Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“And a lot of times it doesn’t work.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
71a6d1abb168c57f15d9f871c959d7ef4751bf08b5a5c7857fa507f88307b338
Signature (Ed25519, base64)
8bJNnREwLoeX/bR+Nad6NIPjxM4GeLcUgKYaCyBpA7xLaLq7WOtoWr1Mscrvg18sgrbu1AxW9/GpGoLWK0zhCA==
Merkle root
d9909e7ff193b610d96d9930fa8111baf2fdaa08b732478b03ded2b9e1e52914
Merkle path
["71af6ee984af2dbb1557d4b18a9ba6ecea61bc85e3dab52d2491436e10edbb30","a675a438c03e856685a2c234c243106be9ee0c6efbddc1513b44b96d3fae041f","eb41e6290e7b396736a4404869d50032ece84bf3e04e347ed8e9e72a4dc8900e","29a005ac870b5f86237d544e15025951673a6d6809d27aa17fe78b047706871f","983ae03ede56c7f69ea709b6738a9b0e8b902846bcffca23d1e2e57afff15813","c5f61ceeb70afa822a9125f9759acfa8a07854967b255bc6c42693a47c715c24","40c20a8e799fe8371802f0c0fceac597309717f8d93eb1c4da0cba5723ea57e6","ccfeaa5eec66c222d7479abda26c960bb4898a7a18ac476e626efe385aca7b2f","fd2d4b1deb92ed1de45f36764b65c3e293e7f0845184382222fbb6345cf0a899","1d2dd5ae57b9f0d1e81af3ce8cf371ea6da321bb4c2042006a264418a9c3fcfb","ab71616747f3f313b6208458f071ffa1432ddf6f9ada13694a8ad71da3536162","9674e4ecef5e17216d02256f30d1a12e9bd64c829be82392db2ad16d9e944e26","fe512df538f31c12d9084e7935c17aa095161d0611453d225ad85718977c3370","fbe51c186e2797045566a65d4e8ac09d80335ed84733c00aea2f32527a4eb0c2","2aa33c224957c89d7d414cc43142ae7c4368efde4f1a1b6051ee910ab17bf997"]
Anchored
2026-08-19
Public log entry
search.sigstore.dev, log index 2515095234 · entry 108e9186e8c5677a299c…
Expected log hash
6f0abb2e15f57da153d99eb9fe756fd2540bcac51fcddbf7ac60c4be3cfb5f7f The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787136684512","kind":"published-quote","locale":"en","page":"theme:canva/delivery/en","quote":"And a lot of times it doesn’t work.","rating":2,"review_date":"2026-08-10","source":"Apple App Store","source_url":"https://apps.apple.com/us/app/id897446215?see-all=reviews","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (d9909e7ff193…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.