Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“I want to know how to get a refund if this isn't going to work.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
85029463ca45596c1bf440f5047998638b9bacad7387fcda887b3eaca8074b81
Signature (Ed25519, base64)
k3XNli/qCVZzwABDTjSMCX2iRGOcI3uE0xFVykt9Ff1jnYxb1v/rYKzRI6Z9pgS94L8WpY0e57ZxMK2a9DBrBg==
Merkle root
a086f9fa8309b32cad6e06b6c84c12133a405483807f462eafed4cabc6f3fb99
Merkle path
["8503a3c5a527b30953da0137aea5e9909a21ad0820fb4a699821decb654af475","3133b7ff92855b7157ff1d10da7a900ad6a32835c626acbce1c887dd3182e17d","94f574dedc388d8d75182f7d8ea8d98a44725dd8f167531f08365f01a92b9cd2","c62ae7fa9f64dbb09f84fe759aea34a7c133b681a0877f71f2f08e7fa6181d9a","16b9a25c07265ee9c892974f9826237a0b9ebef5d337e8247db45bdf44a11a87","3d95b585dafe90dc6f6a7ef7f201ebccf53bbdb25e7042e440302049258ed752","018aa779b5afcec21ffe40c2b55829c3ab76160e8234b172e128a023db3092de","d3285efab8c5dc6d718861c649e22a7d44a28a70f117340b394c229a14cf6267","c92c11a73845597e4fa2e1a6335e3cf6ec4117f30270395e6e36459c5a535bb7","d88ed0081db468a06fde4604c7b5f9b4e26e5f507a1f48929ff7f8ae23972605","d9c15661db48de319e00633d7ad2339b46acdf51df3e0e445f60f5fab01d2c05","538b9b87df7b5e561410a33283f3fad70d36ccc3641e7975aae5a833d33bb86d","c1423a4d1e3405e61a7dfa0f9f0d35446d77e6ae8a2a30431655b9bbf5a67719","1d7676f67710cf1152e64179021560b173262f0f0c11c7101c22e9929c376319","d4cf3fd862731bc6a1728d66b360c0434f801f84e015a828556d2731bd771b26"]
Anchored
2026-08-19
Public log entry
search.sigstore.dev, log index 2514476227 · entry 108e9186e8c5677ab19c…
Expected log hash
9a346357c8991b17bced8f12238c2332c4ac3078c0d9a283ee00f82b3c69be66 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787129084398","kind":"published-quote","locale":"en","page":"theme:accuweather/billing/en","quote":"I want to know how to get a refund if this isn't going to work.","rating":1,"review_date":"2026-07-28","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.accuweather.android","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (a086f9fa8309…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.