Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“They just need to provide an option to mark all notifications as read”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
b41b2a05c9f541d9bc9eb6017df0909f6723c2a266a26dd3deb4b62677b91397
Signature (Ed25519, base64)
Os2TfULbBpeSPAORqXQFMZ9PfvWriU/WLgCF8agpJgJZ+SRVz6+ujc5x7bSrPMOpIDpKGOwh2lQNNFAWmLRQAQ==
Merkle root
04b39eaa56e1cf8f75dc8eac18bf6942167c8418ea731a7471223f0be60e3e6c
Merkle path
["b41e9de44901d888f73d43f2c093b3f599f3dc71f6dae2a0ce51a90a4e62f7d7","ae697b89e2abf9d298c9560763002c728076fe57e4adf18b296e92b7ec7fd19e","8f08df2f3bc98a9d1ddbdf57008dd4bf2e3e4077b24c8d2d725f15f36e11f5f2","3ee589cae6863edae296d1f622fc24c1c54d49aef190037edbe84cc844b8f58b","9c867ea0eb4ee52773090bff9fdf87bb071f5e59cd36883a9fbf3d4ffce5e5c7","3a38834c6455d1dd0061c5b7a03f27c81a7a14a20d7669dc99df3135d7a95d1a","613eabf26409c2139f35dbc7b16a4e7a0377d898c36f9dbcf8446654689d1cf8","8abad34cc208d5362a6b1134eac073da2c288f75bbf6da9e81c5c1aebe35d6a3","ebdfe908f317938fc28e50d544f11e45deb7389330f64e7c56e42b3f338e003a","d2a79a9c20c0d4932303f4134acf2b8c72567e61110c4e14b4f8eec5b13e4284","76bc58a8ab567ab0ff729fa45030cdcefa42a6f685d264f867127e3cbe1966b8","e27b6f0d2a6e378ff36cbc28e04f11599bd9917f1291e082191342792770949d","2f760d0f42bf27702bb03975eaf8d6ea5e036b0f49b2fda05a97a4b8e2bd9942","8f074eddb198349108c1e544aa98c8c80e756f627b29b4943cfd74cb3331adf1","3ba88b0016422cde319348a72d81ed01eacc4bd155bae80b5c4b6ab6d98a745f"]
Anchored
2026-09-19
Public log entry
search.sigstore.dev, log index 2890214870 · entry 108e9186e8c5677af53b…
Expected log hash
1f3acef0f063246e051bf412e40f4279cb96ed334ff7b0647a13320c1b31c4fa The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1789722569406","kind":"published-quote","locale":"en","page":"theme:ifood/communication/en","quote":"They just need to provide an option to mark all notifications as read","rating":4,"review_date":"2025-09-20","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=br.com.brainweb.ifood","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (04b39eaa56e1…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.