored
2026-09-22
Public log entry
search.sigstore.dev, log index 2907673729 · entry 108e9186e8c5677a06ea…
Expected log hash
bf9a74000249ba6e66b1e29aae9d8cb95c3400dc118569a80e5c0949f3e8ac62 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1789969984102","kind":"published-quote","locale":"en","page":"theme:anton-paar/quality/en","quote":"Works wonderfully.","rating":5,"review_date":"2025-01-26","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.antonpaar.homebrew","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (b9a08f9d6d76…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.