Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Seit dem letzten Update lässt es sich nicht mehr mit dem Auto koppeln.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
8c897f67f20b2449c0bf818dd5a250b3409b7754ada2bd220669103b4cfe8e01
Signature (Ed25519, base64)
Djic88BxFE7GiUjjvLmZbMLUrAwIRm4+/e53YsWuso/6p6Kn49Me+amhVdhl1i+N0+MitmeymOFWVKTSsX5aDw==
Merkle root
f26292e960b34f73f9768b4afc64585e265549d794b35b8167826c2bcda92ef5
Merkle path
["8c82c7389c7bfafb6b602ce7b162e5a4e0ac5b47413f1c580d0651271e39b7b4","de8e970b255b992321f07ef100ebaea05cadf45d424b90ea80da3825fade81ae","8f2e89d000e37119c8fdc7148f8de0772a70d5db2973cf8449aae3ea443703b7","66b7cf252fa6ad155afa8ccdcf17f3fe24c4fc094349b53e553fa1930a51bdb9","a2353ebaa05f6f35f729ee02707c59f84b8701dadcb8b23f2ea665f2174350c7","e9fc1389dbcffbdac04497c0f037ec3fcd1f4cfb2cba510fb421da823a336831","d521dd823b8f8bfc739348392fc07bca12815770a315fe5990372a21c63ef61b","4c7fd9ee7490d7c2646835be712f869495f512aca7a4623d7c9a869b8b8c61ce","6aae01304f950ce2ecfcd047248b36b9d234c34fd54d381498fd09cc94f24c1d","512d21c1374a69a3787a41f155b89851ff19eb6937e45234c78804ac532f8b27","3ee4c26b3b5e7bee9c8f7c2261aaa73715be73d5f55359c966a0859b79b1d92a","da342b52039afded388a34c4d220b41695f65ea8d9006b7b024c76c455dc983f","edcaec9f8e5156b483404ee77350f2ddca893e6ce1a1eb48e97046facf217e60","ebe1651655c8b61b6b5364f1f9c2df6d3d2570b884eb1475b1f154f5054feeba","a616224c7837fee9e37cf9dfa53b6dc52945555438d928215ead84ba8ccc7b57"]
Anchored
2026-09-23
Public log entry
search.sigstore.dev, log index 2913636507 · entry 108e9186e8c5677aea51…
Expected log hash
417fac9b806377ff48d30ded01faf8424eb98406df713fe2564ee9077747e6a6 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1790070376053","kind":"published-quote","locale":"de","page":"theme:spotify/returns/de","quote":"Seit dem letzten Update lässt es sich nicht mehr mit dem Auto koppeln.","rating":1,"review_date":"2026-09-18","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.spotify.music","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (f26292e960b3…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.