Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“I can't get it to fill login credentials or payment info in some android apps”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
7568519dc3bb9cfe4f9f5b9605b337997e12fe1647704d33e17e3724ba7fd694
Signature (Ed25519, base64)
q56GvdlQMwEMnMcu4BMyXcg+g1W1N/fu1iz/xKIXCummKE80iiPMeY02FR0sHx2SC+oy7+QwN7naH5a7BoBYDw==
Merkle root
4dc0bd79ba3e9442f7f1feb21f347e2f6fdbc72e99098aa5164776a6202654a8
Merkle path
["756924045d823b1f750a63365ea504ca042ccad0146eeffa2c0c83f92ce36581","7f77e18db4934c72181190a009a9700dbfe19c5d75982eee5b8030b75dfb1da6","675928a372f7dd1f190413e239b2b5eeaf74b32b7f5cafcaea48be852422aa0f","4acefe2a188ab187fe62a65128594542beac6e127950ef8d564210b8b07904e3","27891e7981ee443da1f144010b42ffb4284cecc6f9048abaff59fb088cb3a287","6b4159959f93f2b380c6a5bed451941cdbf48eca6d1dd01cd8288b7143d2627b","ba8961729b94db6f4363454bab718437a23a62f205f8d60cf1ece33882a5f7d8","5a1e256647b2b144b700137c05d2a9b791baf07e58fe6393f4b6e04e40a28579","95644852f1252f185615e2e700f016befb7eb0795975b4bd7703cd7539549df6","8b3ceaa31b631d3c0f6df72f5c88834abbc1029eebba0dafcd1316ec68741b46","c23861cf89f210df9c3cce64813ade3e6652df65ad82bdb7ba0ac6dad53d178b","dc2d2f59aff48bc391b50cf0e65cfe79e98593fdcded5f12999e08f84c8fd9de","77d8cdcf0d2c898e0552ac900c126db61e2277cdb3705b85a834e54dde1ee5ee","d3f9820ef177ffb6742d93ecece273e46037aa87afa8ee19fc7a0b34f6ac592a","e60c2274998b06992577796b6abe86bec144203fe960878f7951a3ae12c9e532"]
Anchored
2026-09-10
Public log entry
search.sigstore.dev, log index 2776103867 · entry 108e9186e8c5677acd4f…
Expected log hash
2498329b7eaf275d309293dfbac35d05dfb8a55c65956add8448561c05945f28 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1788848066028","kind":"published-quote","locale":"en","page":"theme:roboform/fit/en","quote":"I can't get it to fill login credentials or payment info in some android apps","rating":3,"review_date":"2026-05-22","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.siber.roboform","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (4dc0bd79ba3e…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.