Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“It would be interesting to have a way to confirm that the order has been delivered.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
7479a0e20256f0927ead9d8271f7db9e8d002b0bd91cd7361725645e344c8589
Signature (Ed25519, base64)
6iWI+arSvy8wEx70DV3hwqgrx1mhkUNG49VxIJf7sntAnhazcGvQD+JG7a3zQEq/BaEcIcHkJroBT7rpSp29AA==
Merkle root
d312d00ed6ab2beb6e18f20d8087ad3474eb8b04b26d5ad949e9237bf3ca4c52
Merkle path
["7479414dcf9576c4ac13e03b4e6cbe29c9ba8e276822a117213d99b993890f8b","2217be1512fd72e8ed7116b9d61cd12c6bb439f4b3855c7ce083522c12d588ad","fb40b4485b9915bcd73cb293d3da55b7c2972a2d331d519fa004f0e10d8b7543","14230b553d4757c991fffffc5516838d535624b3430fc2a3df7587a1e1025581","02ad50c8548aba886ec2adfa8be99ac14cc2a1231e81fa362d9669ce66a4a539","74e8c2ef825f6de058deb5b55e0ea12fd1d61da645920dd0dfe9ef36654b10fd","ca50daa77adbeda2d4c84e84ef6a510472a39fc730eb46d2fa4ea49427f27c12","ee9ac93c17ed0e871d40f8258430a3f6adf6ed0f24469461056037345917ce12","a335ba7cf874cd842b4a334a4c5ce6f32415e8620f1e3f8a1310aaacb7fe1590","dbd0288a89159d02811b0db8fbd8e6ac22b29a3bb4af9777d48ca595be86a226","e22870ff40c337c3ead2903bb564913004f1e9775d204669447133cb20565790","39c354258bc96a643f491dfc400e34c367a90b518ddd054968eb36792c4eb66e","2677d1cff114508638aaf8e9c4730006ee8b778ccb52fd7ae32f6136ea74705c","1b52c506e73c97f5d2cc9d574137c52cb370bf5407bebe9b32056b133838b1ec","2fe1a36eecbe6e65e0243c1a81f5f430e558c99de7c492361bda367e122fe03b"]
Anchored
2026-09-29
Public log entry
search.sigstore.dev, log index 2991846025 · entry 108e9186e8c5677a5f08…
Expected log hash
321e41cd200068478c5cf6f353f00dbd75153d3d8a640e241b1a6e8e4f8ac2ea The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1790574513694","kind":"published-quote","locale":"en","page":"theme:delivery-much/communication/en","quote":"It would be interesting to have a way to confirm that the order has been delivered.","rating":4,"review_date":"2026-02-12","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=br.com.deliverymuch.gastro","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (d312d00ed6ab…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.